Later archive addition
The Emperor's New APIs: On the (In)Secure Usage of New Client-side Primitives
Facebook Connect and Google Friend Connect were reverse engineered from their JavaScript and checked with the Kudzu symbolic execution engine. Neither validated postMessage sender origins and both used targetOrigin '*', giving message injection, arbitrary code execution and man-in-the-middle data theft.
Record
- Researcher
- Steve Hanna, Eui Chul Richard Shin, Devdatta Akhawe, Arman Boehm, Prateek Saxena and Dawn Song
- Format
- Whitepaper
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Steve Hanna, Eui Chul Richard Shin, Devdatta Akhawe, Arman Boehm, Prateek Saxena and Dawn Song, first published at the original source. Preserved copies are kept so the citation survives its host.