5 ms·
I hacked my company's SSO provider
- meitham 2y agoI wish the article provided the name of the vendor!
- l0b0 2y agoNice find! As for the provider, since they missed this extremely basic step (don't trust the client!!) I would expect they have many more undiscovered vulnerabilities.
- EQYV 2y agoThis is a completely unacceptable vulnerability in any software purporting itself to be an identity provider. OP, name and shame this provider. I do not want to find myself using it.
- nubinetwork 2y agoNever trust the (web) client, sanitize/validate the shit out of everything, and stop using JavaScript...
- pbalau 2y agoYou did not hack anything and that is far from being a security vulnerability, on the side of the SSO.
- globular-toast 2y agoThis is honestly the kind of mistake I'd expect a child to make. It shows a complete lack of understanding of how the web works. And this was put into production by a so-called security company? I think a name and shame is appropriate here. This isn't excusable, it's just straight up incompetence.