【24h】

Vulnerabilities through Usability Pitfalls in Cloud Services: Security Problems due to Unverified Email Addresses

机译:云服务中由于易失性漏洞而导致的漏洞:电子邮件地址未验证导致的安全问题

获取原文
获取原文并翻译 | 示例

摘要

Cloud storage services become increasingly interesting for users to easily backup or synchronize their data. On top of this basic functionality, these services offer functions for collaboration that allow users to share their files with selected other persons in a user-friendly way. We have identified that several cloud storage services do not verify whether the registrating customer is the real owner of the email address entered during the registration. Cloud providers omit the verification for reasons of usability. Here, user-friendliness goes too far at the cost of security. This vulnerability combined with collaboration functions allows attacks on cloud customers. In this paper, we explain which attacks are possible. Missing email verification and collaboration functions allow espionage and malware distribution attacks. Execution is very easy, i.e., they can be done without coding expertise or special tools.
机译:云存储服务对于用户轻松备份或同步其数据变得越来越有趣。除了此基本功能之外,这些服务还提供了协作功能,允许用户以用户友好的方式与选定的其他人共享文件。我们已经确定,几个云存储服务无法验证注册客户是否是注册过程中输入的电子邮件地址的真实所有者。云提供商出于可用性的原因而忽略了验证。在此,用户友好性以牺牲安全性为代价。此漏洞与协作功能结合在一起,可以攻击云客户。在本文中,我们解释了哪些攻击是可能的。缺少电子邮件验证和协作功能会导致间谍活动和恶意软件分发攻击。执行非常容易,即无需编码专业知识或特殊工具即可完成执行。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号