← Back to feed
research PortSwigger Research

The Fragile Lock: Novel Bypasses For SAML Authentication

PortSwigger Research

TLDR This post shows how to achieve a full authentication bypass in the Ruby and PHP SAML ecosystem by exploiting several parser-level inconsistencies: inclu...

T1556
Read the full story PortSwigger Research →

Related Coverage

research 24th August – Threat Intelligence Report Check Point Research · Aug 24 research How a team of entity maintainers monitors, connects and scores entities in Elastic Security Elastic Security Labs · Aug 24 research Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain Unit 42 · Aug 21