Web Hack List

Other nomination

SSO Wars: The Token Menace

Two flaws in .NET single sign-on. An unvalidated algorithm name from a JWT header or an XML SignatureMethod reaches CryptoConfig, letting an attacker instantiate arbitrary types; Dupe Key Confusion adds a second KeyInfo element so signature validation uses the attacker's own key. Lets an attacker forge SAML assertions and log in as any user, plus denial of service and code execution.

Record

Researcher
Oleksandr Mirosh and Alvaro Muñoz
Format
Whitepaper

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Oleksandr Mirosh and Alvaro Muñoz, first published at the original source. Preserved copies are kept so the citation survives its host.