In this post we present the new version of the Burp Suite extension EsPReSSO - Extension for Processing and Recognition of Single Sign-On Protocols. A DTD attacker was implemented on SAML services that was based on the DTD Cheat Sheet by the Chair for Network and Data Security (https://web-in-security.blogspot.de/2016/03/xxe-cheat-sheet.html). In addition, many fixes were added and a new SAML editor was merged. You can find the newest version release here: https://github.com/RUB-NDS/BurpSSOExtension/releases/tag/v3.1
New SAML editor
Before the new release, EsPReSSO had a simple SAML editor where the decoded SAML messages could be modified by the user. We extended the SAML editor so that the user has the possibility to define the encoding of the SAML message and to select their HTTP binding (HTTP-GET or HTTP-POST).Redesigned SAML Encoder/Decoder |
Enhancement of the SAML attacker
XML Signature Wrapping and XML Signature Faking attacks have already been part of the previous EsPReSSO version. Now the user can also perform DTD attacks! The user can select from 18 different attack vectors and manually refine them all before applying the change to the original message. Additional attack vectors can also be added by extending the XML config file of the DTD attacker.The DTD attacker can also be started in a fully automated mode. This functionality is integrated in the BurpSuite Intruder.
DTD Attacker for SAML messages |
Supporting further attacks
We implemented a CertificateViewer which extracts and decodes the certificates contained within the SAML tokens. In addition, a user interface for executing SignatureExclusion attack on SAML has been implemented.Additional functions will follow in later versions.
Currently we are working on XML Encryption attacks.This is a combined work from Nurullah Erinola, Nils Engelbertz, David Herring, Juraj Somorovsky, and Vladislav Mladenov.
The research was supported by the European Commission through the FutureTrust project (grant 700542-Future-Trust-H2020-DS-2015-1).
More information
- Pentest Tools
- Hacking Tools Kit
- Hacking Tools Pc
- Hacking Tools Windows 10
- Blackhat Hacker Tools
- Pentest Tools Apk
- Hack Tools Mac
- Hacker Tools For Mac
- Hak5 Tools
- Pentest Tools Online
- Pentest Tools Subdomain
- Game Hacking
- Hackers Toolbox
- Pentest Automation Tools
- Pentest Reporting Tools
- Hacker Tools Mac
- Pentest Tools For Ubuntu
- Hacker Tools Free Download
- Hacking Tools Windows
- Growth Hacker Tools
- Hacking Tools Software
- Pentest Tools Free
- Hack Tool Apk No Root
- Hack And Tools
- Wifi Hacker Tools For Windows
- Pentest Tools Linux
- Hack Apps
- Hack Tools
- Hacker Tools
- Pentest Recon Tools
- Pentest Tools Nmap
- Nsa Hacker Tools
- Hacker Search Tools
- Android Hack Tools Github
- How To Hack
- Hacker Tools Free
- How To Install Pentest Tools In Ubuntu
- Physical Pentest Tools
- Hacking Tools For Kali Linux
- Hack And Tools
- Hacker Tools Linux
- Pentest Tools Linux
- Pentest Tools Online
- Pentest Tools Apk
- Hacks And Tools
- Blackhat Hacker Tools
- Pentest Tools Url Fuzzer
- Hacking Tools Windows
- Pentest Tools Website
- Hacker Tools
- Hacker Tools Linux
- Hackrf Tools
- Pentest Tools Open Source
- Hacker Tools Github
- Pentest Tools Review
- Hacker Tools 2019
- Top Pentest Tools
- Pentest Tools For Windows
- Pentest Tools Open Source
- Hacking Tools Online
- Physical Pentest Tools
- Physical Pentest Tools
- Hacking Tools Pc
- Pentest Tools Linux
- Physical Pentest Tools
- How To Hack
- Pentest Tools Download
- Hack Tool Apk No Root
- Beginner Hacker Tools
- Pentest Tools Android
- World No 1 Hacker Software
- Pentest Tools For Ubuntu
- Pentest Tools List
- Hacker Tools For Ios
- Pentest Tools For Windows
- Pentest Tools Url Fuzzer
- Easy Hack Tools
- Hack Tools Download
- Tools For Hacker
- Pentest Tools Nmap
- Hacker Techniques Tools And Incident Handling
- Hacking Tools And Software
- Hack Tools 2019
- Hacker Tools Apk
- Hacking Tools For Pc
- Pentest Reporting Tools
- Hack And Tools
- Hacking Tools Windows 10
- Pentest Automation Tools
- Underground Hacker Sites
- Android Hack Tools Github
- Beginner Hacker Tools
- Easy Hack Tools
- Github Hacking Tools
- Hacker Security Tools
- Hacker Tools 2020
- Hack Tools
- Pentest Tools Windows
- Hack Tools
- Hack Tools For Mac
- Hack Tools For Ubuntu
- Hacker Tool Kit
- Hacker Tool Kit
- Hacker Tools Mac
- Wifi Hacker Tools For Windows
- Hackers Toolbox
- Game Hacking
- Github Hacking Tools
- Hack Tools Download
- Wifi Hacker Tools For Windows
- Hack Tool Apk No Root
- Hack Tools
- Hacking Tools Mac
- Hack Tools Github
- Ethical Hacker Tools
- Hack Tool Apk
- Pentest Tools Alternative
- Hack And Tools
- Hack Tools
- Hack Tools Pc
- Hack Apps
- Hacking Tools Windows 10
- Hacker Tools Mac
- Hacker Tools Mac
- Hacking Tools Name
- Pentest Tools Download
- Hacker Techniques Tools And Incident Handling
- Hacking Tools And Software
- Hacking Tools For Pc
- Hacker Tools For Windows
- Hacking Tools
- Free Pentest Tools For Windows
- How To Make Hacking Tools
- Hacking Tools For Windows 7
- Hacker Hardware Tools
- Pentest Tools Port Scanner
- Best Hacking Tools 2020
- Hacker Tools 2020
- Pentest Tools For Android
- Hacker Tools Github
- Hacking Tools For Windows 7
- Pentest Tools Download
- Bluetooth Hacking Tools Kali
- Tools Used For Hacking
- Hacking Tools For Windows Free Download
- Pentest Tools Alternative
- Hacker Tools Free
- Best Hacking Tools 2020
- New Hack Tools
- Hacker Tools Free Download
- Pentest Recon Tools
- Hack Tools For Games
- Termux Hacking Tools 2019
- Hacker Tools List
- Kik Hack Tools