Web Hack List

Collected research

On Breaking SAML: Be Whoever You Want to Be

An analysis of 14 SAML frameworks found 11, including Salesforce, Shibboleth and IBM XS40, open to XML Signature wrapping, letting an attacker re-parent a signed assertion and impersonate any user. The work models the attack as information flow between two Relying Party components, builds a penetration testing tool from that model, and derives countermeasures.

Record

Researcher
Juraj Somorovsky, Andreas Mayer, Jörg Schwenk, Marco Kampmann and Meiko Jensen
Published by
usenix.org
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Juraj Somorovsky, Andreas Mayer, Jörg Schwenk, Marco Kampmann and Meiko Jensen, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .