Web Hack List

Collected research

Vetting Single Sign-On SDK Implementations via Symbolic Reasoning

S3KVetter models Single Sign-On SDKs symbolically and tests them for logical correctness rather than for crashes. Applied to ten widely deployed SSO SDKs it found seven classes of logic flaw, four previously unknown, enabling anything from tracking a user's activity to hijacking their account.

Record

Researcher
Ronghai Yang, Wing Cheong Lau, Jiongyi Chen and Kehuan Zhang
Published by
usenix.org
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Ronghai Yang, Wing Cheong Lau, Jiongyi Chen and Kehuan Zhang, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .