« Home | WiFi Hacking On Tablets » | W3AF » | Top 20 Best Free Hacking Apps For Android |2019| » | APPLE IPHONE X FACE ID CAN BE HACKED WITH SILICON ... » | AlienSpy Java RAT Samples And Traffic Information » | RtlDecompresBuffer Vulnerability » | Backtrack4 » | 5 BEST HACKING BOOKS 2018 » | El Perfume Del Vino - Duda Ante La Experiencia Sen... » | How tO Secure Yourself From Evil Twin Attack »

Support For XXE Attacks In SAML In Our Burp Suite Extension


In this post we present the new version of the Burp Suite extension EsPReSSO - Extension for Processing and Recognition of Single Sign-On Protocols. A DTD attacker was implemented on SAML services that was based on the DTD Cheat Sheet by the Chair for Network and Data Security (https://web-in-security.blogspot.de/2016/03/xxe-cheat-sheet.html). In addition, many fixes were added and a new SAML editor was merged. You can find the newest version release here: https://github.com/RUB-NDS/BurpSSOExtension/releases/tag/v3.1

New SAML editor

Before the new release, EsPReSSO had a simple SAML editor where the decoded SAML messages could be modified by the user. We extended the SAML editor so that the user has the possibility to define the encoding of the SAML message and to select their HTTP binding (HTTP-GET or HTTP-POST).

Redesigned SAML Encoder/Decoder

Enhancement of the SAML attacker

XML Signature Wrapping and XML Signature Faking attacks have already been part of the previous EsPReSSO version. Now the user can also perform DTD attacks! The user can select from 18 different attack vectors and manually refine them all before applying the change to the original message. Additional attack vectors can also be added by extending the XML config file of the DTD attacker.
The DTD attacker can also be started in a fully automated mode. This functionality is integrated in the BurpSuite Intruder.

DTD Attacker for SAML messages

Supporting further attacks

We implemented a CertificateViewer which extracts and decodes the certificates contained within the SAML tokens. In addition, a user interface for executing SignatureExclusion attack on SAML has been implemented.

Additional functions will follow in later versions.

Currently we are working on XML Encryption attacks.

This is a combined work from Nurullah Erinola, Nils Engelbertz, David Herring, Juraj Somorovsky, and Vladislav Mladenov.

The research was supported by the European Commission through the FutureTrust project (grant 700542-Future-Trust-H2020-DS-2015-1).
Related news
  1. Hacking App
  2. Free Pentest Tools For Windows
  3. Hack Tools Download
  4. Pentest Tools Apk
  5. Hack Tools Pc
  6. Hacking Tools For Windows 7
  7. Physical Pentest Tools
  8. Nsa Hacker Tools
  9. Hacker Tools Hardware
  10. Pentest Tools For Ubuntu
  11. Hacking App
  12. Hacks And Tools
  13. Hacker Techniques Tools And Incident Handling
  14. Pentest Tools Alternative
  15. Hacking Tools
  16. Underground Hacker Sites
  17. Hacker Security Tools
  18. Hacker Hardware Tools
  19. Hacking Tools Free Download
  20. Hacking Tools Free Download
  21. Hacking Tools For Beginners
  22. Pentest Tools Download
  23. Hacking Tools Pc
  24. Nsa Hacker Tools
  25. Hacking Tools Free Download
  26. Hack Tools Download
  27. Blackhat Hacker Tools
  28. Bluetooth Hacking Tools Kali
  29. Hacking Tools Github
  30. Hacker Tools For Pc
  31. Pentest Tools Download
  32. Pentest Recon Tools
  33. Hacker Tools For Windows
  34. Pentest Tools For Windows
  35. Pentest Tools Github
  36. Hacker Tools Hardware
  37. Hacker Search Tools
  38. Hacking Tools For Kali Linux
  39. Hak5 Tools
  40. Underground Hacker Sites
  41. Hacker Tools List
  42. Ethical Hacker Tools
  43. Blackhat Hacker Tools
  44. Hack Tools Online
  45. Wifi Hacker Tools For Windows
  46. Pentest Reporting Tools
  47. Hacking Tools Usb
  48. Github Hacking Tools
  49. Game Hacking
  50. Hack Tools
  51. Hack Tools 2019
  52. Pentest Box Tools Download
  53. Pentest Tools For Ubuntu
  54. Install Pentest Tools Ubuntu
  55. Pentest Tools Subdomain
  56. Hacking Tools Name
  57. Pentest Tools Android
  58. Pentest Tools For Android
  59. Pentest Tools For Windows
  60. Hackers Toolbox
  61. Hacking Tools Name
  62. Hack Tools 2019
  63. Pentest Tools Download
  64. Hacker Tools Apk Download