SAML: Signature Stripping

Bookmarked!

This exercise covers the exploitation of a signature stripping vulnerability in SAML

PRO Medium < 1 Hr. 2094 Authentication / Authorization Badge
Course

This course explores the exploitation of an insecure SAML implementation, enabling a malicious user to impersonate another user by tampering with the SAMLResponse. The exercise demonstrates how to alter the email address within the SAML response and bypass signature verification.

Skills covered
Authentication Cryptography Operating System Network
Included with PRO
Full course content 3 videos

Ready to practice?

Get access to this lab and 600+ hands-on exercises with a PRO subscription.