Web Hack List

Later archive addition

Automatic Forgery of Cryptographically Consistent Messages to Identify Security Vulnerabilities in Mobile Services

Mobile apps sign, hash or encrypt their API requests, so servers assume a client cannot forge a valid message. AUTOFORGE reverse-engineers how a client builds messages and automatically produces cryptographically consistent ones, letting an attacker brute-force passwords, probe leaked passwords and hijack Facebook access tokens against app backends.

Record

Researcher
Chaoshun Zuo, Wubing Wang, Rui Wang and Zhiqiang Lin
Format
Whitepaper

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Chaoshun Zuo, Wubing Wang, Rui Wang and Zhiqiang Lin, first published at the original source. Preserved copies are kept so the citation survives its host.