Regarding Shibboleth IDP Login Page.

David Langenberg davel at uchicago.edu
Tue Dec 18 09:58:07 EST 2012


On Tue, Dec 18, 2012 at 6:17 AM, Peter Schober
<peter.schober at univie.ac.at>wrote:

> * Naresh Thota <nareshthota005 at gmail.com> [2012-12-18 12:58]:
> > I am using Shibboleth IDP as My Id Provider and Configured Service
> Provider
> > by using Spring Saml Support. I am trying to authenticate the user by
> using
> > idp who is requesting a service from My Service Provider. So while
> > accessing the service user has prompted to enter the "User Name" &
> > "Password" from Service Provider Side. Then I will hold the details and
> > submit the request to the Shibboleth IDP. IDP is simply redirecting to
> > Shibboleth Login Page. I want that login page to be filled with the
> values
> > which are entered by the user initially. How can I do this.
>
> Search the web for "phishing howto",
> -peter
>

Seriously, we just got phished in this way (phisher cloned our IdP page and
once you entered creds would POST them to the IdP. As a response we ended
up modifying error.jsp to say something like, "Does this email look
familiar <img src="phishMsg.png" />?  If so, call IT Security".

Dave

-- 
David Langenberg
Identity & Access Management
The University of Chicago
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20121218/0e4cb3f4/attachment.html 


More information about the users mailing list