← Back to feed
research PortSwigger Research

The Fragile Lock: Novel Bypasses For SAML Authentication

PortSwigger Research •

TLDR This post shows how to achieve a full authentication bypass in the Ruby and PHP SAML ecosystem by exploiting several parser-level inconsistencies: inclu...

T1556
Read the full story PortSwigger Research →

Related Coverage

research Introducing AlertZero: Inbox zero for your alert queue Elastic Security Labs · Oct 8 research Japan Adopts Proactive Cyber Defense Strategy Recorded Future · Oct 8 research Evolution of Web3 in Cloud Supply Chain Attacks Unit 42 · Oct 7