SAML IV: Finding the private key by using the certificate in a SAMLResponse

Return to Exercise
image of exercise SAML IV: Finding the private key by using the certificate in a SAMLResponse

This video requires PentesterLab PRO

GO PRO
Spoiler
SAML IV: Finding the private key by using the certificate in a SAMLResponse

In this video, we explore the SAML IV challenge from the authentication and authorization badge. We demonstrate how to extract a certificate from a SAML Response and determine if the application uses a default certificate and private key to sign the response.

video duration icon05:16 number of views icon990