{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,14]],"date-time":"2025-11-14T21:01:52Z","timestamp":1763154112665,"version":"3.45.0"},"reference-count":42,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"6","license":[{"start":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T00:00:00Z","timestamp":1761955200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T00:00:00Z","timestamp":1761955200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T00:00:00Z","timestamp":1761955200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key Research and Development Program of China","award":["2020YFB1807500"],"award-info":[{"award-number":["2020YFB1807500"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2025,11]]},"DOI":"10.1109\/tdsc.2025.3593598","type":"journal-article","created":{"date-parts":[[2025,7,29]],"date-time":"2025-07-29T18:32:46Z","timestamp":1753813966000},"page":"6955-6967","source":"Crossref","is-referenced-by-count":0,"title":["OTP-Hunter: An App-Based Fuzzing Framework to Discover One Time Password Vulnerabilities"],"prefix":"10.1109","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5898-7317","authenticated-orcid":false,"given":"Futai","family":"Zou","sequence":"first","affiliation":[{"name":"School of Computer Science, Shanghai Jiao Tong University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-6715-4983","authenticated-orcid":false,"given":"Zehui","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Computer Science, Shanghai Jiao Tong University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuzong","family":"Hu","sequence":"additional","affiliation":[{"name":"School of Computer Science, Shanghai Jiao Tong University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN48063.2020.00045"},{"year":"2021","key":"ref2","article-title":"TBomb"},{"year":"2018","key":"ref3","article-title":"SMSBomb"},{"year":"2020","key":"ref4","article-title":"Ni_bomber"},{"article-title":"No rate limiting on https:\/\/[domain]\/accounts\/password\/reset\/ endpoint leads to denial of service","year":"2020","author":"Nagli","key":"ref5"},{"article-title":"No rate limit on forgot password page of NordVPN","year":"2019","author":"Devgan","key":"ref6"},{"year":"2020","key":"ref7","article-title":"No rate limit in otp code sending"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00066"},{"year":"2023","key":"ref9","article-title":"Retrofit2"},{"article-title":"Lenovosmart apk","volume-title":"Apkpure.com","year":"2023","key":"ref10"},{"year":"2023","key":"ref11","article-title":"Burp suite"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1155\/2018\/7849065"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359828"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/tmc.2025.3550883"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.3390\/e21121136"},{"key":"ref16","first-page":"1","article-title":"The soot framework for java program analysis: A retrospective","volume-title":"Proc. Cetus Users Compiler Infastruct. Workshop","author":"Lam"},{"year":"2017","key":"ref17","article-title":"Pysoot"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.17"},{"year":"2023","key":"ref19","article-title":"Rxjava2"},{"year":"2019","key":"ref20","article-title":"Okhttp3"},{"year":"2023","key":"ref21","article-title":"JADX"},{"year":"2023","key":"ref22","article-title":"Noxplayer"},{"article-title":"frida","year":"2023","author":"Ravns","key":"ref23"},{"year":"2023","key":"ref24","article-title":"Charles"},{"year":"2023","key":"ref25","article-title":"Google play"},{"year":"2023","key":"ref26","article-title":"Apkpure"},{"year":"2022","key":"ref27","article-title":"Frida-dexdump"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3134600.3134615"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1007\/s11276-023-03455-w"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE43902.2021.00148"},{"key":"ref31","first-page":"150","article-title":"SMS-based one-time passwords: Attacks and defense: (short paper)","volume-title":"Proc. DIMVA","author":"Mulliner"},{"key":"ref32","first-page":"1499","article-title":"Security analysis of unified payments interface and payment apps in India","volume-title":"Proc. USENIX Secur. Symp","author":"Kumar"},{"key":"ref33","first-page":"2043","article-title":"A study of multi-factor and risk-based authentication availability","volume-title":"Proc. USENIX Secur. Symp","author":"Gavazzi"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.9"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24212"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/DSN-W52860.2021.00013"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2023.3289754"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3512766"},{"key":"ref39","first-page":"3667","article-title":"Share first, ask later (or never?) studying violations of $\\lbrace${GDPR\u2019s$\\rbrace$} explicit consent in android apps","volume-title":"Proc. USENIX Secur. Symp.","author":"Nguyen"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/SCAM55253.2022.00008"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1145\/3292006.3300027"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3155693"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11242243\/11098918.pdf?arnumber=11098918","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,14]],"date-time":"2025-11-14T21:00:41Z","timestamp":1763154041000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11098918\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11]]},"references-count":42,"journal-issue":{"issue":"6"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2025.3593598","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"type":"print","value":"1545-5971"},{"type":"electronic","value":"1941-0018"},{"type":"electronic","value":"2160-9209"}],"subject":[],"published":{"date-parts":[[2025,11]]}}}