论文部分内容阅读
分析了OAuth 2.0协议中两大主流模式的安全机制和实现过程,给出了针对协议中部分敏感数据的威胁模型,针对协议部署过程中常见的安全漏洞提出了访问令牌注入攻击以及针对授权码注入的CSRF攻击的攻击路线,并对若干网站进行测试,结果显示攻击效果良好,验证了攻击方法的有效性,最后提出了相应的防范策略.
The security mechanism and implementation process of the two main modes in OAuth 2.0 protocol are analyzed. The threat model for some sensitive data in the protocol is given. An access token injection attack is proposed for common security vulnerabilities in the protocol deployment. Injected CSRF attack attack route, and tested a number of websites, the results show that the attack effect is good, verify the effectiveness of the attack method, and finally put forward the corresponding preventive strategy.