Don't Leak Your Keys: Understanding, Measuring, and Exploiting the AppSecret Leaks in Mini-Programs
Yue Zhang, Yuqing Yang, Zhiqiang Lin
摘要
Mobile mini-programs in WeChat have gained significant popularity since their debut in 2017, reaching a scale similar to that of Android apps in the Play Store. Like Google, Tencent, the provider of WeChat, offers APIs to support the development of mini-programs and also maintains a mini-program market within the WeChat app. However, mini-program APIs often manage sensitive user data within the social network platform, both on the WeChat client app and in the cloud. As a result, cryptographic protocols have been implemented to secure data access. In this paper, we demonstrate that WeChat should have required the use of the "appsecret" master key, which is used to authenticate a mini-program, to be used only in the mini-program back-end. If this key is leaked in the front-end of the mini-programs, it can lead to catastrophic attacks on both mini-program developers and users. Using a mini-program crawler and a master key leakage inspector, we measured 3,450,586 crawled mini-programs and found that 40,880 of them had leaked their master keys, allowing attackers to carry out various attacks such as account hijacking, promotion abuse, and service theft. Similar issues were confirmed through testing and measuring of Baidu mini-programs too. We have reported these vulnerabilities and the list of vulnerable mini-programs to Tencent and Baidu, which awarded us with bug bounties, and also Tencent recently released a new API to defend against these attacks based on our findings.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper20
- RIoTFuzzer: Companion App Assisted Remote Fuzzing for Detecting Vulnerabilities in IoT DevicesKaizheng Liu, Ming Yang, Zhen Ling, Yue Zhang 等CCS 2024 · 被引用 8 次
- MiniCAT: Understanding and Detecting Cross-Page Request Forgery Vulnerabilities in Mini-ProgramsZidong Zhang, Qinsheng Hou, Lingyun Ying, Wenrui Diao 等CCS 2024 · 被引用 6 次
- FAMOS: Robust Privacy-Preserving Authentication on Payment Apps via Federated Multi-Modal Contrastive LearningYifeng Cai, Ziqi Zhang, Jiaping Gui, Bingyan Liu 等USENIX Security 2024 · 被引用 6 次
- A First Look at Security and Privacy Risks in the RapidAPI EcosystemSong Liao, Long Cheng, Xiapu Luo, Zheng Song 等CCS 2024 · 被引用 3 次
- Keys on Doormats: Exposed API Credentials on the WebNurullah Demir, Yash Vekaria, Georgios Smaragdakis, Zakir DurumericCCS 2026 · 被引用 2 次
它引用的顶会 Paper12
- How Bad Can It Git? Characterizing Secret Leakage in Public GitHub RepositoriesMichael Meli, Matthew R. McNiece, Bradley ReavesNDSS 2019 · 被引用 130 次
- Why Does Your Data Leak? Uncovering the Data Leakage in Cloud from Mobile AppsChaoshun Zuo, Zhiqiang Lin, Yinqian ZhangS&P 2019 · 被引用 123 次
- Finding Clues for Your Secrets: Semantics-Driven, Learning-Based Privacy Discovery in Mobile AppsYuhong Nan, Zhemin Yang, Xiaofeng Wang, Yuan Zhang 等NDSS 2018 · 被引用 79 次
- API-Misuse Detection Driven by Fine-Grained API-Constraint Knowledge GraphXiaoxue Ren, Xinyuan Ye, Zhenchang Xing, Xin Xia 等ASE 2020 · 被引用 62 次
- Demystifying Resource Management Risks in Emerging Mobile App-in-App EcosystemsHaoran Lu, Luyi Xing, Yue Xiao, Yifan Zhang 等CCS 2020 · 被引用 48 次
相关 Paper
- Mini-Programs, Mega-Problems: Unveiling OAuth-based Authentication Misuses in Mini-Programs via Dynamic AnalysisZidong Zhang, Zhentao Xie, Lingyun Ying, Qinsheng Hou 等CCS 2026
- Taintmini: Detecting Flow of Sensitive Data in Mini-Programs with Static Taint AnalysisChao Wang, Ronny Ko, Yue Zhang, Yuqing Yang 等ICSE 2023 · 被引用 36 次
- Cross Miniapp Request Forgery: Root Causes, Attacks, and Vulnerability DetectionYuqing Yang, Yue Zhang, Zhiqiang LinCCS 2022 · 被引用 29 次
- Characterizing and Detecting Bugs in WeChat Mini-ProgramsTao Wang, Qingxin Xu, Xiaoning Chang, Wensheng Dou 等ICSE 2022 · 被引用 19 次
- Demystifying Cookie Sharing Risks in WebView-based Mobile App-in-app EcosystemsMiao Zhang, Shenao Wang, Guilin Zheng, Yanjie Zhao 等ASE 2025 · 被引用 1 次
