Regarding Shibboleth IDP Login Page.

Cantor, Scott cantor.2 at osu.edu
Tue Dec 18 10:10:29 EST 2012


>Seriously, we just got phished in this way (phisher cloned our IdP page
>and once you entered creds would POST them to the IdP. As a response we
>ended up modifying error.jsp to say something like, "Does this email look
>familiar <img src="phishMsg.png" />?
>  If so, call IT Security".

David, can you file a RFE so I remember to add a nonce of some sort to the
default page? I can't rely on a key like my custom handler can, but we
have the login context to use, so I can do something based on that.

-- Scott




More information about the users mailing list