Tweet ghim

Using SimpleSAMLphp as an IdP? Please, read this carefully! simplesamlphp.org/security/20161…
English
SimpleSAMLphp
33 posts

@simplesamlphp
Open Source implementation of the SAML standard providing functionality as an Identity Provider, as a Service Provider and even as a proxy. Written in PHP.







After a longer time, we had again a look at SAML...resulted in a complete signature bypass in SimpleSAMLphp and xmlseclibs, and my coolest (public) Signature Wrapping exploit. Please patch. Writeup: hackmanit.de/en/blog-en/82-… (CVE-2019-3465) // cc @hackmanit


















