Infosecurity.US

Information Security & Occasional Forays Into Adjacent Realms

  • Web Log

SAML, The p0wnage

August 01, 2018 by Marc Handelman in SAML, Information Security

Oh, How Sweet It Is*... via the superlative Anitian Blog, and of course - writer Rick Osgood, comes this tremendous piece - titled 'Owning SAML, in which, the p0wning of SAML, and the fix thereof, is revealed. It's a great read, and highly receommended, enjoy.

(*Jackie Gleason, in The Honeymooners)

August 01, 2018 /Marc Handelman
SAML, Information Security

SAML Flaws Discovered With SSO Implications →

February 28, 2018 by Marc Handelman in SAML, Security, Secure Coding, Security Architecture, Authentication, SSO

Kelby Ludwig - writing at Duo Lab's has just posted a fascinating blog entry detailing their recent discovery of SAML vulns potentially affecting a range of implementations and deployments. In this case, the vulnerability appears to be a zero knowledge scenario (of the attributes of the target's password). H/T

"This blog post describes a new vulnerability class that affects SAML-based single sign-on (SSO) systems. This vulnerability can allow an attacker with authenticated access to trick SAML systems into authenticating as a different user without knowledge of the victim user’s password. - via Duo Lab's Kelby Ludwig

Oops.

February 28, 2018 /Marc Handelman
SAML, Security, Secure Coding, Security Architecture, Authentication, SSO

BSides Nashville 2017, Bruce Wilson's 'Trust But Verify Your SAML Service Providers ' →

May 22, 2017 by Marc Handelman in BSides, Information Security, SAML
May 22, 2017 /Marc Handelman
BSides, Information Security, SAML

On SAML, The Breaking

September 04, 2015 by Marc Handelman in All is Information, Education, Information Security, SAML
September 04, 2015 /Marc Handelman
All is Information, Education, Information Security, SAML

On SAML, The Chalk Talk →

September 04, 2015 by Marc Handelman in All is Information, Information Security, SAML
September 04, 2015 /Marc Handelman
All is Information, Information Security, SAML