Security Assertion Markup Language (SAML) is an XML-based open-standard for transferring identity data between two parties. SAML is what enables users to seamlessly authenticate to various web services, creating a secure and hassle-free experience.
This course will take you through the full experience of securing the SAML workflow, including offensive and defensive techniques. We start off by understanding what SAML is, how it works, and go through a typical authentication flow used in real-world apps.
Next, we’ll explore the critical points in a practical SAML workflow. This is where you’ll learn how to attack the SAML authentication flow, followed by an exercise where you defend the SAML flow against attacks.
These lessons are brought to you through practical hands-on labs inspired by real-world security scenarios.
SAML Attacks and defense
Signature removal
Signature replace