SAML Spoofing

Schwoerer, Brad schwoerb at uww.edu
Thu Jul 17 13:59:01 EDT 2014


It got generated out of the IDP logs on my system.  I figure the person is
trying to spoof my IDP and made a mistake somewhere in crafting the SAML
message and that it got accidently sent to my IDP instead of theirs.

Maybe I am reading the error message wrong.  It didn¹t look correct to me
and thought I would put it infront of eyes that understand some of that
better than me.


-Bradley


On 7/17/14, 12:54 PM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:

>On 7/17/14, 1:43 PM, "Schwoerer, Brad" <schwoerb at uww.edu> wrote:
>
>>I was wondering if anyone else was seeing jesterscourt.cc trying to spoof
>>their IdP.
>
>Where did you obtain that log? That would have to come from a system that
>believes it's hostname is jesterscourt. So in effect you'd have to access
>the logs of the miscreant. Sort of.
>
>You have a request generated from an SP that's meant to go to idp.uww.edu,
>but somehow it ends up at a different location. Is that a DNS attack?
>Wouldn't that trigger a certificate warning also?
>
>-- Scott
>
>--
>To unsubscribe from this list send an email to
>users-unsubscribe at shibboleth.net



More information about the users mailing list