Signing into One Billion Mobile App Accounts Effortlessly with OAuth 2 . 0

Signing into One Billion Mobile App Accounts Effortlessly with OAuth 2 . 0
复制标题

DOI:
--
复制
发表时间:
2016
期刊:
--
影响因子:
--
通讯作者:
Ronghai Yang;W. Lau;Tianyu Liu
Ronghai Yang;W. Lau;Tianyu Liu
中科院分区:
其他
文献类型:
--
作者:
Ronghai Yang;W. Lau;Tianyu Liu

文献摘要

被引文献

相似文献

OAuth2.0协议已被主流idp广泛采用,以支持单点登录服务。由于该协议最初是为了满足第三方网站的授权需求而设计的,因此在调整OAuth以支持移动应用程序身份验证时,发现了不同的陷阱。据我们所知,迄今为止发现的所有攻击,包括BlackHat USA ' 16 [3], CCS ' 14[5]和ACSAC ' 15[5],都需要与受害者进行交互,例如通过恶意应用程序或网络窃听等。相反,我们发现了第三方移动应用程序开发人员广泛但不正确地使用OAuth的一种新型方法,攻击者可以远程利用这种方法登录受害者的移动应用程序帐户,而无需受害者参与/意识到受害者。为了证明该漏洞的普遍性和严重影响,我们开发了一个漏洞来检查600个排名靠前的美国和中国Android应用程序的实现,这些应用程序使用了由三个顶级IdPs(即Facebook,谷歌或新浪)提供的基于oauth2.0的身份验证服务。我们的实证结果令人担忧:平均而言,41.21%的应用程序容易受到这种新攻击。我们向受影响的境内流离失所者报告了我们的发现,并以各种方式获得他们的认可/奖励。
OAuth2.0 protocol has been widely adopted by mainstream Identity Providers (IdPs) to support Single-Sign-On service. Since this protocol was originally designed to serve the authorization need for 3rd party websites, different pitfalls have been uncovered when adapting OAuth to support mobile app authentication. To the best of our knowledge, all the attacks discovered so far, including BlackHat USA’16 [3], CCS’14 [2] and ACSAC’15 [5], require to interact with the victim, for example via malicious apps or network eavesdropping, etc. On the contrary, we have discovered a new type of widespread but incorrect usages of OAuth by 3rd party mobile app developers, which can be exploited remotely and solely by the attacker to sign into a victim’s mobile app account without any involvement/ awareness of the victim. To demonstrate the prevalence and severe impact of this vulnerability, we have developed an exploit to examine the implementations of 600 top-ranked US and Chinese Android Apps which use the OAuth2.0-based authentication service provided by three top-tier IdPs, namely Facebook, Google or Sina. Our empirical results are alarming: on average, 41.21% of these apps are vulnerable to this new attack. We have reported our findings to the affected IdPs, and received their acknowledgements/ rewards in various ways.