SAMLRaider icon indicating copy to clipboard operation
SAMLRaider copied to clipboard

SAML2 Burp Extension

Results 24 SAMLRaider issues
Sort by recently updated
recently updated
newest added

It's not possible to clone the certificate if the serial number of the certificate is negative.

bug

Implement https://github.com/pwntester/DupeKeyInjector in SAMLRaider, so only one tool is needed for testing SAML.

enhancement
help wanted

The popular SAML library SimpleSAMLphp had an auth bypass vuln in Nov 2019 [here](https://simplesamlphp.org/security/201911-01). This is a novel XSW attack that could be added into SAMLRaider functionality. I was able...

enhancement
help wanted

In real-world cases, the SAMLResponse is often only valid for 10 seconds or similar. It would be nice to have a way to use the XSW attacks in an automated...

enhancement

I haven't found a pattern yet, but the "Parsed & Prettified" XML section of the "SAML Message Info" tab will be blank. It doesn't appear to be anything wrong with...

bug
help wanted

Add new XSW10 attack. This can e.g. be used to exploit CVE-2021-28091 (https://git.entrouvert.org/lasso.git/tree/NEWS?id=v2.7.0): ``` 2.7.0 - June 1st 2021 ---------------------- 36 commits, 45 files changed, 1945 insertions, 177 deletions *...

enhancement

![image](https://user-images.githubusercontent.com/84201009/193213908-e2d13ec1-7df6-40f3-9431-98be4ac7c9db.png) ![image](https://user-images.githubusercontent.com/84201009/193213994-30c0c189-9e81-4173-a059-07ba3de6ca5d.png) I think the format of certificate is right.When I selected the certificate and clicked `Send Certificate to SAML Raider Certificates`, error appeared

bug

Using v1.4.1 of SAMLRaider in Burp Suite Pro v2023.5.2 (although the bug has shown up in versions before 2023.5.2, as well). When the SAMLRaider extension is enabled and the proxy...

Bumps org.apache.santuario:xmlsec from 2.1.7 to 2.2.6. [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=org.apache.santuario:xmlsec&package-manager=maven&previous-version=2.1.7&new-version=2.2.6)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a...

dependencies

Hi all. In the current state of the awesome SAMLRaider, it is not possible to remove signatures from an AuthnRequest, but it is not possible to re-sign them with a...

enhancement