Web Hack List

Later archive addition

Pre-hijacked Accounts: An Empirical Study of Security Failures in User Account Creation on the Web

Account pre-hijacking: an attacker knowing only a victim's email address creates or primes an account at a service before the victim signs up, then regains access after the victim registers or recovers it. Five variants abuse the interaction of classic passwords with federated sign-in; 35 of 75 popular services tested were vulnerable, often invisibly to the victim.

Record

Researcher
Avinash Sudhodanan and Andrew Paverd
Published by
arXiv.org

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Avinash Sudhodanan and Andrew Paverd, first published at the original source. Preserved copies are kept so the citation survives its host.