首页> 外文会议>International conference on ICT systems security and privacy protection >Revisiting Security Vulnerabilities in Commercial Password Managers
【24h】

Revisiting Security Vulnerabilities in Commercial Password Managers

机译:在商业密码经理中重新审视安全漏洞

获取原文

摘要

In this work we analyse five popular commercial password managers for security vulnerabilities. Our analysis is twofold. First, we compile a list of previously disclosed vulnerabilities through a comprehensive review of the academic and non-academic sources and test each password manager against all the previously disclosed vulnerabilities. We find a mixed picture of fixed and persisting vulnerabilities. Then we carry out systematic functionality tests on the considered password managers and find four new vulnerabilities. Notably, one of the new vulnerabilities we identified allows a malicious app to impersonate a legitimate app to two out of five widely-used password managers we tested and as a result steal the user's password for the targeted service. We implement a proof-of-concept attack to show the feasibility of this vulnerability in a real-life scenario. Finally, we report and reflect on our experience of responsible disclosure of the newly discovered vulnerabilities to the corresponding password manager vendors.
机译:在这项工作中,我们分析了五个受欢迎的商业密码经理,用于安全漏洞。我们的分析是双重的。首先,我们通过全面审查学术和非学术来源的全面审查来编制先前披露的漏洞的列表,并针对所有先前披露的漏洞测试每个密码管理器。我们找到了固定和持久漏洞的混合图片。然后,我们对所考虑的密码管理器进行系统功能测试,并找到四种新漏洞。值得注意的是,我们所识别的新漏洞之一允许恶意应用程序将合法的应用程序模拟到我们测试的五个广泛使用的密码经理中的两个,并且结果窃取用户的目标服务密码。我们实施概念验证攻击,以表明在现实生活场景中的这种漏洞的可行性。最后,我们报告并反思我们对相应的密码经理供应商的新发现漏洞的负责任披露的经验。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号