Inproceedings,

Social networks as a platform for distributed dictionary attack

, and .
Proceedings of the 5th WSEAS international conference on Communications and information technology, page 101--106. Stevens Point, Wisconsin, USA, World Scientific and Engineering Academy and Society (WSEAS), (2011)

Abstract

The programming interface (API) for application developers associated with a social network has become a de-facto standard in the modern web development. These features can be exploited by a malicious user in order to trick common users of social networks into unknowingly performing various malicious tasks. This paper shows how a distributed dictionary attack can be performed in such manner. A proof of concept application for a real-world social network has been developed to illustrate this concept. During the application development only legitimate web technologies were used. However, the application execution results in an attack on a remote web server while the user of the application is unaware of its true nature. It is also illustrated how web technologies and JavaScript in particular can be used for distributed computing, a fairly new concept introduced in the past few years. The developed application distributes parts of the dictionary to its clients resulting in a faster attack rate as more users execute the application.

Tags

Users

  • @fernand0

Comments and Reviews