Truncating TLS connections to violate beliefs in web applications

  • Authors:
  • Ben Smyth;Alfredo Pironti

  • Affiliations:
  • INRIA Paris-Rocquencourt, Paris, France;INRIA Paris-Rocquencourt, Paris, France

  • Venue:
  • WOOT'13 Proceedings of the 7th USENIX conference on Offensive Technologies
  • Year:
  • 2013

Quantified Score

Hi-index 0.00

Visualization

Abstract

We identify logical web application flaws which can be exploited by TLS truncation attacks to desynchronize the user- and server-perspective of an application's state. It follows immediately that servers may make false assumptions about users, hence, the flaw constitutes a security vulnerability. Moreover, in the context of authentication systems, we exploit the vulnerability to launch the following practical attacks: we exploit the Helios electronic voting system to cast votes on behalf of honest voters, take full control of Microsoft Live accounts, and gain temporary access to Google accounts.