Authentication / Authorization Badge

The Authentication/Authorization Badge covers vulnerabilities in authentication and authorisation. If focuses on SAML and Oauth.

7

Exercises

0

Completed this badge

7

CPEs

OAuth2: Authorization Server CSRF

This exercise covers the exploitation of a CSRF in the Authorization server

Difficulty: EASY
  • Ruby-On-Rails
  • Completed by 12 students
  • Takes Less than an hour on average

SAML: Introduction

This exercise covers the exploitation of a signature stripping vulnerability in SAML

Difficulty: EASY
  • 1 video
  • RoR
  • Completed by 542 students
  • Takes Less than an hour on average

SAML: Signature Stripping

This exercise covers the exploitation of a signature stripping vulnerability in SAML

Difficulty: EASY
  • 1 video
  • RoR
  • Completed by 357 students
  • Takes Less than an hour on average

CVE-2016-4977 Coming soon

This exercise explains how you can gain code execution on a system that relies on a vulnerable version of Spring's Oauth

Difficulty: MEDIUM
  • Java/Spring
  • Completed by 0 student
  • Takes -- on average

OAuth2: Authorization Server OpenRedirect

This exercise covers the exploitation of an OpenRedirect in the Authorization Server

Difficulty: MEDIUM
  • 3 videos
  • Ruby-On-Rails
  • Completed by 114 students
  • Takes Between 1 and 2 hours on average

OAuth2: Client OpenRedirect

This exercise covers the exploitation of an OpenRedirect in the OAuth2 Client

Difficulty: MEDIUM
  • 1 video
  • Ruby-On-Rails
  • Completed by 69 students
  • Takes Between 1 and 2 hours on average

OAuth2: Github HTTP HEAD

This exercise covers the exploitation of the HTTP HEAD issue impacting Github in 2019

Difficulty: HARD
  • 1 video
  • Ruby-On-Rails
  • Completed by 16 students
  • Takes Between 2 and 4 hours on average