Access Token Substitution
Severity [Medium]
Description
The vulnerability is caused by the improper implementations in the RP server. In Fig. 1, right after Step 7, the RP server should compare the received user data from Step 7 with the user information from Step 3 and check the binding between itself and the access token. However, the verification is usually missing, so that the attacker can inject the stolen (network Attacker) / obtained (malicious RP attacker) access token of the victim into his own session, e.g., Step 3 in Fig. 1, to cheat the RP server into the wrong authentication.
Fig. 1
Fig. 2
Impact
The attacker can impersonate as the RP and is able to exchange the stolen code for a valid access token and further extract victim’s user profile on the IdP server with the token. In addition, since Facebook utilizes the same secret to sign the user profile, the attacker is capable of forging a valid signature to launch the profile attack.
Solution
- Sina Weibo: The RP server should check the binding between the access token and User as well as the one between the access token and App.
- WeChat: In WeChat, it is IdP’s duty to check the binding between the access token and App. The IdP server requires both the access token and (app-specific) openid when RP server/ app queries user information in api.weixin. qq.com/sns/oauth2/access_token=Token&openid=id. However, after manually checking the API, we find that the IdP server actually does not verify the binding (the value of openid). As a remedy, the RP developers should deploy Step 6 to Step 9 in Fig. 2 on the server side, so that the attacker has no way to inject the stolen/ obtained access token.
- Facebook: RP server should authenticate the user based on the signed user information (signed request/ id token) after verifying its signature. Besides, the RP developers should not hardcode the app secret in the APK..
Reference
[1] Hu, Pili, et al. "Application impersonation: problems of OAuth and API design in online social networks." Proceedings of the second ACM conference on Online social networks. ACM, 2014.