Web Hack List

Collected research

The Emperor's New APIs: On the (In)Secure Usage of New Client-side Primitives

Facebook Connect and Google Friend Connect were reverse engineered from their JavaScript and checked with the Kudzu symbolic execution engine. Neither validated postMessage sender origins and both used targetOrigin '*', giving message injection, arbitrary code execution and man-in-the-middle data theft.

Record

Researcher
Steve Hanna, Eui Chul Richard Shin, Devdatta Akhawe, Arman Boehm, Prateek Saxena and Dawn Song
Published by
comp.nus.edu.sg
Format
Whitepaper
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Steve Hanna, Eui Chul Richard Shin, Devdatta Akhawe, Arman Boehm, Prateek Saxena and Dawn Song, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .