Collected research
SSOScan: Automated Testing of Web Applications for Single Sign-On Vulnerabilities
SSOScan automatically signs into a website with Facebook single sign-on, completes registration, then replays and inspects OAuth credentials to test five integration flaws. A scan of 20,000 sites found 345 of the 1,660 that use Facebook SSO vulnerable to impersonation or to credential leakage through referer headers and page content.
Record
- Researcher
- Yuchen Zhou and David Evans
- Published by
- usenix.org
- Topic
- Identity
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Yuchen Zhou and David Evans, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .