%0 Conference Proceedings %T Who On Earth Is "Mr. Cypher": Automated Friend Injection Attacks on Social Networking Sites %+ SBA Research %A Huber, Markus %A Mulazzani, Martin %A Weippl, Edgar %< avec comité de lecture %( IFIP Advances in Information and Communication Technology %B 25th IFIP TC 11 International Information Security Conference (SEC) / Held as Part of World Computer Congress (WCC) %C Brisbane, Australia %Y Kai Rannenberg; Vijay Varadharajan; Christian Weber %I Springer %3 Security and Privacy - Silver Linings in the Cloud %V AICT-330 %P 80-89 %8 2010-09-20 %D 2010 %R 10.1007/978-3-642-15257-3_8 %K social networks %K privacy %K infiltration %Z Computer Science [cs]/Digital Libraries [cs.DL]Conference papers %X Within this paper we present our novel friend injection attack which exploits the fact that the great majority of social networking sites fail to protect the communication between its users and their services. In a practical evaluation, on the basis of public wireless access points, we furthermore demonstrate the feasibility of our attack. The friend injection attack enables a stealth infiltration of social networks and thus outlines the devastating consequences of active eavesdropping attacks against social networking sites. %G English %2 https://inria.hal.science/hal-01054574/document %2 https://inria.hal.science/hal-01054574/file/paperwho.pdf %L hal-01054574 %U https://inria.hal.science/hal-01054574 %~ IFIP %~ IFIP-AICT %~ IFIP-AICT-330 %~ IFIP-TC %~ IFIP-TC11 %~ IFIP-SEC %~ IFIP-WCC %~ IFIP-2010