Social sign-on and social sharing are becoming an ever more popular fea-ture of web applications. This success is largely due to the APIs and support offered by prominent social networks, such as Facebook, Twitter, and Google, on the basis of new open standards such as the OAuth 2.0 authorization protocol. A formal analysis of these protocols must account for malicious websites and common web application vulnerabilities, such as cross-site re-quest forgery and open redirectors. We model several configurations of the OAuth 2.0 protocol in the applied pi-calculus and verify them using ProVerif. Our models rely on WebSpi, a new library for modeling web applications and web-based attackers that is designed to help discover concrete attacks on w...
Millions of web users today employ their Facebook accounts to sign into more than one million relyin...
Abstract — As social websites get more and more users across internet, Cross Site Scripting is becom...
We present WPSE, a browser-side security monitor for web protocols designed to ensure compliance wit...
Abstract—Social sign-on and social sharing are becoming an ever more popular feature of web applicat...
Abstract—Social sign-on and social sharing are becoming an ever more popular feature of web applicat...
International audienceSocial sign-on and social sharing are becoming an ever more popular feature of...
International audienceSocial sign-on and social sharing are becoming an ever more popular feature of...
As attacks on web applications get more sophisticated, browser manufactur-ers, application developer...
Implementation errors are commonly found in modern web applications. They can be caused by a multitu...
Social sign-on and social sharing are becoming an ever more popular feature of web applications. Thi...
Modern web applications often rely on third-party services to provide their functionality to users. ...
Modern web applications often rely on third-party services to provide their functionality to users. ...
Millions of web users today employ their Facebook accounts to sign into more than one million relyin...
Web applications allow users to receive and communicate content from remote servers through web brow...
Web applications allow users to receive and communicate content from remote servers through web brow...
Millions of web users today employ their Facebook accounts to sign into more than one million relyin...
Abstract — As social websites get more and more users across internet, Cross Site Scripting is becom...
We present WPSE, a browser-side security monitor for web protocols designed to ensure compliance wit...
Abstract—Social sign-on and social sharing are becoming an ever more popular feature of web applicat...
Abstract—Social sign-on and social sharing are becoming an ever more popular feature of web applicat...
International audienceSocial sign-on and social sharing are becoming an ever more popular feature of...
International audienceSocial sign-on and social sharing are becoming an ever more popular feature of...
As attacks on web applications get more sophisticated, browser manufactur-ers, application developer...
Implementation errors are commonly found in modern web applications. They can be caused by a multitu...
Social sign-on and social sharing are becoming an ever more popular feature of web applications. Thi...
Modern web applications often rely on third-party services to provide their functionality to users. ...
Modern web applications often rely on third-party services to provide their functionality to users. ...
Millions of web users today employ their Facebook accounts to sign into more than one million relyin...
Web applications allow users to receive and communicate content from remote servers through web brow...
Web applications allow users to receive and communicate content from remote servers through web brow...
Millions of web users today employ their Facebook accounts to sign into more than one million relyin...
Abstract — As social websites get more and more users across internet, Cross Site Scripting is becom...
We present WPSE, a browser-side security monitor for web protocols designed to ensure compliance wit...