Главная
Study mode:
on
1
Intro
2
Agenda
3
Delegated Authentication
4
JWT token
5
Similar code for SAML
6
Potential Attack Vectors (2/2)
7
Simplified SAML Token
8
SAML Signature Verification in .NET
9
A tale of two resolvers
10
Possible scenarios for different key resolution
11
Examples of affected frameworks
12
Windows Communication Foundation (WCF)
13
Key & Token Resolution
14
Token resolution - Breadth First
15
Dupe Key Confusion
16
Key and Token resolutions
17
Attack limitations
18
SharePoint Authentication Flow
19
SharePoint Attack Flow
20
Conclusions
Description:
Explore the intricacies of Single Sign-On (SSO) security in this comprehensive conference talk from BSidesLV 2019. Delve into the world of delegated authentication, focusing on JWT and SAML tokens. Examine potential attack vectors, including signature verification vulnerabilities in .NET frameworks. Analyze key resolution methods and their impact on security. Investigate specific scenarios involving Windows Communication Foundation (WCF) and SharePoint authentication flows. Gain valuable insights into dupe key confusion attacks and their limitations. Equip yourself with essential knowledge to fortify SSO implementations against token-based threats.

SSO Wars - The Token Menace

BSidesLV
Add to list