Collected research
On Breaking SAML: Be Whoever You Want to Be
An analysis of 14 SAML frameworks found 11, including Salesforce, Shibboleth and IBM XS40, open to XML Signature wrapping, letting an attacker re-parent a signed assertion and impersonate any user. The work models the attack as information flow between two Relying Party components, builds a penetration testing tool from that model, and derives countermeasures.
Record
- Researcher
- Juraj Somorovsky, Andreas Mayer, Jörg Schwenk, Marco Kampmann and Meiko Jensen
- Published by
- usenix.org
- Topic
- Identity
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Juraj Somorovsky, Andreas Mayer, Jörg Schwenk, Marco Kampmann and Meiko Jensen, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .