How to test SSO/SAML Implementation for Web Apps?
https://www.reddit.com/r/Pentesting/comments/mcpn4c/how_to_test_ssosaml_implementation_for_web_apps/
<!-- SC_OFF -->I am currently on an assessment for a large organization. I am tasked to specifically test the authentication mechanism for several web apps which are now starting to use ADFS/SSO and SAML. However, are there actually vulnerabilities associated with this? I assume they are using existing framework to implement it? Basically, lost on how exactly to test it, as it is generating a randomly generated token in Burp as far as I can see. Can't edit anything with SAMLRaider extension. I just want to learn more about how to properly test it as don't have skillset to reverse engineer it. Any good blogs, videos, threads where I can learn to test them properly? Thanks! <!-- SC_ON --> submitted by /u/SlickTA (https://www.reddit.com/user/SlickTA)
[link] (https://www.reddit.com/r/Pentesting/comments/mcpn4c/how_to_test_ssosaml_implementation_for_web_apps/) [comments] (https://www.reddit.com/r/Pentesting/comments/mcpn4c/how_to_test_ssosaml_implementation_for_web_apps/)
https://www.reddit.com/r/Pentesting/comments/mcpn4c/how_to_test_ssosaml_implementation_for_web_apps/
<!-- SC_OFF -->I am currently on an assessment for a large organization. I am tasked to specifically test the authentication mechanism for several web apps which are now starting to use ADFS/SSO and SAML. However, are there actually vulnerabilities associated with this? I assume they are using existing framework to implement it? Basically, lost on how exactly to test it, as it is generating a randomly generated token in Burp as far as I can see. Can't edit anything with SAMLRaider extension. I just want to learn more about how to properly test it as don't have skillset to reverse engineer it. Any good blogs, videos, threads where I can learn to test them properly? Thanks! <!-- SC_ON --> submitted by /u/SlickTA (https://www.reddit.com/user/SlickTA)
[link] (https://www.reddit.com/r/Pentesting/comments/mcpn4c/how_to_test_ssosaml_implementation_for_web_apps/) [comments] (https://www.reddit.com/r/Pentesting/comments/mcpn4c/how_to_test_ssosaml_implementation_for_web_apps/)
HTML injection via email
Hi everyone, I am suraj . Hope you are doing well in this carona pandemic. so here i will be demonstrating how i was able to perform html…Continue reading on Medium »
Read more...
Hi everyone, I am suraj . Hope you are doing well in this carona pandemic. so here i will be demonstrating how i was able to perform html…Continue reading on Medium »
Read more...
Subdomain Enumeration Methodology
https://thetowsif.medium.com/subdomain-enumeration-methodology-e1a23a78c37a?source=rss------bug_bounty-5
How i enumerate subdomains with custom scriptContinue reading on Medium » (https://thetowsif.medium.com/subdomain-enumeration-methodology-e1a23a78c37a?source=rss------bug_bounty-5)
https://thetowsif.medium.com/subdomain-enumeration-methodology-e1a23a78c37a?source=rss------bug_bounty-5
How i enumerate subdomains with custom scriptContinue reading on Medium » (https://thetowsif.medium.com/subdomain-enumeration-methodology-e1a23a78c37a?source=rss------bug_bounty-5)
Subdomain Enumeration Methodology
How i enumerate subdomains with custom scriptContinue reading on Medium »
Read more...
How i enumerate subdomains with custom scriptContinue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HTML injection via email
https://cdn-images-1.medium.com/max/1024/0*i8pYLNaHoyz4lVbk.png
Hi everyone, I am suraj . Hope you are doing well in this carona pandemic. so here i will be demonstrating how i was able to perform html…
Continue reading on Medium »
HTML injection via email
https://cdn-images-1.medium.com/max/1024/0*i8pYLNaHoyz4lVbk.png
Hi everyone, I am suraj . Hope you are doing well in this carona pandemic. so here i will be demonstrating how i was able to perform html…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
[TryHackMe]- Bounty Hacker
https://cdn-images-1.medium.com/max/1219/1*IxUScBh5Cl5SLQCQsAwzBw.png
Langkah pertama lakukan enumerasi pada 10.10.130.216 dengan cara melakukan scanning pada port (Nmap) dan juga scanning directory…
Continue reading on Medium »
[TryHackMe]- Bounty Hacker
https://cdn-images-1.medium.com/max/1219/1*IxUScBh5Cl5SLQCQsAwzBw.png
Langkah pertama lakukan enumerasi pada 10.10.130.216 dengan cara melakukan scanning pada port (Nmap) dan juga scanning directory…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
История жизни и смерти хакера, взломавшего пентагон и NASA в 15 лет
https://cdn-images-1.medium.com/max/1052/1*mhOy3CmqObQXDzK2X4td6w.png
Как правило, хакеры стараются вести скрытный образ жизни и соблюдать анонимность. Многим это удается, но некоторые из них обретают…
Continue reading on Medium »
История жизни и смерти хакера, взломавшего пентагон и NASA в 15 лет
https://cdn-images-1.medium.com/max/1052/1*mhOy3CmqObQXDzK2X4td6w.png
Как правило, хакеры стараются вести скрытный образ жизни и соблюдать анонимность. Многим это удается, но некоторые из них обретают…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Subdomain Enumeration Methodology
How i enumerate subdomains with custom script
Continue reading on Medium »
Subdomain Enumeration Methodology
How i enumerate subdomains with custom script
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Deep Web
Block DX as a Crypto Currency Provider for TOR Transactions?
first time user. is it good to use a decentralized bitcoin exchange to transact on deep web? does this track my identity? I'm doubtly to use coinbase on transacting because they use KYC.
https://blockdx.com/
submitted by /u/St3gm4
[link] [comments]
Block DX as a Crypto Currency Provider for TOR Transactions?
first time user. is it good to use a decentralized bitcoin exchange to transact on deep web? does this track my identity? I'm doubtly to use coinbase on transacting because they use KYC.
https://blockdx.com/
submitted by /u/St3gm4
[link] [comments]
hacking: security in practice
A missing/runaway child
Hi all,
Someone recently posted about a missing and runaway child. Is it possible to somehow track and find their location through social media, etc.? Also if this is not the right place, could someone direct to me correct subreddit? Thank you.
d
submitted by /u/diamondplatter
[link] [comments]
A missing/runaway child
Hi all,
Someone recently posted about a missing and runaway child. Is it possible to somehow track and find their location through social media, etc.? Also if this is not the right place, could someone direct to me correct subreddit? Thank you.
d
submitted by /u/diamondplatter
[link] [comments]
reddit
A missing/runaway child
Hi all, Someone recently posted about a missing and runaway child. Is it possible to somehow track and find their location through social media,...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Editing metadata with gThumb!
https://cdn-images-1.medium.com/max/1358/1*119wQ5kiTqYUMKhM5DdYPg.png
We have learnt about metadata and stuff in one of the previous blog post. Today we’ll see how to edit metadata using a free software…
Continue reading on Medium »
Editing metadata with gThumb!
https://cdn-images-1.medium.com/max/1358/1*119wQ5kiTqYUMKhM5DdYPg.png
We have learnt about metadata and stuff in one of the previous blog post. Today we’ll see how to edit metadata using a free software…
Continue reading on Medium »
Gitrecon - OSINT Tool To Get Information From A Github Profile And Find GitHub User'S Email Addresses Leaked On Commits
http://www.kitploit.com/2021/03/gitrecon-osint-tool-to-get-information.html
http://www.kitploit.com/2021/03/gitrecon-osint-tool-to-get-information.html