Shepherd: Enabling Automatic and Large-Scale Login Security Studies

08/02/2018
by   Hugo Jonker, et al.
0

More and more parts of the internet are hidden behind a login field. This poses a barrier to any study predicated on scanning the internet. Moreover, the authentication process itself may be a weak point. To study authentication weaknesses at scale, automated login capabilities are needed. In this work we introduce Shepherd, a scanning framework to automatically log in on websites. The Shepherd framework enables us to perform large-scale scans of post-login aspects of websites. Shepherd scans a website for login fields, attempts to submit credentials and evaluates whether login was successful. We illustrate Shepherd's capabilities by means of a scan for session hijacking susceptibility. In this study, we use a set of unverified website credentials, some of which will be invalid. Using this set, Shepherd is able to fully automatically log in and verify that it is indeed logged in on 6,273 unknown sites, or 12.4 2,579 sites, i.e., 41.4

READ FULL TEXT
research
09/06/2023

Measuring Website Password Creation Policies At Scale

Researchers have extensively explored how password creation policies inf...
research
10/19/2022

Illuminating Large-Scale IPv6 Scanning in the Internet

While scans of the IPv4 space are ubiquitous, today little is known abou...
research
06/15/2021

Snail Mail Beats Email Any Day: On Effective Operator Security Notifications in the Internet

In the era of large-scale internet scanning, misconfigured websites are ...
research
09/14/2021

Image-Based Alignment of 3D Scans

Full 3D scanning can efficiently be obtained using structured light scan...
research
02/02/2023

SSO-Monitor: Fully-Automatic Large-Scale Landscape, Security, and Privacy Analyses of Single Sign-On in the Wild

Single Sign-On (SSO) shifts the crucial authentication process on a webs...
research
01/12/2023

LZR: Identifying Unexpected Internet Services

Internet-wide scanning is a commonly used research technique that has he...
research
01/22/2019

Hidden Treasures - Recycling Large-Scale Internet Measurements to Study the Internet's Control Plane

Internet-wide scans are a common active measurement approach to study th...

Please sign up or login with your details

Forgot password? Click here to reset