{"repo":"RUB-NDS/DISTINCT","free":true,"listed":false,"github":"https://github.com/RUB-NDS/DISTINCT","clone":"git clone https://github.com/RUB-NDS/DISTINCT.git","description":"Dynamic In-Browser Single Sign-On Tracer Inspecting Novel Communication Techniques","language":"JavaScript","stars":12,"topics":["authentication","authorization","iframe","in-browser-javascript","oauth","openid-connect","popup","postmessage","research-paper","research-tool"],"license":"Apache-2.0","category":"auth-billing-email","readme_excerpt":"DISTINCT: Dynamic In-Browser Single Sign-On Tracer Inspecting Novel Communication Techniques DISTINCT is a web-based Single Sign-On security analysis framework for modern communication techniques that was developed for the paper 📝 \"DISTINCT: Identity Theft using In-Browser Communications in Dual-Window Single Sign-On\". It is designed to monitor and analyze the in-browser communication techniques sending in-browser messages across browser windows at runtime. Its dynamic analysis approach automates the (1) capturing, (2) detection, (3) visualization, (4) security analysis, and (5) exploitation of Single Sign-On flows relying on novel in-browser communication techniques. You can find more details in the paper 📝. 🚀 Quick Start - Install Docker and Docker-Compose - Make sure ports 9070 , 9080 , and 9090 are free on your host - Clone this repo: git clone https://github.com/RUB-NDS/DISTINCT.git - Note that you will need git lfs to fetch all files, including the distinct-chromium.zip file. Otherwise, you will receive an unzip error during build process. - Go into its src directory: cd ./DISTINCT/src - Run: docker-compose build - Optional: Configure log level, password, and identity provider accounts - Create .env file in ./src : cp .env.example .env - For VERBOSITY , choose between DEBUG , INFO , WARNING , ERROR , CRITICAL (default: DEBUG ) - For VNCPWD , choose a custom password that is required in the web interface to control the browser (default: changeme ) - You can optionally","default_branch":null,"files":null,"tree":[],"storefront":"/r/RUB-NDS","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/RUB-NDS/DISTINCT/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}