首页> 外文会议>International conference on information technology: new generations >Implementation Vulnerability Associated with OAuth 2.0 -- A Case Study on Dropbox
【24h】

Implementation Vulnerability Associated with OAuth 2.0 -- A Case Study on Dropbox

机译:与OAuth 2.0相关的实现漏洞 - Dropbox的案例研究

获取原文

摘要

Drop box is a cloud based file storage service used by more than 200 million users. Its ability to seamlessly provide cloud storage with minimal user complexity is the key for its wide spread popularity. Despite of its high usability, Drop box has been recently criticized for loose ends in security. Security and usability is not always mutually exclusive, and we believe there is still a lot of room to improve Drop box's security without affecting the unique user experience. In this paper, we present a RAM analysis based method to extract the key security token for account access. In addition, we describe a new technique to bypass authentication and gain unauthorized access to Drop box accounts by using the new tray login feature on the most current Drop box client (v2.4.x). Through these exploits, we demonstrate that most of these security issues are at the level of implementation, rather than design. Finally, we describe potential resolutions that can improve Drop box's security without affecting its high usability.
机译:Drop Box是由200多万用户使用的基于云的文件存储服务。它能够使用最小的用户复杂性无缝提供云存储是其广泛普遍普及的关键。尽管有很高的可用性,最近批评了丢弃盒,以便在安全方面松散。安全性和可用性并不总是相互排斥的,我们相信仍然有很多空间来改善丢弃盒的安全性,而不会影响独特的用户体验。在本文中,我们介绍了基于RAM分析的方法,以提取用于帐户访问的密钥安全令牌。此外,我们描述了一种绕过身份验证的新技术,并通过在最新的丢弃框客户端(v2.4.x)上使用新的纸盘登录功能来获得未经授权访问丢弃框帐户。通过这些漏洞,我们证明了大多数这些安全问题都处于实施的水平,而不是设计。最后,我们描述了可以提高丢弃框的安全性的潜在分辨率,而不会影响其高可用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号