O365 vulnerability article analysis

Nate Klingenstein ndk at sudonym.me
Mon May 2 13:31:24 EDT 2016


Josh,

It already landed here in another thread.

http://marc.info/?l=shibboleth-users&m=146177758931043

You’ll get the color commentary of the list in the thread.  It would be a good place to ask for more details.

Take care,
Nate.

> On May 2, 2016, at 11:05, O'Dowd, Josh <Josh.O'Dowd at mso.umt.edu> wrote:
> 
> Can you guys chime in on this article[1].  I am looking for clarity of the problem, because the author didn’t seem qualified to describe it.  Also I am looking for best practice to avoid such a scenario, specifically from an IdP administrator’s perspective.  Not to mention that our campus is in the planning stages for an Office365 integration with our IdP.
>  
> Thanks for your time.
>  
> Josh O’Dowd
> Software Systems Engineer
> Central IT, University of Montana
>  
> [1] https://threatpost.com/office-365-vulnerability-exposed-any-federated-account/117716/ <https://threatpost.com/office-365-vulnerability-exposed-any-federated-account/117716/>-- 
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net <mailto:users-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160502/d5cc4544/attachment-0001.html>


More information about the users mailing list