Collected research
SSO Wars: The Token Menace
Two flaws in .NET single sign-on. An unvalidated algorithm name from a JWT header or an XML SignatureMethod reaches CryptoConfig, letting an attacker instantiate arbitrary types; Dupe Key Confusion adds a second KeyInfo element so signature validation uses the attacker's own key. Lets an attacker forge SAML assertions and log in as any user, plus denial of service and code execution.
Record
- Researcher
- Oleksandr Mirosh and Alvaro Muñoz
- Published by
- i.blackhat.com
- Format
- Whitepaper
- Topic
- Identity
In the archive
Related sources
- G1234! - SSO Wars: The Token Menace - Alvaro Munoz & Oleksandr Mirosh
- Alvaro Muñoz - SSO Wars: The Token Menace - DEF CON 27 Conference
- SSO Wars: The Token Menace
Tags
This page is the archive's own catalogue record. The research is the work of Oleksandr Mirosh and Alvaro Muñoz, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .