Web Hack List

Collected research

Do not trust me: Using malicious IdPs for analyzing and attacking Single Sign-On

Uses an attacker-controlled identity provider to examine OpenID discovery, association and token verification. OpenID Attacker tests recipient confusion, key confusion, identity spoofing and discovery spoofing against 16 implementations, compromising 11. The paper traces failures to missing bindings between identities, provider URLs, cryptographic keys and session state.

Record

Researcher
Christian Mainka, Vladislav Mladenov and Jörg Schwenk
Published by
arxiv.org
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Christian Mainka, Vladislav Mladenov and Jörg Schwenk, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .