首页> 外文会议>International conference on information technology: new generations >Implementation Vulnerability Associated with OAuth 2.0 -- A Case Study on Dropbox
【24h】

Implementation Vulnerability Associated with OAuth 2.0 -- A Case Study on Dropbox

机译:与OAuth 2.0相关的实施漏洞-以Dropbox为例

获取原文

摘要

Drop box is a cloud based file storage service used by more than 200 million users. Its ability to seamlessly provide cloud storage with minimal user complexity is the key for its wide spread popularity. Despite of its high usability, Drop box has been recently criticized for loose ends in security. Security and usability is not always mutually exclusive, and we believe there is still a lot of room to improve Drop box's security without affecting the unique user experience. In this paper, we present a RAM analysis based method to extract the key security token for account access. In addition, we describe a new technique to bypass authentication and gain unauthorized access to Drop box accounts by using the new tray login feature on the most current Drop box client (v2.4.x). Through these exploits, we demonstrate that most of these security issues are at the level of implementation, rather than design. Finally, we describe potential resolutions that can improve Drop box's security without affecting its high usability.
机译:投递箱是一种基于云的文件存储服务,已有超过2亿用户使用。它能够以最少的用户复杂性无缝提供云存储的能力是其广泛普及的关键。尽管具有很高的可用性,但Drop Box最近因安全方面的松懈而受到批评。安全性和可用性并不总是相互排斥的,我们认为在不影响独特用户体验的情况下,仍有很多空间可以改善Dropbox的安全性。在本文中,我们提出了一种基于RAM分析的方法来提取用于帐户访问的密钥安全令牌。此外,我们介绍了一种新技术,可通过使用最新的保管箱客户端(v2.4.x)上的新托盘登录功能来绕过身份验证并获得对保管箱帐户的未经授权的访问。通过这些漏洞,我们证明了大多数安全问题都在实现级别上,而不是设计级别上。最后,我们描述了可能的解决方案,这些解决方案可以提高Dropbox的安全性而又不影响其高可用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号