Discovering concrete attacks on website authorization by formal analysis1

This paper is an extended and revised version of [13]. Social sign-on and social sharing are becoming an ever more popular feature of web applications. This success is largely due to the APIs and support offered by prominent social networks, such as