@inproceedings{Smyth13-truncation-attacks-to-violate-beliefs, author = {Ben Smyth and Alfredo Pironti}, title = {{Truncating TLS Connections to Violate Beliefs in Web Applications}}, booktitle = {WOOT'13: 7th USENIX Workshop on Offensive Technologies}, year = {2013}, month = {June}, publisher = {USENIX Association}, url = {https://publications.bensmyth.com/2013-truncation-attacks-to-violate-beliefs/}, url-pdf = {https://publications.bensmyth.com/files/Smyth13-truncation-attacks-to-violate-beliefs.pdf}, url-bib = {https://publications.bensmyth.com/files/Smyth13-truncation-attacks-to-violate-beliefs.bib}, url-yaml = {https://publications.bensmyth.com/files/Smyth13-truncation-attacks-to-violate-beliefs.yml}, url-md = {https://publications.bensmyth.com/files/Smyth13-truncation-attacks-to-violate-beliefs.md}, note = {(First appeared at Black Hat USA 2013.)}, keywords = {attack, exploit, vulnerability, Google, Gmail, YouTube, Hotmail, Microsoft, Live, Helios, logic flaw, sign-out, single-sign-on, TLS truncation, web application}, abstract = {We identify logical web application flaws which can be exploited by TLS truncation attacks to desynchronize the user- and server-perspective of an application's state. It follows immediately that servers may make false assumptions about users, hence, the flaw constitutes a security vulnerability. Moreover, in the context of authentication systems, we exploit the vulnerability to launch the following practical attacks: we exploit the Helios electronic voting system to cast votes on behalf of honest voters, take full control of Microsoft Live accounts, and gain temporary access to Google accounts.} }