Collected research
The Emperor's New APIs: On the (In)Secure Usage of New Client-side Primitives
Facebook Connect and Google Friend Connect were reverse engineered from their JavaScript and checked with the Kudzu symbolic execution engine. Neither validated postMessage sender origins and both used targetOrigin '*', giving message injection, arbitrary code execution and man-in-the-middle data theft.
Record
- Researcher
- Steve Hanna, Eui Chul Richard Shin, Devdatta Akhawe, Arman Boehm, Prateek Saxena and Dawn Song
- Published by
- comp.nus.edu.sg
- Format
- Whitepaper
- Topic
- Browser
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Steve Hanna, Eui Chul Richard Shin, Devdatta Akhawe, Arman Boehm, Prateek Saxena and Dawn Song, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .