arrow
返回

Practical attacks on Login CSRF in OAuth

delete2022-10-01
delete5
PRE
AI
E
Elham Arshad *
M
Michele Benolli
B
Bruno Crispo
DOI:10.1016/j.cose.2022.102859delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
OAuth 2.0 is an important and well studied protocol. However, despite the presence of guidelines and best practices, the current implementations are still vulnerable and error-prone. This research mainly focused on the Cross-Site Request Forgery (CSRF) attack. This attack is one of the dangerous vulnerabilities in OAuth protocol, which has been mitigated through state parameter. However, despite the presence of this parameter in the OAuth deployment, many websites are still vulnerable to the OAuth-CSRF (OCSRF) attack. We studied one of the most recurrent type of OCSRF attack through a variety range of novel attack strategies based on different possible implementation weaknesses and the state of the victim's browser at the time of the attack. In order to validate them, we designed a repeatable methodology and conducted a large-scale analysis on 395 high-ranked sites to assess the prevalence of OCSRF vulnerabilities. Our automated crawler discovered about 36% of targeted sites are still vulnerable and detected about 20% more well-hidden vulnerable sites utilizing the novel attack strategies. Based on our experiment, there was a significant rise in the number of OCSRF protection compared to the past scale analyses and yet over 25% of sites are exploitable to at least one proposed attack strategy. Despite a standard countermeasure exists to mitigate the OCSRF, our study shows that lack of awareness about implementation mistakes is an important reason for a significant number of vulnerable sites.(c) 2022 Elsevier Ltd. All rights reserved.
Keyword:
OAuth
OpenID Connect
Request Forgery
CSRF
Login CSRF
state parameter
Custom HTTP Headers

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

U
University of Trento
学者数:
8.8K
论文数: 9.0K
被引数: 1.2W
引用论文

引用论文

err
IF0
err
err0
PREAI
err
err分享
err收藏