saml-sso-assertion-attacks
SAML SSO assertion attack playbook. Use when testing signature validation, assertion wrapping, audience restrictions, ACS handling, XML trust boundaries, and enterprise SSO flaws.
来源信息
- 仓库
- Kur1sulab/blackbox
- 最近来源活动
- 2026年8月12日 15:17
- 检测到的 SKILL.md 语言
- 英语
- 星标
- 3
- 分支
- 1
安装方式
默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。
检查来源文件
决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。
正在显示 SKILL.md
SKILL.md
来源说明 · 只读预览- name
- saml-sso-assertion-attacks
- description
- SAML SSO assertion attack playbook. Use when testing signature validation, assertion wrapping, audience restrictions, ACS handling, XML trust boundaries, and enterprise SSO flaws.
# SKILL: SAML SSO and Assertion Attacks — Signature Validation, Binding, and Trust Confusion
> **AI LOAD INSTRUCTION**: Use this skill when the target uses SAML-based SSO and you need to validate assertion trust: signature coverage, audience and recipient checks, ACS handling, XML parsing weaknesses, and IdP/SP confusion.
## 1. WHEN TO LOAD THIS SKILL
Load when:
- Enterprise SSO uses SAML requests or responses
- You see `SAMLRequest`, `SAMLResponse`, XML assertions, or ACS endpoints
- Login flows involve an external IdP and browser POST/redirect binding
## 2. HIGH-VALUE MISCONFIGURATION CHECKS
| Theme | What to Check |
|---|---|
| signature validation | unsigned assertion accepted, wrong node signed, signature wrapping |
| audience and recipient | weak `Audience`, `Recipient`, `Destination`, or ACS validation |
| issuer trust | wrong IdP accepted or multi-tenant issuer confusion |
| replay and freshness | missing `InResponseTo`, weak `NotBefore` / `NotOnOrAfter` enforcement |
| account mapping | email-only binding, case folding, unverified attributes |
| XML parser behavior | XXE-like parser issues or unsafe transforms around SAML documents |
## 3. QUICK TRIAGE
1. Capture one full login round trip.
2. Inspect which XML nodes are signed and which attributes drive account binding.
3. Compare SP-initiated and IdP-initiated flows.
4. Test replay, altered attributes, and assertion placement confusion.
## 4. RELATED ROUTES
- XML parser attack depth: [xxe xml external entity](../hack-xxe-xml-external-entity/SKILL.md)
- OAuth or OIDC SSO alternatives: [oauth oidc misconfiguration](../hack-oauth-oidc-misconfiguration/SKILL.md)
- Auth boundary issues after SSO: [authbypass authentication flaws](../hack-authbypass-authentication-flaws/SKILL.md)
在 GitHub 查看