Web Hack List

Collected research

How to break SAML if I have paws?

A practical attack methodology for SAML single sign-on. It fingerprints an implementation from the SAMLRequest and metadata, forges a SAMLResponse from scratch, and defeats signature validation through missing Signature tags, self-signed certificates trusted from KeyInfo, and .NET dupe key confusion. XML DSig reference dereferencing and transforms such as base64, XPath and XSLT then yield SSRF, XXE and remote code execution, before ACS spoofing and multi-tenant IdP confusion.

Record

Researcher
Aleksei "GreenDog" Tiurin
Published by
Speaker Deck
Date
Format
Slides
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Aleksei "GreenDog" Tiurin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .