[Contribution – PoC] Fortinet SSO IdP – Credential Stealer RXSS
Posted by: Yann C. /
Category: Contributions / Vulnerabilities, exploits and PoC / XSS /
No Comments
04
Mar
2016
SSO authentication page of one of Fortigate IdP presents a Cross-Site Scripting vulnerability which can be used to steal user credentials in plaintext.
Companies and current majors turn increasingly to identity federation. A central and single repository containing users credentials (login / password) like LDAP, AD, etc., a single web application centralized authentication (commonly referred to IdP for. Read more