首页> 外文会议>IEEE Consumer Communications and Networking Conference >A study of SSL Proxy attacks on Android and iOS mobile applications
【24h】

A study of SSL Proxy attacks on Android and iOS mobile applications

机译:对Android和iOS移动应用程序的SSL代理攻击的研究

获取原文

摘要

According to recent articles in popular technology websites, some mobile applications function in an insecure manner when presented with untrusted SSL certificates. These non-browser based applications seem to, in the absence of a standard way of alerting a user of an SSL error, accept any certificate presented to it. This paper intends to research these claims and show whether or not an invisible proxy based SSL attack can indeed steal user's credentials from mobile applications, and which types applications are most likely to be vulnerable to this attack vector. To ensure coverage of the most popular platforms, applications on both Android 4.2 and iOS 6 are tested. The results of our study showed that stealing credentials is indeed possible using invisible proxy man in the middle attacks.
机译:根据流行技术网站上的最新文章,当某些移动应用程序收到不受信任的SSL证书时,其功能将以不安全的方式运行。这些基于非浏览器的应用程序似乎在没有一种向用户发出SSL错误警报的标准方法的情况下,接受提供给它的任何证书。本文旨在研究这些主张,并表明基于隐形代理的SSL攻击是否确实可以从移动应用程序中窃取用户的凭据,以及哪种类型的应用程序最有可能受到此攻击媒介的攻击。为了确保覆盖最流行的平台,已经对Android 4.2和iOS 6上的应用程序进行了测试。我们的研究结果表明,在中间攻击中使用隐形代理人确实可以窃取凭据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号