Semester project, ETH Zürich, Fall 2024
Supervised by Prof. Dr. Kenneth Paterson and Matteo Scarlata
Summary
An analysis of Single Sign-On (SSO) implementations and deployments, focusing on OpenID. We found a pattern of newspaper websites that fail to follow the specification, leading to a vulnerability that allows account hijacking. We also discovered a practical attack against an identity provider library based on a JSON format oracle, leading to complete authentication failure.