Elham Arshad

dblp:296/7715 · DBLP profile ↗
← Back
3ranked-venue papers
2as first author
3since 2021 · last 2022
0000-0003-1256-2863ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2022 Mollywood: Subtitles as an attack vector
abstract
Online subtitle repositories manage a huge amount of subtitle files for a variety of movies/TV-shows in 88 different languages and are available to the public to download and upload. Given the popularity of these repositories, we study the subtitle providers (STP) ecosystem by identifying and analyzing the involved parties. Our observations reveal that these STPs seem to be one of the most widespread and easily accessed resources to be potentially abused by attackers. Therefore, due to the features of STP ecosystem, they could be considered as a new attack vector through the subtitle files. However, all potentials of this new attack vector have not been yet exploited. Due to the rise of cryptojacking attacks substantially, this paper shows how a vulnerability present in a popular streaming platform can be exploited to perform a cryptojacking attack using the malicious subtitles delivered by STPs.
Elham Arshad, Giuliano Turri, Bruno Crispo
ISCC1
2022 Practical attacks on Login CSRF in OAuth
Elham Arshad, Michele Benolli, Bruno Crispo
Comput. Secur.1
2021 The Full Gamut of an Attack: An Empirical Analysis of OAuth CSRF in the Wild
Michele Benolli, Seyed Ali Mirheidari, Elham Arshad, Bruno Crispo
DIMVA3