Web Hack List

Collected research

WPSE: Fortifying Web Protocols via Browser-Side Security Monitoring

WPSE is a browser-side monitor that enforces the intended message flow plus confidentiality and integrity of a web protocol run, formally proved expressive enough to stop a range of implementation bugs and web attacks. Formalising SAML 2.0 in it exposed a new attack on Google's implementation, and an OAuth 2.0 study found flaws in 55 of 90 sites, some introduced by tracking libraries.

Record

Researcher
Stefano Calzavara, Riccardo Focardi, Matteo Maffei, Clara Schneidewind, Marco Squarcina and Mauro Tempesta
Published by
usenix.org
Topic
Browser

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Stefano Calzavara, Riccardo Focardi, Matteo Maffei, Clara Schneidewind, Marco Squarcina and Mauro Tempesta, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .