Whitelisting relaystate or equivalent

Paul Koh paul.koh at anacle.com
Thu Feb 2 22:37:56 EST 2017


Hi,

 

A web application security assessment tool has flagged the relaystate as
vulnerability, in that it could be hijacked to send the user to a url of the
attacker's choosing. 

 

I have checked previous threads and documentation on the web and understand
that following:

 

1.      The IdP is able to set/modify the relaystate sent to the SP after
authentication

2.      If the login flow begins from the SP, the IdP should send back the
same relaystate value sent from the SP

3.      If the login flow begins from the IdP, the IdP should set the
relaystate value

4.      The hijacking would have to occur at the point of the user being
redirected from the IdP to the SP after authentication - there is no way to
provide the user with a url which can spoof the initial redirection from the
SP for an unauthenticated user

 

I am using the Sibboleth SP v2.6.0.1, with the default ss:mem at the
relayState option. The tool's attach seems to have come from a custom cookie
with a relaystate value. Is there any way to whitelist the url in such a
case?

 

Regards,

 

Paul Koh

 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170203/402e5779/attachment-0001.html>


More information about the users mailing list