Discovering Concrete Attacks on Website Authorization by Formal Analysis

Social sign-on and social sharing are becoming an ever more popular feature of web applications. This success is largely due to the APIs and support offered by prominent social networks, such as Facebook, Twitter, and Google, on the basis of new open standards such as the OAuth 2.0 authorization protocol. A formal analysis of these protocols must account for malicious websites and common web application vulnerabilities, such as cross-site request forgery and open redirectors. We model several configurations of the OAuth 2.0 protocol in the applied pi-calculus and verify them using ProVerif. Our models rely on WebSpi, a new library for modeling web applications and web-based attackers that is designed to help discover concrete attacks on websites. Our approach is validated by finding dozens of previously unknown vulnerabilities in popular websites such as Yahoo and WordPress, when they connect to social networks such as Twitter and Facebook.

Data and Resources

Additional Info

Field Value
Source https://inria.hal.science/hal-00815834
Author Bansal, Chetan, Bhargavan, Karthikeyan, Delignat-Lavaud, Antoine, Maffeis, Sergio
Maintainer CCSD
Last Updated May 11, 2026, 09:39 (UTC)
Created May 11, 2026, 09:39 (UTC)
Identifier Report N°: RR-8287
Language en
Rights https://about.hal.science/hal-authorisation-v1/
contributor Microsoft Research [Redmond] ; Microsoft Corporation [Redmond, Wash.]
creator Bansal, Chetan
date 2013-04-11T00:00:00
harvest_object_id e5857b74-5d84-48f2-9dc7-1ecaea4fb4c6
harvest_source_id 3374d638-d20b-4672-ba96-a23232d55657
harvest_source_title test moissonnage SELUNE
metadata_modified 2025-11-11T00:00:00
relation info:eu-repo/grantAgreement//259639/EU/CRYSP: A Novel Framework for Collaboratively Building Cryptographically Secure Programs and their Proofs/CRYSP
set_spec type:REPORT