← Back to feed
research PortSwigger Research

The Fragile Lock: Novel Bypasses For SAML Authentication

PortSwigger Research

TLDR This post shows how to achieve a full authentication bypass in the Ruby and PHP SAML ecosystem by exploiting several parser-level inconsistencies: inclu...

T1556
Read the full story PortSwigger Research →

Related Coverage

research Agent Running in the Age of AI Recorded Future · Sep 22 research 21st September – Threat Intelligence Report Check Point Research · Sep 21 research SAML: A fractal of bad design Trail of Bits · Sep 21