Web Hack List

Collected research

Signing Me onto Your Accounts through Facebook and Google

A black-box field study of deployed web SSO: the authors capture browser-relayed messages between relying party and identity provider, label each element's semantics and what an adversary can read or write, then follow the openings to working exploits. Eight logic flaws let an attacker sign in as the victim on Google ID/OpenID RPs, Facebook Connect, JanRain, Freelancer, Sears and FarmVille.

Record

Researcher
Rui Wang, Shuo Chen and XiaoFeng Wang
Published by
ieee-security.org
Format
Whitepaper
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Rui Wang, Shuo Chen and XiaoFeng Wang, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .