Главная
Study mode:
on
1
Intro
2
Quick Recap - Federated Login
3
Additional CSRF Scenarios
4
OAuth Code Grant Flow
5
Recommended State parameter
6
OpenID connect login flow
7
Risk in the current scenario
8
Recommended Parameter from OpenID Connect Spec
9
Federated Login CSRF (Pre-Conditions)
10
Attacker configuration
11
Attack data flow sequence
12
Risks
13
Demo
14
Mitigation 1: Show a 2nd Consent dialog before linking identities
15
Conclusions
Description:
Explore a comprehensive analysis of Federated Login CSRF vulnerabilities in this 30-minute conference talk from AppSecUSA 2017. Delve into the concept of Login CSRF and its application to federated identity systems using OpenID Connect and OAuth 2.0. Examine the conditions that can lead to Federated Login CSRF, potential risks, and effective mitigation strategies. Learn from Microsoft Senior Security Engineer Murali Vadakke Puthanveetil as he walks through the intricacies of this security issue, including a detailed breakdown of OAuth Code Grant Flow, OpenID Connect login flow, and the importance of recommended parameters. Gain valuable insights into attack configurations, data flow sequences, and practical demonstrations. Understand how to implement robust security measures, such as implementing a second consent dialog before linking identities, to protect against these sophisticated attacks in federated login systems.

Federated Login CSRF

OWASP Foundation
Add to list