The Password Reset MitM Attack
Nethanel Gelernter, Senia Kalma, Bar Magnezi, Hen Porcilan
Abstract
We present the password reset MitM (PRMitM) attack and show how it can be used to take over user accounts. The PRMitM attack exploits the similarity of the registration and password reset processes to launch a man in the middle (MitM) attack at the application level. The attacker initiates a password reset process with a website and forwards every challenge to the victim who either wishes to register in the attacking site or to access a particular resource on it. The attack has several variants, including exploitation of a password reset process that relies on the victim's mobile phone, using either SMS or phone call. We evaluated the PRMitM attacks on Google and Facebook users in several experiments, and found that their password reset process is vulnerable to the PRMitM attack. Other websites and some popular mobile applications are vulnerable as well. Although solutions seem trivial in some cases, our experiments show that the straightforward solutions are not as effective as expected. We designed and evaluated two secure password reset processes and evaluated them on users of Google and Facebook. Our results indicate a significant improvement in the security. Since millions of accounts are currently vulnerable to the PRMitM attack, we also present a list of recommendations for implementing and auditing the password reset process.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers6
- Is Real-time Phishing Eliminated with FIDO? Social Engineering Downgrade Attacks against FIDO ProtocolsEnis Ulqinaku, Hala Assal, AbdelRahman Abdou, Sonia Chiasson et al.USENIX Security 2021 · 42 citations
- Characterizing Pixel Tracking through the Lens of Disposable Email ServicesHang Hu, Peng Peng, Gang WangS&P 2019 · 25 citations
- A Comparative Long-Term Study of Fallback Authentication SchemesLeona Lassak, Philipp Markert, Maximilian Golla, Elizabeth Stobert et al.CHI 2024 · 7 citations
- App's Auto-Login Function Security Testing via Android OS-Level VirtualizationWenna Song, Jiang Ming, Lin Jiang, Han Yan et al.ICSE 2021 · 6 citations
- A Mixed-Methods Study on User Experiences and Challenges of Recovery Codes for an End-to-End Encrypted ServiceSandra Höltervennhoff, Noah Wöhler, Arne Möhle, Marten Oltrogge et al.USENIX Security 2024 · 6 citations
Related papers
- Fine with "1234"? An Analysis of SMS One-Time Password Randomness in Android AppsSiqi Ma, Juanru Li, Hyoungshick Kim, Elisa Bertino et al.ICSE 2021 · 16 citations
- "We've Disabled MFA for You": An Evaluation of the Security and Usability of Multi-Factor Authentication Recovery DeploymentsSabrina Amft, Sandra Höltervennhoff, Nicolas Huaman, Alexander Krause et al.CCS 2023 · 14 citations
- Client-side Name Collision Vulnerability in the New gTLD Era: A Systematic StudyQi Alfred Chen, Matthew Thomas, Eric Osterweil, Yulong Cao et al.CCS 2017 · 13 citations
- Phishing Attacks on Modern AndroidSimone Aonzo, Alessio Merlo, Giulio Tavella, Yanick FratantonioCCS 2018 · 68 citations
- Pre-hijacked accounts: An Empirical Study of Security Failures in User Account Creation on the WebAvinash Sudhodanan, Andrew PaverdUSENIX Security 2022
