Web Hack List

Collected research

SSOScan: Automated Testing of Web Applications for Single Sign-On Vulnerabilities

SSOScan automatically signs into a website with Facebook single sign-on, completes registration, then replays and inspects OAuth credentials to test five integration flaws. A scan of 20,000 sites found 345 of the 1,660 that use Facebook SSO vulnerable to impersonation or to credential leakage through referer headers and page content.

Record

Researcher
Yuchen Zhou and David Evans
Published by
usenix.org
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Yuchen Zhou and David Evans, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .