Black Hat USA 2019, LAS VEGAS, AUG 3-8, 2019. SSO Wars: The Token Menace



Don't miss this session!

SSO Wars: The Token Menace

Alvaro Munoz  |  Principal Software Security Researcher, Micro Focus Fortify
Oleksandr Mirosh  |  Software Security Researcher, Micro Focus Fortify
Location:  South Pacific
Date: Wednesday, August 7 | 10:30am-10:55am
Format: 25-Minute Briefings
Tracks:  Web AppSec,  Enterprise
It is the year 2019. Humanity has almost won its long-standing war against Single-Sign On (SSO) bugs. The last of them were discovered and eradicated some time ago and the world is now living in an era of prosperity while the Auth Federation enjoys peaceful CVE-free times. However, while things seem to be running smoothly, new bugs are brewing at the core of major implementation libraries. This is probably the last chance for the evil empire to launch a world scale attack against the Auth Federation.

In this talk, we will present two new techniques:
  1. A new breed of SAML implementation flaws that break XML signature validation and enable arbitrary modification of the SAML assertion, which enables attackers to authenticate as arbitrary users or grant themselves arbitrary authorization claims. Although any implementation may be affected by this flaw, we will show how it affects Microsoft Windows Identity Framework (WIF) applications, Windows Communication Foundation (WCF) web services, and flagship products such as SharePoint and Exchange Servers.
  2. A bug in the .NET crypto library, which may allow attackers to gain Remote Code Execution (RCE) or Denial of Service (DoS) depending on the availability of code gadgets in the target server.
A new tool to detect this type of vulnerability will also be discussed and released.

Caroline Oest

Micro Focus Customer Experience Marketing

If you find this post useful, give it a ‘Like’ or use ‘Verify Answer’


Comment List
Related Discussions