The Fragile Lock: Novel Bypasses For SAML Authentication (opens in new tab)
SAML2 has been the backbone of enterprise single sign-on for over 20 years\. Behind its familiar facade lies a chaotic mix of legacy specifications, fragile XML processing, and false assurances of security\. Despite endless patches and best practices, the protocol continues to collapse under the weight of its own complexity\. In this talk, I will show you how to bypass authentication using subtle flaws in XML handling\. I will introduce several previously unpublished techniques that enable th...
Read the original article