{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,12]],"date-time":"2026-05-12T18:04:43Z","timestamp":1778609083860,"version":"3.51.4"},"reference-count":54,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,5,14]],"date-time":"2025-05-14T00:00:00Z","timestamp":1747180800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,5,14]],"date-time":"2025-05-14T00:00:00Z","timestamp":1747180800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"Universit\u00e0 degli Studi di Bari Aldo Moro"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Comput Virol Hack Tech"],"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>In our modern digital landscape, web browsers play a crucial role as gateways to large amounts of information and services. However, recent developments have demonstrated that the very features that make browsing convenient and seamless can be exploited by malicious actors through a potent threat vector known as the \u201cBrowser-in-the-Middle\u201d (BitM) attack. Most of the Multi-Factor Authen- tication (MFA) security measures are shown to be ineffective to prevent BitM attacks. However, the FIDO2 Project that includes CTAP2 protocol that works together with the Web Authentication API (WebAuthn API) has been proven to be a virtually unattackable MFA method by current state-of-the-art BitM implementations. At least until now. This work expands the range of applica- ble scenarios where BitM attack can be used by taking its technical architecture a step further: we show how the effectiveness of BitM\u2014used along a Reflected XSS vulnerability exploitation\u2014can be improved resulting in the novel BitM\u2009+\u2009attack that proves to be capable of defeating any available MFA method includ- ing FIDO2\/WebAuthn solutions that rely on hardware dongles and represent the only method of authentication that went undefeated by virtually any phishing attack approach to date.<\/jats:p>","DOI":"10.1007\/s11416-025-00556-2","type":"journal-article","created":{"date-parts":[[2025,5,14]],"date-time":"2025-05-14T06:31:03Z","timestamp":1747204263000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Defeating FIDO2\/CTAP2\/WebAuthn using browser in the middle and reflected cross site scripting"],"prefix":"10.1007","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4038-2317","authenticated-orcid":false,"given":"Christian","family":"Catalano","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andrea","family":"Chezzi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0163-6786","authenticated-orcid":false,"given":"Vita Santa","family":"Barletta","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2419-7381","authenticated-orcid":false,"given":"Franco","family":"Tommasi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,5,14]]},"reference":[{"key":"556_CR1","unstructured":"Cyber security threat trends. (2021). https:\/\/ learn-cloudsecurity.cisco.com\/umbrella-resources\/umbrella\/2021-cyber-security-threat-trends-phishing-crypto-top-the-list"},{"key":"556_CR2","doi-asserted-by":"publisher","unstructured":"Sharma, A.K., Galav, R.K., Sharma, B.: A comprehensive survey of various cyber attacks. In: 2023 6th International Conference on Information Systems and Com- puter Networks (ISCON), pp. 1\u20134 (2023). https:\/\/doi.org\/10.1109\/ISCON57294.2023.10111998","DOI":"10.1109\/ISCON57294.2023.10111998"},{"key":"556_CR3","unstructured":"Patat, G., Sabt, M.: Please Remember Me: Security Analysis of U2F Remember Me Implementations in The Wild (2020). idHAL:hal-02865105"},{"key":"556_CR4","unstructured":"Ulqinaku, E., Assal, H., Abdou, A., Chiasson, S., Capkun, S.: Is Real-time Phish- ing Eliminated with FIDO? Social Engineering Downgrade Attacks against FIDO Protocols. Proceedings of the 30th USENIX Security Symposium (2021)"},{"key":"556_CR5","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4842-2601-8","volume-title":"Securing the Perimeter: Deploying Identity and Access Management with Free Open Source Software","author":"M Schwartz","year":"2018","unstructured":"Schwartz, M., Machulak, M.: Securing the Perimeter: Deploying Identity and Access Management with Free Open Source Software. Apress, Berkeley, CA (2018). https:\/\/doi.org\/10.1007\/978-1-4842-2601-8"},{"key":"556_CR6","unstructured":"Alliance, F.: Certification overview. (2022). https:\/\/fidoalliance.org\/ certification\/"},{"key":"556_CR7","unstructured":"Microsoft: Microsoft digital defense report. (2022). https:\/\/query.prod.cms. rt.microsoft.com\/cms\/api\/am\/binary\/RE5bUvv,https:\/\/query.prod.cms.rt.microsoft.com\/cms\/api\/am\/binary\/RE5bUvv"},{"issue":"6","key":"556_CR8","doi-asserted-by":"publisher","first-page":"455","DOI":"10.1080\/1043859042000304070","volume":"14","author":"Z M\u2019Chirgui","year":"2005","unstructured":"M\u2019Chirgui, Z.: The economics of the smart card industry: Towardscoopetitive strategies. Econ. Innov. New Technol. 14(6), 455\u2013477 (2005)","journal-title":"Econ. Innov. New Technol."},{"issue":"2","key":"556_CR9","doi-asserted-by":"publisher","first-page":"179","DOI":"10.1007\/s10207-021-00548-5","volume":"21","author":"F Tommasi","year":"2021","unstructured":"Tommasi, F., Catalano, C., Taurino, I.: Browser-in-the-Middle (BitM) attack. Int. J. Inf. Secur. 21(2), 179\u2013189 (2021). https:\/\/doi.org\/10.1007\/s10207-021-00548-5","journal-title":"Int. J. Inf. Secur."},{"issue":"1","key":"556_CR10","doi-asserted-by":"publisher","first-page":"27","DOI":"10.1007\/s11416-023-00484-z","volume":"20","author":"C Catalano","year":"2023","unstructured":"Catalano, C., Tommasi, F.: Persistent MobileApp-in-the-Middle (MAitM) attack. J. Comput. Virol. Hack. Tech. 20(1), 27\u201339 (2023). https:\/\/doi.org\/10.1007\/s11416-023-00484-z","journal-title":"J. Comput. Virol. Hack. Tech."},{"key":"556_CR11","doi-asserted-by":"crossref","unstructured":"Kepkowski, M., Machulak, M., Wood, I., Kaafar, D.: Challenges with Passwordless FIDO2 in an enterprise setting: a usability study (2023). arXiv:2308.08096v2","DOI":"10.1109\/SecDev56634.2023.00017"},{"key":"556_CR12","unstructured":"Client to authenticator protocol (ctap). (2021). https:\/\/fidoalliance.org\/specs\/fido-v2.1-ps-20210615\/fido-client-to-authenticator-protocol-v2.1-ps-20210615. html"},{"key":"556_CR13","unstructured":"W3C: Web authentication: An api for accessing public key credentials level 2. https:\/\/www.w3.org\/TR\/webauthn-2\/"},{"key":"556_CR14","unstructured":"Web authentication: An api for accessing public key credentials level 2. (2022). https:\/\/www.w3.org\/TR\/webauthn-2\/"},{"key":"556_CR15","unstructured":"Google: Chromium project. https:\/\/www.chromium.org\/Home\/"},{"key":"556_CR16","unstructured":"Yubico: Yubico product documentation. https:\/\/docs.yubico.com\/"},{"key":"556_CR17","unstructured":"Feitian: Documentation resources. https:\/\/www.ftsafe.com\/Support\/Resources"},{"key":"556_CR18","doi-asserted-by":"publisher","unstructured":"Tzschoppe, J., L\u00a8ohr, H.: Browser-in-the-Middle - Evaluation of a modern approach to phishing. EUROSEC \u201923: Proceedings of the 16th European Work- shop on System Security (2023). https:\/\/doi.org\/10.1145\/3578357.3589458","DOI":"10.1145\/3578357.3589458"},{"issue":"5","key":"556_CR19","doi-asserted-by":"publisher","first-page":"410","DOI":"10.1002\/spy2.410","volume":"7","author":"RO Jagannath","year":"2024","unstructured":"Jagannath, R.O., Jain, A.K.: Browser-in-the-middle attacks: a comprehensive analysis and countermeasures. Sec. Privacy 7(5), 410 (2024)","journal-title":"Sec. Privacy"},{"key":"556_CR20","unstructured":"Corinto, A.D.: Tre ricercatori italiani hanno scoperto come neutralizzare l\u2019autenticazione a due fattori. (2022)"},{"key":"556_CR21","unstructured":"Browser-in-the-middle buca anche l\u2019autenticazione a due fattori. (2022). https:\/\/www.securityopenlab.it\/news\/2016\/ browser-in-the-middle-buca-anche-lautenticazione-a-due-fattori.html"},{"key":"556_CR22","unstructured":"Capec-701: Browser in the middle (bitm). (2023). https:\/\/capec.mitre.org\/data\/ definitions\/701.html"},{"key":"556_CR23","unstructured":"MITRE: Mitre web reference. https:\/\/attack.mitre.org\/"},{"key":"556_CR24","doi-asserted-by":"publisher","unstructured":"Schwartz, M., Machulak, M.: Securing the perimeter - Deploying Identity and Access Management with Free Open Source Software (Chapter 7: Strong Authen- tication). Apress Berkeley, CA, 231\u2013265 (2018). https:\/\/doi.org\/10.1007\/978-1-4842\u20132601\u20138","DOI":"10.1007\/978-1"},{"issue":"4","key":"556_CR25","doi-asserted-by":"publisher","first-page":"333","DOI":"10.1007\/s11416-022-00420-7","volume":"18","author":"F Tommasi","year":"2022","unstructured":"Tommasi, F., Catalano, C., Corvaglia, U., Taurino, I.: MinerAlert: an hybrid approach for web mining detection. J. Comput. Virol. Hacking Tech. 18(4), 333\u2013346 (2022). https:\/\/doi.org\/10.1007\/s11416-022-00420-7","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"556_CR26","doi-asserted-by":"publisher","first-page":"41576","DOI":"10.1109\/ACCESS.2019.2905219","volume":"7","author":"F Tommasi","year":"2019","unstructured":"Tommasi, F., Catalano, C., Fornaro, M., Taurino, I.: Mobile session fixation attack in micropayment systems. IEEE Access 7, 41576\u201341583 (2019). https:\/\/doi.org\/10.1109\/ACCESS.2019.2905219","journal-title":"IEEE Access"},{"key":"556_CR27","unstructured":"Gonzalez-Burgue, A., Aparicio, D., Escobar, S., Meadows, C., Meseguer, J.: For- mal verification of the YubiKey and YubiHSM APIs in Maude-NPA (2018). arXiv:1806.07209v1"},{"key":"556_CR28","doi-asserted-by":"crossref","unstructured":"Jacomme, C., Kremer, S.: An extensive formal analysis of multi-factor authenti- cation protocols. IEEE 31st Computer Security Foundations Symposium (2018)","DOI":"10.1109\/CSF.2018.00008"},{"key":"556_CR29","unstructured":"FIDO Security Reference - FIDO Alliance Implementation Draft 27 February 2018. FIDO Alliance (2018). https:\/\/fidoalliance.org\/specs\/fido-v2.0-id-20180227\/fido-security-ref-v2.0-id-20180227.html"},{"key":"556_CR30","doi-asserted-by":"crossref","unstructured":"Sanam Ghorbani Lyastani, M.N.M.B. Michael Schilling, Bugiel, S.: Is fido2 the kingslayer of user authentication? A comparative usability study of fido2 assword- less authentication. IEEE Symposium on Security and Privacy (SP), pp 268\u2013285 (2020)","DOI":"10.1109\/SP40000.2020.00047"},{"key":"556_CR31","unstructured":"Kentrell Owens, A.K. Olabode Anise, Ur, B.: User perceptions of the usability and security of smartphones as fido2 roaming authenticators. Seventeenth Symposium on Usable Privacy and Security (SOUPS 2021) - USENIX Association, pp 57\u201376 (2021)"},{"key":"556_CR32","doi-asserted-by":"crossref","unstructured":"Reynolds, J., Smith, T., Reese, K., Dickinson, L., Ruoti, S., Seamons, K.: A Tale of Two Studies: The Best and Worst of YubiKey Usability. IEEE Symposium on Security and Privacy (2018)","DOI":"10.1109\/SP.2018.00067"},{"key":"556_CR33","doi-asserted-by":"crossref","unstructured":"Chezzi, A., Catalano, C., Tommasi, F.: Bitm+ attack: An improved bitm\/mitb- based phishing attack capable of passing through and defeating the fido\/ctap2 protocol and the w3c webauthn api. Mitb-Based Phishing Attack Capable of Passing through and Defeating the Fido\/Ctap2 Protocol and the W3c Webauthn Api (2024)","DOI":"10.2139\/ssrn.4711140"},{"key":"556_CR34","unstructured":"Documentation, M.-M.W.: Web authentication api. (2019). https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/API\/Web Authentication API"},{"key":"556_CR35","unstructured":"Wikipedia contributors: WebAuthn \u2014 Wikipedia, The Free Encyclopedia. [Online; accessed 2023] (2023). https:\/\/en.wikipedia.org\/w\/index.php?title=WebAuthn&oldid=1180406727"},{"key":"556_CR36","unstructured":"GitHub - FIDO Alliance WebAuthn demo (webauthn-demo. FIDO Alliance (fido- alliance) (2020). https:\/\/github.com\/fido-alliance\/webauthn-demo"},{"key":"556_CR37","unstructured":"WebAuthn WORKSHOP: Authenticating your web like a boss. FIDO Alliance (2018). https:\/\/slides.com\/fidoalliance\/jan-2018-fido-seminar-webauthn-tutorial"},{"key":"556_CR38","unstructured":"GitHub - FIDO Alliance WebAuthn demo (webauthn-demo). nerocrux (2020). https:\/\/github.com\/nerocrux\/webauthn-demo"},{"key":"556_CR39","unstructured":"Corporation, M.: [ms-rdpewa]: Remote desktop protocol: Webauthn vir- tual channel protocol. (2022). https:\/\/learn.microsoft.com\/en-us\/openspecs\/windowsprotocols\/ms-rdpewa\/68f2df2e-7c40-4a93-9bb0-517e4283a991"},{"key":"556_CR40","unstructured":"Wikipedia contributors: Node.js \u2014 Wikipedia, The Free Encyclopedia. [Online; accessed 18-November-2023] (2023). https:\/\/en.wikipedia.org\/w\/index.php?title=Node.js&oldid=1185467042"},{"key":"556_CR41","unstructured":"Node.js: About node.js. https:\/\/nodejs.org\/en\/about"},{"key":"556_CR42","unstructured":"Node.js: About documentation - node.js. https:\/\/nodejs.org\/en\/docs"},{"key":"556_CR43","unstructured":"Puppeteer: Puppeteer documentation. https:\/\/devdocs.io\/puppeteer\/"},{"key":"556_CR44","unstructured":"Google: Welcome to chromium. https:\/\/blog.chromium.org\/2008\/09\/ welcome-to-chromium 02.html"},{"key":"556_CR45","unstructured":"Express.js: Fast, unopinionated, minimalist web framework for node.js. https:\/\/expressjs.com\/"},{"key":"556_CR46","unstructured":"VentureBeat: Case study: How why to build a consumer app with node.js. https:\/\/venturebeat.com\/dev\/building-consumer-apps-with-node\/"},{"key":"556_CR47","unstructured":"noVNC: novnc - the open source vnc client. https:\/\/novnc.com\/info.html"},{"key":"556_CR48","unstructured":"nginx: nginx. https:\/\/nginx.org\/en\/"},{"key":"556_CR49","unstructured":"docs, M.: The WebSocket API (WebSockets) (2023). https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/API\/WebSockets API"},{"key":"556_CR50","unstructured":"hardock14: dorowu-docker-ubuntu-vnc-desktop. Docker Hub (2017). https:\/\/hub.docker.com\/r\/hardock14\/dorowu-docker-ubuntu-vnc-desktop"},{"key":"556_CR51","unstructured":"hardock14: dorowu-docker-ubuntu-vnc-desktop. Github (2017). https:\/\/github.com\/HarGit14\/dorowu-docker-ubuntu-vnc-desktop"},{"key":"556_CR52","unstructured":"Window: localStorage property. MDN web docs (2023). https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/API\/Window\/localStorage"},{"key":"556_CR53","unstructured":"ArrayBuffer. MDN web docs (2023). https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/JavaScript\/Reference\/Global.Objects\/ArrayBuffer"},{"key":"556_CR54","doi-asserted-by":"crossref","unstructured":"Catalano, C., Chezzi, A., Santa Barletta, V., Corallo, A.: Securing web technol- ogy and navigation against phishing through cnn. In: 2023 IEEE International Conference on Metrology for eXtended Reality, Artificial Intelligence and Neural Engineering (MetroXRAINE), pp. 944\u2013948 (2023). IEEE","DOI":"10.1109\/MetroXRAINE58569.2023.10405836"}],"container-title":["Journal of Computer Virology and Hacking Techniques"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-025-00556-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11416-025-00556-2\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-025-00556-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,24]],"date-time":"2025-11-24T17:20:02Z","timestamp":1764004802000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11416-025-00556-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,5,14]]},"references-count":54,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["556"],"URL":"https:\/\/doi.org\/10.1007\/s11416-025-00556-2","relation":{},"ISSN":["2263-8733"],"issn-type":[{"value":"2263-8733","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,5,14]]},"assertion":[{"value":"12 November 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"16 April 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"14 May 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"In this research, we have designed cyber attacks on personal web account, Google account. These experiments have been performed against the author\u2019s accounts. All the experiments were performed by intercepting con- fiden- tial information belonging exclusively to the authors of the paper. This research does not involve human participants and\/or animals.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical approval"}}],"article-number":"11"}}