key: 2014-truncation-attacks-to-violate-beliefs type: techreport title: Truncating TLS Connections to Violate Beliefs in Web Applications authors: - Ben Smyth - Alfredo Pironti year: 2015 number: hal-01102013 institution: INRIA description: >- We identify logic flaws to: cast votes on behalf of honest voters in e-voting, take full control of Microsoft accounts, and temporary access to Google accounts. keywords: >- attack, exploit, vulnerability, Google, Gmail, YouTube, Hotmail, Microsoft, Live, Helios, logic flaw, sign-out, single-sign-on, TLS truncation, web application abstract: >-
We identify logical web application flaws which can be exploited by TLS truncation attacks to desynchronize the user- and server-perspective of an application's state. It follows immediately that servers may make false assumptions about users, hence, the flaw constitutes a security vulnerability. Moreover, in the context of authentication systems, we exploit the vulnerability to launch the following practical attacks: we exploit the Helios electronic voting system to cast votes on behalf of honest voters, take full control of Microsoft Live accounts, and gain temporary access to Google accounts.
Update (October 18, 2014). This technical report revisits our earlier work (2013) and shows that Google remain vulnerable to the attacks that we disclosed.
extra: "Our contribution has been acknowledged in Google's Hall of Fame and\n\t\t\tMicrosoft's Security Researcher Acknowledgements.\n\t\t
\n\n\t\t\n\t\t\tThis article has been discussed by The Register (local cache) and Spiegel Online (local cache).\n\t\t
\n\n\t\tOur Black Hat talk and videos demonstrating our attacks against \n\t\t\tGoogle,\n\t\t\tHelios \n\t\t\tand Microsoft are available on YouTube:\t\t\n\t\t
\n\n\t\t\n\t\t\n\t\t\n\t\t\n" links: - file: Smyth14-truncation-attacks-to-violate-beliefs.pdf text: Technical Report alt: url: https://hal.inria.fr/hal-01102013 text: INRIA Archive version