Collected research
Securing XML implementations across the web
Several XML implementations do not round-trip documents faithfully: parsing and re-serialising a crafted document changes its structure, because mismatched quotes in a notation declaration let a system identifier swallow following markup. SAML libraries read the identity before validating the signature but validate after a round-trip, so one signed document logs an attacker in as anyone.
Record
- Researcher
- Juho Forsén
- Published by
- Mattermost.com
- Date
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Juho Forsén, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .