Infosecurity.US

Information Security & Occasional Forays Into Adjacent Realms

  • Web Log

SAML Flaws Discovered With SSO Implications →

February 28, 2018 by Marc Handelman in SAML, Security, Secure Coding, Security Architecture, Authentication, SSO

Kelby Ludwig - writing at Duo Lab's has just posted a fascinating blog entry detailing their recent discovery of SAML vulns potentially affecting a range of implementations and deployments. In this case, the vulnerability appears to be a zero knowledge scenario (of the attributes of the target's password). H/T

"This blog post describes a new vulnerability class that affects SAML-based single sign-on (SSO) systems. This vulnerability can allow an attacker with authenticated access to trick SAML systems into authenticating as a different user without knowledge of the victim user’s password. - via Duo Lab's Kelby Ludwig

Oops.

February 28, 2018 /Marc Handelman
SAML, Security, Secure Coding, Security Architecture, Authentication, SSO