{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T16:12:20Z","timestamp":1783008740326,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":34,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,12,4]],"date-time":"2023-12-04T00:00:00Z","timestamp":1701648000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"EU Horizon project DUCA","award":["HORIZON-MSCA-2021-SE-01 programme under GA 101086308"],"award-info":[{"award-number":["HORIZON-MSCA-2021-SE-01 programme under GA 101086308"]}]},{"DOI":"10.13039\/501100006374","name":"National Science Foundation","doi-asserted-by":"publisher","award":["2329540,2219921,2127200"],"award-info":[{"award-number":["2329540,2219921,2127200"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,12,4]]},"DOI":"10.1145\/3627106.3627140","type":"proceedings-article","created":{"date-parts":[[2023,12,2]],"date-time":"2023-12-02T18:13:22Z","timestamp":1701540802000},"page":"256-267","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":7,"title":["OAuth 2.0 Redirect URI Validation Falls Short, Literally"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0247-806X","authenticated-orcid":false,"given":"Tommaso","family":"Innocenti","sequence":"first","affiliation":[{"name":"Northeastern University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8743-0825","authenticated-orcid":false,"given":"Matteo","family":"Golinelli","sequence":"additional","affiliation":[{"name":"University of Trento, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-7832-5884","authenticated-orcid":false,"given":"Kaan","family":"Onarlioglu","sequence":"additional","affiliation":[{"name":"Akamai Technologies, USA and Northeastern University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0159-5037","authenticated-orcid":false,"given":"Ali","family":"Mirheidari","sequence":"additional","affiliation":[{"name":"independent researcher, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1252-8465","authenticated-orcid":false,"given":"Bruno","family":"Crispo","sequence":"additional","affiliation":[{"name":"University of Trento, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9988-6873","authenticated-orcid":false,"given":"Engin","family":"Kirda","sequence":"additional","affiliation":[{"name":"Northeastern University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,12,4]]},"reference":[{"key":"e_1_3_2_2_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/3178876.3186090"},{"key":"e_1_3_2_2_2_1","volume-title":"Automated Discovery of Parameter Pollution Vulnerabilities in Web Applications. In Network and Distributed System Security Symposium.","author":"Balduzzi Marco","year":"2011","unstructured":"Marco Balduzzi, Carmen Torrano\u00a0Gimenez, Davide Balzarotti, and Engin Kirda. 2011. Automated Discovery of Parameter Pollution Vulnerabilities in Web Applications. In Network and Distributed System Security Symposium."},{"key":"e_1_3_2_2_3_1","volume-title":"OAuth \u2018masterclass","author":"Bannister Adam","year":"2022","unstructured":"Adam Bannister. 2023. OAuth \u2018masterclass\u2019 crowned top web hacking technique of 2022. PortSwigger\u2013The Daily Swig. https:\/\/portswigger.net\/daily-swig\/oauth-masterclass-crowned-top-web-hacking-technique-of-2022."},{"key":"e_1_3_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-80825-9_2"},{"key":"e_1_3_2_2_5_1","volume-title":"USENIX Security Symposium.","author":"Calzavara Stefano","year":"2018","unstructured":"Stefano Calzavara, Riccardo Focardi, Matteo Maffei, Clara Schneidewind, Marco Squarcina, and Mauro Tempesta. 2018. WPSE: Fortifying Web Protocols via Browser-Side Security Monitoring. In USENIX Security Symposium."},{"key":"e_1_3_2_2_6_1","volume-title":"Universally Composable Security Analysis of OAuth v2.0. Cryptology ePrint Archive","author":"Chari Suresh","year":"2011","unstructured":"Suresh Chari, Charanjit Jutla, and Arnab Roy. 2011. Universally Composable Security Analysis of OAuth v2.0. Cryptology ePrint Archive (2011)."},{"key":"e_1_3_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978385"},{"key":"e_1_3_2_2_8_1","volume-title":"Towards Automated Auditing for Account and Session Management Flaws in Single Sign-On Deployments. In IEEE Symposium on Security and Privacy.","author":"Ghasemisharif Mohammad","year":"2022","unstructured":"Mohammad Ghasemisharif, Chris Kanich, and Jason Polakis. 2022. Towards Automated Auditing for Account and Session Management Flaws in Single Sign-On Deployments. In IEEE Symposium on Security and Privacy."},{"key":"e_1_3_2_2_9_1","volume-title":"An Empirical Analysis of Single Sign-On Account Hijacking and Session Management on the Web. In USENIX Security Symposium.","author":"Ghasemisharif Mohammad","year":"2018","unstructured":"Mohammad Ghasemisharif, Amrutha Ramesh, Stephen Checkoway, Chris Kanich, and Jason Polakis. 2018. O Single Sign-Off, Where Art Thou? An Empirical Analysis of Single Sign-On Account Hijacking and Session Management on the Web. In USENIX Security Symposium."},{"key":"e_1_3_2_2_10_1","unstructured":"GitHub Docs. 2023. Authorizing OAuth Apps. https:\/\/docs.github.com\/en\/apps\/oauth-apps\/building-oauth-apps\/authorizing-oauth-apps#web-application-flow."},{"key":"e_1_3_2_2_11_1","unstructured":"Dick Hardt. 2005. RFC 3986\u2013Uniform Resource Identifier (URI): Generic Syntax. https:\/\/datatracker.ietf.org\/doc\/rfc3986\/."},{"key":"e_1_3_2_2_12_1","doi-asserted-by":"crossref","unstructured":"Dick Hardt. 2012. RFC 6749\u2013The OAuth 2.0 Authorization Framework. https:\/\/datatracker.ietf.org\/doc\/rfc6749\/.","DOI":"10.17487\/rfc6749"},{"key":"e_1_3_2_2_13_1","unstructured":"Lauritz Holtmann. 2021. Insufficient Redirect URI validation: The risk of allowing to dynamically add arbitrary query parameters and fragments to the redirect_uri. (Web-)Insecurity Blog. https:\/\/security.lauritz-holtmann.de\/post\/sso-security-redirect-uri-ii\/."},{"key":"e_1_3_2_2_14_1","unstructured":"David Krispin and Nir Swartz. 2021. Microsoft and GitHub OAuth Implementation Vulnerabilities Lead to Redirection Attacks. https:\/\/www.proofpoint.com\/us\/blog\/cloud-security\/microsoft-and-github-oauth-implementation-vulnerabilities-lead-redirection."},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3338500.3360331"},{"key":"e_1_3_2_2_16_1","unstructured":"T. Lodderstedt J. Bradley A. Labunets and D. Fett. 2023. OAuth 2.0 Security Best Current Practice. https:\/\/datatracker.ietf.org\/doc\/html\/draft-ietf-oauth-security-topics."},{"key":"e_1_3_2_2_17_1","unstructured":"T. Lodderstedt M. McGloin and P. Hunt. 2013. RFC 6819\u2013OAuth 2.0 Threat Model and Security Considerations. https:\/\/datatracker.ietf.org\/doc\/rfc6819\/."},{"key":"e_1_3_2_2_18_1","volume-title":"Cached and Confused: Web Cache Deception in the Wild. In USENIX Security Symposium.","author":"Mirheidari Seyed\u00a0Ali","year":"2020","unstructured":"Seyed\u00a0Ali Mirheidari, Sajjad Arshad, Kaan Onarlioglu, Bruno Crispo, Engin Kirda, and William Robertson. 2020. Cached and Confused: Web Cache Deception in the Wild. In USENIX Security Symposium."},{"key":"e_1_3_2_2_19_1","volume-title":"USENIX Security Symposium.","author":"Mirheidari Seyed\u00a0Ali","year":"2022","unstructured":"Seyed\u00a0Ali Mirheidari, Matteo Golinelli, Kaan Onarlioglu, Engin Kirda, and Bruno Crispo. 2022. Web Cache Deception Escalates!. In USENIX Security Symposium."},{"key":"e_1_3_2_2_20_1","volume-title":"Empirical Analysis and Privacy Implications in OAuth-Based Single Sign-On Systems. In Workshop on Privacy in the Electronic Society.","author":"Morkonda G.","year":"2021","unstructured":"Srivathsan\u00a0G. Morkonda, Sonia Chiasson, and Paul\u00a0C. van Oorschot. 2021. Empirical Analysis and Privacy Implications in OAuth-Based Single Sign-On Systems. In Workshop on Privacy in the Electronic Society."},{"key":"e_1_3_2_2_21_1","unstructured":"NAVER Developers. 2023. API Specification. https:\/\/developers.naver.com\/docs\/login\/api\/api.md."},{"key":"e_1_3_2_2_22_1","volume-title":"OAuth Security Advisory","author":"Auth","year":"2014","unstructured":"OAuth 2.0. 2014. OAuth Security Advisory: 2014.1 \"Covert Redirect\". https:\/\/oauth.net\/advisories\/2014-1-covert-redirect\/."},{"key":"e_1_3_2_2_23_1","unstructured":"Open Bug Bounty. [n. d.]. Free Bug Bounty Program and Coordinated Vulnerability Disclosure. https:\/\/www.openbugbounty.org."},{"key":"e_1_3_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSNT.2011.141"},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3545948.3545955"},{"key":"e_1_3_2_2_26_1","volume-title":"Tranco: A Research-Oriented Top Sites Ranking Hardened Against Manipulation. In Network and Distributed System Security Symposium.","author":"Pochat Victor\u00a0Le","year":"2019","unstructured":"Victor\u00a0Le Pochat, Tom\u00a0Van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski, and Wouter Joosen. 2019. Tranco: A Research-Oriented Top Sites Ranking Hardened Against Manipulation. In Network and Distributed System Security Symposium."},{"key":"e_1_3_2_2_27_1","unstructured":"Frans Ros\u00e9n. 2022. Account hijacking using \"dirty dancing\" in sign-in OAuth-flows. https:\/\/labs.detectify.com\/2022\/07\/06\/account-hijacking-using-dirty-dancing-in-sign-in-oauth-flows\/."},{"key":"e_1_3_2_2_28_1","unstructured":"Youssef Sammouda. 2021. More secure Facebook Canvas: Tale of $126k worth of bugs that lead to Facebook Account Takeovers. https:\/\/ysamm.com\/?p=708."},{"key":"e_1_3_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-20550-2_13"},{"key":"e_1_3_2_2_30_1","volume-title":"USENIX Security Symposium.","author":"Sudhodanan Avinash","year":"2022","unstructured":"Avinash Sudhodanan and Andrew Paverd. 2022. Pre-hijacked accounts: An Empirical Study of Security Failures in User Account Creation on the Web. In USENIX Security Symposium."},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382238"},{"key":"e_1_3_2_2_32_1","volume-title":"Explicating SDKs: Uncovering Assumptions Underlying Secure Authentication and Authorization. In USENIX Security Symposium.","author":"Wang Rui","year":"2013","unstructured":"Rui Wang, Yuchen Zhou, Shuo Chen, Shaz Qadeer, David Evans, and Yuri Gurevich. 2013. Explicating SDKs: Uncovering Assumptions Underlying Secure Authentication and Authorization. In USENIX Security Symposium."},{"key":"e_1_3_2_2_33_1","unstructured":"Xianbo Wang Wing\u00a0Cheong Lau Shangcheng Shi and Ronghai Yang. 2019. Make Redirection Evil Again - URL Parser Issues in OAuth. Black Hat Asia. https:\/\/www.blackhat.com\/asia-19\/briefings\/schedule\/#make-redirection-evil-again\u2014url-parser-issues-in-oauth-13704."},{"key":"e_1_3_2_2_34_1","volume-title":"SSOScan: Automated Testing of Web Applications for Single Sign-On Vulnerabilities. In USENIX Security Symposium.","author":"Zhou Yuchen","year":"2014","unstructured":"Yuchen Zhou and David Evans. 2014. SSOScan: Automated Testing of Web Applications for Single Sign-On Vulnerabilities. In USENIX Security Symposium."}],"event":{"name":"ACSAC '23: Annual Computer Security Applications Conference","location":"Austin TX USA","acronym":"ACSAC '23"},"container-title":["Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3627106.3627140","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3627106.3627140","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T17:41:11Z","timestamp":1755884471000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3627106.3627140"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,12,4]]},"references-count":34,"alternative-id":["10.1145\/3627106.3627140","10.1145\/3627106"],"URL":"https:\/\/doi.org\/10.1145\/3627106.3627140","relation":{},"subject":[],"published":{"date-parts":[[2023,12,4]]},"assertion":[{"value":"2023-12-04","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}