<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span style="color: rgb(0, 0, 0); font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt;">We continue to see scan findings come back from our security department regarding Shibboleth.  The scan results included the results below.  We are currently
 on </span><span style="color: rgb(0, 0, 0); font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt;">Shibboleth SP 3.2.3.1 release:
<a href="https://shibboleth.net/downloads/service-provider/latest/" id="LPlnk572524">
https://shibboleth.net/downloads/service-provider/latest/</a> . Has anyone else seen these results?</span></div>
<div dir="ltr">
<div dir="ltr">
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<span style="color:rgb(0,0,0); font-size:12pt"><br>
</span></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<table width="100%" class="x_x_results" style="border:none; font-size:13px; font-family:"Helvetica Neue",Helvetica,Arial,sans-serif">
<tbody>
<tr height="24" class="x_x_risk-medium" style="background-color:orange; color:rgb(255,255,255)">
<th width="20%" style="padding:3px 4px; word-break:break-word; font-weight:bold; text-align:left">
Medium (Medium)</th>
<th width="80%" style="padding:3px 4px; word-break:break-word; font-weight:bold; text-align:left">
Buffer Overflow</th>
</tr>
<tr>
<td width="20%" style="padding:3px 4px; word-break:break-word">Description</td>
<td width="80%" style="padding:3px 4px; word-break:break-word">
<p style="margin-top: 0px; margin-bottom: 0px;margin-top:0px; margin-bottom:0px">
Buffer overflow errors are characterized by the overwriting of memory spaces of the background web process, which should have never been modified intentionally or unintentionally. Overwriting values of the IP (Instruction Pointer), BP (Base Pointer) and other
 registers causes exceptions, segmentation faults, and other process errors to occur. Usually these errors end execution of the application in an unexpected way.</p>
</td>
</tr>
<tr valign="top">
<td colspan="2" style="padding:3px 4px; word-break:break-word"></td>
</tr>
<tr>
<td width="20%" class="x_x_indent1" style="padding:4px 20px; word-break:break-word">
URL</td>
<td width="80%" style="padding:3px 4px; word-break:break-word">https://profiles.umassmed.edu/Shibboleth.sso/SAML2/POST</td>
</tr>
<tr>
<td width="20%" class="x_x_indent2" style="padding:4px 40px; word-break:break-word">
Method</td>
<td width="80%" style="padding:3px 4px; word-break:break-word">POST</td>
</tr>
<tr>
<td width="20%" class="x_x_indent2" style="padding:4px 40px; word-break:break-word">
Parameter</td>
<td width="80%" style="padding:3px 4px; word-break:break-word">SAMLResponse</td>
</tr>
<tr>
<td width="20%" class="x_x_indent2" style="padding:4px 40px; word-break:break-word">
Attack</td>
<td width="80%" style="padding:3px 4px; word-break:break-word">POST https://profiles.umassmed.edu/Shibboleth.sso/SAML2/POST HTTP/1.1 Connection: keep-alive Content-Length: 2200 Cache-Control: max-age=0 sec-ch-ua: " Not A;Brand";v="99", "Chromium";v="96", "Google
 Chrome";v="96" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Windows" Upgrade-Insecure-Requests: 1 Origin: https://sm-tst11.ucollaborate.net Content-Type: application/x-www-form-urlencoded User-Agent: Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36
 (KHTML, like Gecko) Chrome/96.0.4664.45 Safari/537.36 Accept: </td>
</tr>
</tbody>
</table>
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
<table width="100%" class="x_x_results" style="border:none; font-size:13px; font-family:"Helvetica Neue",Helvetica,Arial,sans-serif">
<tbody>
<tr>
<td width="80%" style="padding:3px 4px; word-break:break-word"></td>
</tr>
</tbody>
</table>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<table class="x_x_results" style="border: none; font-size: 13px; font-family: "Helvetica Neue", Helvetica, Arial, sans-serif; box-sizing: border-box; width: 838px; height: 339.2px;">
<tbody>
<tr class="x_x_risk-high" style="background-color:red; color:rgb(255,255,255)">
<th style="padding: 3px 4px; word-break: break-word; font-weight: bold; text-align: left; box-sizing: border-box; width: 166.637px; height: 24px;">
High (Medium)</th>
<th style="padding: 3px 4px; word-break: break-word; font-weight: bold; text-align: left; box-sizing: border-box; width: 666.562px; height: 24px;">
SQL Injection</th>
</tr>
<tr>
<td style="padding: 3px 4px; word-break: break-word; box-sizing: border-box; width: 166.637px; height: 21.2px;">
Description</td>
<td style="padding: 3px 4px; word-break: break-word; box-sizing: border-box; width: 666.562px; height: 21.2px;">
<p style="margin-top: 0px; margin-bottom: 0px;margin-top:0px; margin-bottom:0px">
SQL injection may be possible.</p>
</td>
</tr>
<tr valign="top">
<td colspan="2" style="padding: 3px 4px; word-break: break-word; box-sizing: border-box; width: 834.8px; height: 6px;">
<br>
</td>
</tr>
<tr>
<td class="x_x_indent1" style="padding: 4px 20px; word-break: break-word; box-sizing: border-box; width: 166.637px; height: 23.2px;">
URL</td>
<td style="padding: 3px 4px; word-break: break-word; box-sizing: border-box; width: 666.562px; height: 23.2px;">
https://profiles.umassmed.edu/Shibboleth.sso/SAML2/POST</td>
</tr>
<tr>
<td class="x_x_indent2" style="padding: 4px 40px; word-break: break-word; box-sizing: border-box; width: 166.637px; height: 23.2px;">
Method</td>
<td style="padding: 3px 4px; word-break: break-word; box-sizing: border-box; width: 666.562px; height: 23.2px;">
POST</td>
</tr>
<tr>
<td class="x_x_indent2" style="padding: 4px 40px; word-break: break-word; box-sizing: border-box; width: 166.637px; height: 23.2px;">
Parameter</td>
<td style="padding: 3px 4px; word-break: break-word; box-sizing: border-box; width: 666.562px; height: 23.2px;">
RelayState</td>
</tr>
<tr>
<td class="x_x_indent2" style="padding: 4px 40px; word-break: break-word; box-sizing: border-box; width: 166.637px; height: 23.2px;">
Attack</td>
<td style="padding: 3px 4px; word-break: break-word; box-sizing: border-box; width: 666.562px; height: 23.2px;">
ss:mem:714a0f4dcc377cbf4da5711788e1a5fafbaf4210e55721ab1ed425e639022676 AND 1=1 --</td>
</tr>
<tr>
<td style="padding: 3px 4px; word-break: break-word; box-sizing: border-box; width: 166.637px; height: 21.2px;">
Instances</td>
<td style="padding: 3px 4px; word-break: break-word; box-sizing: border-box; width: 666.562px; height: 21.2px;">
1</td>
</tr>
<tr>
<td style="padding: 3px 4px; word-break: break-word; box-sizing: border-box; width: 166.637px; height: 142.8px;">
Solution</td>
<td style="padding: 3px 4px; word-break: break-word; box-sizing: border-box; width: 666.562px; height: 142.8px;">
<p style="margin-top: 0px; margin-bottom: 0px;margin-top:0px; margin-bottom:0px">
Do not trust client side input, even if there is client side validation in place.</p>
<p style="margin-top: 0px; margin-bottom: 0px;margin-top:0px; margin-bottom:0px">
In general, type check all data on the server side.</p>
<p style="margin-top: 0px; margin-bottom: 0px;margin-top:0px; margin-bottom:0px">
If the application uses JDBC, use PreparedStatement or CallableStatement, with parameters passed by '?'</p>
<p style="margin-top: 0px; margin-bottom: 0px;margin-top:0px; margin-bottom:0px">
If the application uses ASP, use ADO Command Objects with strong type checking and parameterized queries.</p>
<p style="margin-top: 0px; margin-bottom: 0px;margin-top:0px; margin-bottom:0px">
If database Stored Procedures can be used, use them.</p>
<p style="margin-top: 0px; margin-bottom: 0px;margin-top:0px; margin-bottom:0px">
Do *not* concatenate strings into queries in the stored procedure, or use 'exec', 'exec immediate', or equivalent functionality!</p>
<p style="margin-top: 0px; margin-bottom: 0px;margin-top:0px; margin-bottom:0px">
Do not create dynamic SQL queries using simple string concatenation.</p>
<p style="margin-top: 0px; margin-bottom: 0px;margin-top:0px; margin-bottom:0px">
<br>
</p>
</td>
</tr>
</tbody>
</table>
<br>
</div>
<div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Pete Bowers</div>
<div id="x_x_Signature"></div>
</div>
</div>
</div>
</body>
</html>