Automatic Forgery of Cryptographically Consistent Messages to Identify Security Vulnerabilities in Mobile Services
Chaoshun Zuo, Wubing Wang, Zhiqiang Lin, Rui Wang
Abstract
Most mobile apps today require access to remote services, and many of them also require users to be authenticated in order to use their services. To ensure the security between the client app and the remote service, app developers often use cryptographic mechanisms such as encryption (e.g., HTTPS), hashing (e.g., MD5, SHA1), and signing (e.g., HMAC) to ensure the confidentiality and integrity of the network messages. However, these cryptographic mechanisms can only protect the communication security, and server-side checks are still needed because malicious clients owned by attackers can generate any messages they wish. As a result, incorrect or missing server side checks can lead to severe security vulnerabilities including password brute-forcing, leaked password probing, and security access token hijacking. To demonstrate such a threat, we present AUTOFORGE, a tool that can automatically forge valid request messages from the client side to test whether the server side of an app has ensured the security of user accounts with sufficient checks. To enable these security tests, a fundamental challenge lies in how to forge a valid cryptographically consistent message such that it can be consumed by the server. We have addressed this challenge with a set of systematic techniques, and applied them to test the server side implementation of 76 popular mobile apps (each of which has over 1,000,000 installs). Our experimental results show that among these apps, 65 (86%) of their servers are vulnerable to password brute-forcing attacks, all (100%) are vulnerable to leaked password probing attacks, and 9 (12%) are vulnerable to Facebook access token hijacking attacks. Permission to freely reproduce all or part of this paper for noncommercial purposes is granted provided that copies bear this notice and the full citation on the first page. Reproduction for commercial purposes is strictly prohibited without the prior written consent of the Internet Society, the first-named author (for reproduction of an entire paper only), and the author's employer if the paper was prepared within the scope of employment.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 202fffb3-6ad4-4e03-bb37-37a0614e61e5Cited by top-tier papers13
- SoK: Security Evaluation of Home-Based IoT DeploymentsOmar Alrawi, Chaz Lever, Manos Antonakakis, Fabian MonroseS&P 2019 · 411 citations
- IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based FuzzingJiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo et al.NDSS 2018 · 311 citations
- Obfuscation-Resilient Privacy Leak Detection for Mobile Apps Through Differential AnalysisAndrea Continella, Yanick Fratantonio, Martina Lindorfer, Alessandro Puccetti et al.NDSS 2017 · 131 citations
- Why Does Your Data Leak? Uncovering the Data Leakage in Cloud from Mobile AppsChaoshun Zuo, Zhiqiang Lin, Yinqian ZhangS&P 2019 · 123 citations
- Automatic Fingerprinting of Vulnerable BLE IoT Devices with Static UUIDs from Mobile AppsChaoshun Zuo, Haohuang Wen, Zhiqiang Lin, Yinqian ZhangCCS 2019 · 77 citations
Related papers
- Cross Miniapp Request Forgery: Root Causes, Attacks, and Vulnerability DetectionYuqing Yang, Yue Zhang, Zhiqiang LinCCS 2022 · 29 citations
- Vault Raider: Stealthy UI-based Attacks Against Password Managers in Desktop EnvironmentsAndrea Infantino, Mir Masood Ali, Kostas Solomos, Jason PolakisNDSS 2026 · 1 citation
- AUTHSCOPE: Towards Automatic Discovery of Vulnerable Authorizations in Online ServicesChaoshun Zuo, Qingchuan Zhao, Zhiqiang LinCCS 2017 · 59 citations
- The Cookie Hunter: Automated Black-box Auditing for Web Authentication and Authorization FlawsKostas Drakonakis, Sotiris Ioannidis, Jason PolakisCCS 2020 · 56 citations
- Automatic Insecurity: Exploring Email Auto-configuration in the WildShushang Wen, Yiming Zhang, Yuxiang Shen, Bingyu Li et al.NDSS 2025
