TAILIEUCHUNG - Flickr's API Signature Forgery Vulnerability

1. Vulnerability Description Flickr is almost certainly the best online photo management and sharing application in the world. As of June 2009, it claims to host more than billion images. In order to allow independent programmers to expand its services, Flickr offers a fairly comprehensive web-service API that allows programmers to create applications that can perform almost any function a user on the Flickr site can do. The Flickr's API consists of a set of callable methods, and some API endpoints. To perform an action using the Flickr's API, you need to select a calling convention, send a request to. | Flickr s API Signature Forgery Vulnerability Thai Duong and Juliano Rizzo Date Published Sep. 28 2009 Advisory ID MOCB-01 Advisory URL http research Title Flickr s API Signature Forgery Vulnerability Remotely Exploitable Yes 1. Vulnerability Description Flickr is almost certainly the best online photo management and sharing application in the world. As of June 2009 it claims to host more than billion images. In order to allow independent programmers to expand its services Flickr offers a fairly comprehensive web-service API that allows programmers to create applications that can perform almost any function a user on the Flickr site can do. The Flickr s API consists of a set of callable methods and some API endpoints. To perform an action using the Flickr s API you need to select a calling convention send a request to its endpoint specifying a method and some arguments and will receive a formatted response. Many methods require the user to be logged in. At present there is only one way to accomplish this. Users should be authenticated using the Flickr Authentication API. Any applications wishing to use the Flickr Authentication API must have already obtained a Flickr s API Key. An 8-byte long shared secret for the API Key is then issued by Flickr and cannot be changed by the users. This secret is used in the signing process which is required for all API calls using an authentication token. In addition calls to the . methods and login URLs pointing to the auth page on Flickr must also be signed. For more details please read the Flickr Authentication API Spec 1 . This advisory describes a vulnerability in the signing process that allows an attacker to generate valid signatures without knowing the shared secret. By exploiting this vulnerability an attacker can send valid arbitrary requests on behalf of any application using Flickr s API. When combined with other vulnerabilities and attacks an attacker can .

TỪ KHÓA LIÊN QUAN
TAILIEUCHUNG - Chia sẻ tài liệu không giới hạn
Địa chỉ : 444 Hoang Hoa Tham, Hanoi, Viet Nam
Website : tailieuchung.com
Email : tailieuchung20@gmail.com
Tailieuchung.com là thư viện tài liệu trực tuyến, nơi chia sẽ trao đổi hàng triệu tài liệu như luận văn đồ án, sách, giáo trình, đề thi.
Chúng tôi không chịu trách nhiệm liên quan đến các vấn đề bản quyền nội dung tài liệu được thành viên tự nguyện đăng tải lên, nếu phát hiện thấy tài liệu xấu hoặc tài liệu có bản quyền xin hãy email cho chúng tôi.
Đã phát hiện trình chặn quảng cáo AdBlock
Trang web này phụ thuộc vào doanh thu từ số lần hiển thị quảng cáo để tồn tại. Vui lòng tắt trình chặn quảng cáo của bạn hoặc tạm dừng tính năng chặn quảng cáo cho trang web này.