Adonis P. H. Fung

dblp:50/7986 · DBLP profile ↗
← Back
5ranked-venue papers
3as first author
2since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 3 first-author · 2 since 2021
YearPublicationVenuePosition
2026 Demystifying the (In)Security of Oauth-Based Account Linking in Connector Ecosystems
Kaixuan Luo, Xianbo Wang, Adonis P. H. Fung, Wing Cheong Lau
SP3
2025 Universal Cross-app Attacks: Exploiting and Securing OAuth 2.0 in Integration Platforms
Kaixuan Luo, Xianbo Wang, Adonis P. H. Fung, Wing Cheong Lau, Julien Lecomte
USENIX Security Symposium3
2014 Scanning of real-world web applications for parameter tampering vulnerabilities
abstract
Web applications require exchanging parameters between a client and a server to function properly. In real-world systems such as online banking transfer, traversing multiple pages with parameters contributed by both the user and server is a must, and hence the applications have to enforce workflow and parameter dependency controls across multiple requests. An application that applies insufficient server-side input validations is however vulnerable to parameter tampering attacks, which manipulate the exchanged parameters. Existing fuzzing-based scanning approaches however neglected these important controls, and this caused their fuzzing requests to be dropped before they can reach any vulnerable code. In this paper, we propose a novel approach to identify the workflow and parameter dependent constraints, which are then maintained and leveraged for automatic detection of server acceptances during fuzzing. We realized the approach by building a generic blackbox parameter tampering scanner. It successfully uncovered a number of severe vulnerabilities, including one from the largest multi-national banking website, which other scanners miss.
Adonis P. H. Fung, Tielei Wang, Kwok-Wai Cheung 0003, Tsz-Yeung Wong
AsiaCCS1
2010 SSLock: sustaining the trust on entities brought by SSL
abstract
We propose a new, simple and effective domain segmentation approach to sustain SSL protection which is usually compromised when users are expected to perform legitimacy judgment. It has been established that using security warnings and indicators is a serious operational flaw of SSL. As a security-critical system, SSL should never rely on users' judgment as the ultimate defense because adversaries that exploit users' ignorance and illiteracy are sufficient to break the most secure system. The proposal simply requires a service provider to opt-in by hosting its service in a special subdomain "secure". The enhanced protection will then be automatically in force. In this paper, we consider three severe and characteristic attack models, namely dynamic pharming, deceptive captive portal and SSLStrip attacks, and we show that there is no single defeating solution except SSLock. We have conducted deployability analysis which further justifies the proposal in terms of its high compatibility rate. SSLock is the only approach that is generic and light-weight for application vendors, opt-in and zero-initialization for service providers, and privacy-preserving and idiot-proof for generic users.
Adonis P. H. Fung, Kwok-Wai Cheung 0003
AsiaCCS1
2010 HTTPSLock: Enforcing HTTPS in Unmodified Browsers with Cached Javascript
abstract
HTTPS is designed to protect a connection against eavesdropping and man-in-the-middle attacks. HTTPS is however often compromised and voided when users are to embrace invalid certificates or disregard if HTTPS is being used. The current HTTPS deployment relies on unsophisticated users to safeguard themselves by performing legitimacy judgment. We propose HTTPS Lock, a simple and immediate approach to enforce HTTPS security. HTTPS Lock can be deployed to a website with a valid certificate by simply including several Javascript and HTML files, which will be cached in browsers. Similar to the trust-on-first-use model used by SSH, the trusted code cached on the client-side can effectively enforce the use of HTTPS and forbid users to embrace invalid certificates for any compromised networks subsequently encountered. Over 72% of major web browsers are supported, and further growth is expected. In any situation where the protection is unsupported or expired, the current security standard is gracefully maintained. As desired, the deployment is not hindered by standardization and collaboration from browser vendors as with other proposals.
Adonis P. H. Fung, Kwok-Wai Cheung 0003
NSS1