Web Saml

Attack SAML SSO — signature exclusion/wrapping (XSW), unsigned assertions, and comment/XXE tricks to forge authentication. Load on SAML SSO (SAMLResponse, ACS URL, IdP/SP), enterprise login, or "SAML". Signals: SAMLResponse base64 in POST, /saml/acs, <saml:Assertion>, Shibboleth/ADFS/Okta SSO.

NoorQureshi 62e89ac 2.3 KB Updated

File contents

NoorQureshi/SploitAgent/tree/main/skills/web/web-saml commit 62e89ac5e8

Frequently asked questions

npx skillmds@latest add noorqureshi/web-saml