Top 10 winner
Hacking the Cloud with SAML
A SAML service provider must run attacker-supplied XMLDsig transforms before it knows the signature can be trusted, putting XML canonicalisation, XSLT and their parsers on the pre-authentication attack surface. The talk turns that into .NET external entity injection, a libxml2 heap overflow and a constant-pool truncation bug in the JVM XSLT compiler that yields arbitrary bytecode.
Record
- Researcher
- Felix Wilhelm
- Published by
- Hexacon 2022
- Date
- Format
- Recording
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Felix Wilhelm, first published at the original source. Preserved copies are kept so the citation survives its host.