论坛首页 Web安全讨论区 阅读主题

The Fragile Lock: Novel Bypasses For SAML Authentication

12 浏览 0 回复
#1 楼主 2026-04-16 13:39:03
TLDR This post shows how to achieve a full authentication bypass in the Ruby and PHP SAML ecosystem by exploiting several parser-level inconsistencies: including attribute pollution, namespace confusi

---
来源: PortSwigger
原文链接: https://portswigger.net/research/the-fragile-lock

暂无回复,快来抢沙发吧!

请登录后参与讨论

立即登录 注册账号