Ensuring that our IdP can not be used to redirect users to an arbitrary URL
Max Spicer
max.spicer at york.ac.uk
Mon Feb 15 16:40:06 UTC 2021
The Shibboleth SP has the redirectLimit attribute on the Sessions
<https://wiki.shibboleth.net/confluence/display/SP3/Sessions> element which
can be used to prevent misuse of the SP to carry out phishing attacks. We
used this to ensure the SP's Logout endpoint couldn't be exploited via the
return parameter.
Are there any similar situations to be aware of with the IdP's available
endpoints under 4.0? I do not believe that the /profile/Logout endpoint
could be exploited in this way, but I do vaguely recall that a similar
endpoint with a return parameter did once exist in the IdP.
Thanks,
Max Spicer
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210215/5483df93/attachment.htm>
More information about the users
mailing list