Web Hack List

Later archive addition

Bypassing SAML 2.0 SSO with XML Signature Attacks

The guide explains how SAML consumers can accept forged identities when signatures are missing, trusted incorrectly, or made to cover a different XML element than the one consumed. It provides SAML Raider steps, a manual XML-signature-wrapping workflow, limitations, and a testing checklist.

Record

Researcher
Tim Goddard
Published by
Aura Information Security
Date

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Tim Goddard, first published at the original source. Preserved copies are kept so the citation survives its host.