Web Hack List

Collected research

SSO Wars: The Token Menace

Two flaws in .NET single sign-on. An unvalidated algorithm name from a JWT header or an XML SignatureMethod reaches CryptoConfig, letting an attacker instantiate arbitrary types; Dupe Key Confusion adds a second KeyInfo element so signature validation uses the attacker's own key. Lets an attacker forge SAML assertions and log in as any user, plus denial of service and code execution.

Record

Researcher
Oleksandr Mirosh and Alvaro Muñoz
Published by
i.blackhat.com
Format
Whitepaper
Topic
Identity

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Oleksandr Mirosh and Alvaro Muñoz, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .