The Password Reset MitM Attack
Nethanel Gelernter, Senia Kalma, Bar Magnezi, Hen Porcilan
摘要
We present the password reset MitM (PRMitM) attack and show how it can be used to take over user accounts. The PRMitM attack exploits the similarity of the registration and password reset processes to launch a man in the middle (MitM) attack at the application level. The attacker initiates a password reset process with a website and forwards every challenge to the victim who either wishes to register in the attacking site or to access a particular resource on it. The attack has several variants, including exploitation of a password reset process that relies on the victim's mobile phone, using either SMS or phone call. We evaluated the PRMitM attacks on Google and Facebook users in several experiments, and found that their password reset process is vulnerable to the PRMitM attack. Other websites and some popular mobile applications are vulnerable as well. Although solutions seem trivial in some cases, our experiments show that the straightforward solutions are not as effective as expected. We designed and evaluated two secure password reset processes and evaluated them on users of Google and Facebook. Our results indicate a significant improvement in the security. Since millions of accounts are currently vulnerable to the PRMitM attack, we also present a list of recommendations for implementing and auditing the password reset process.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- Is Real-time Phishing Eliminated with FIDO? Social Engineering Downgrade Attacks against FIDO ProtocolsEnis Ulqinaku, Hala Assal, AbdelRahman Abdou, Sonia Chiasson 等USENIX Security 2021 · 被引用 42 次
- Characterizing Pixel Tracking through the Lens of Disposable Email ServicesHang Hu, Peng Peng, Gang WangS&P 2019 · 被引用 25 次
- A Comparative Long-Term Study of Fallback Authentication SchemesLeona Lassak, Philipp Markert, Maximilian Golla, Elizabeth Stobert 等CHI 2024 · 被引用 7 次
- App's Auto-Login Function Security Testing via Android OS-Level VirtualizationWenna Song, Jiang Ming, Lin Jiang, Han Yan 等ICSE 2021 · 被引用 6 次
- A Mixed-Methods Study on User Experiences and Challenges of Recovery Codes for an End-to-End Encrypted ServiceSandra Höltervennhoff, Noah Wöhler, Arne Möhle, Marten Oltrogge 等USENIX Security 2024 · 被引用 6 次
相关 Paper
- Fine with "1234"? An Analysis of SMS One-Time Password Randomness in Android AppsSiqi Ma, Juanru Li, Hyoungshick Kim, Elisa Bertino 等ICSE 2021 · 被引用 16 次
- "We've Disabled MFA for You": An Evaluation of the Security and Usability of Multi-Factor Authentication Recovery DeploymentsSabrina Amft, Sandra Höltervennhoff, Nicolas Huaman, Alexander Krause 等CCS 2023 · 被引用 14 次
- Client-side Name Collision Vulnerability in the New gTLD Era: A Systematic StudyQi Alfred Chen, Matthew Thomas, Eric Osterweil, Yulong Cao 等CCS 2017 · 被引用 13 次
- Phishing Attacks on Modern AndroidSimone Aonzo, Alessio Merlo, Giulio Tavella, Yanick FratantonioCCS 2018 · 被引用 68 次
- Pre-hijacked accounts: An Empirical Study of Security Failures in User Account Creation on the WebAvinash Sudhodanan, Andrew PaverdUSENIX Security 2022
