XML Signature Element Wrapping Attacks and Countermeasures¶
McIntosh, M., & Austel, P. (2005). XML Signature Element Wrapping Attacks and Countermeasures. Proceedings of the 2005 workshop on Secure web services, 20-27.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Mechanisms¶
- Canonicalization Rule
- The classic misuse is bolting canonicalization onto a security scheme after the fact and assuming "canonical" implies "safe"; XML signature-wrapping attacks are the standing cautionary tale.
This sourceDemonstrates that naive XML Signature use can permit wrapping attacks that alter valid signed messages without detection.
- The classic misuse is bolting canonicalization onto a security scheme after the fact and assuming "canonical" implies "safe"; XML signature-wrapping attacks are the standing cautionary tale.
Verification¶
Does it exist? Confirmed. This work's DOI resolves to a registered record, which fixes its identity. That is all it fixes.
Does it back the claim? Not recorded. The single citation of this work carries no recorded support check.
Support is checked per citation rather than per work — the same source can be cited soundly in one article and wrongly in another. Per-citation recording began recently, so a citation with no recorded check is a gap in the record rather than evidence it went unchecked.
See how references were verified.
Registry ID ref:0b5ec1172b68 · see in the full table