Web Hack List

Collected research

O Single Sign-Off, Where Art Thou? An Empirical Analysis of Single Sign-On Account Hijacking and Session Management on the Web

An empirical study of single sign-on account hijacking: a Facebook cookie hijacking attack gives full account takeover, and further attacks retain long-term control of the relying-party accounts it unlocks, measured across 95 services. Most offer no way to revoke those sessions after a compromise, so the authors propose Single Sign-Off, an OpenID Connect revocation extension.

Record

Researcher
Mohammad Ghasemisharif, Amrutha Ramesh, Stephen Checkoway, Chris Kanich and Jason Polakis
Published by
usenix.org
Topic
Identity

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Mohammad Ghasemisharif, Amrutha Ramesh, Stephen Checkoway, Chris Kanich and Jason Polakis, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .