TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

I hacked my company's SSO provider

20 pointsby MattSayar2 months ago

6 comments

EQYV2 months ago
This is a completely unacceptable vulnerability in any software purporting itself to be an identity provider. OP, name and shame this provider. I do not want to find myself using it.
l0b02 months ago
Nice find! As for the provider, since they missed this extremely basic step (don&#x27;t trust the client!!) I would expect they have <i>many</i> more undiscovered vulnerabilities.
globular-toast2 months ago
This is honestly the kind of mistake I&#x27;d expect a child to make. It shows a complete lack of understanding of how the web works. And this was put into production by a so-called security company? I think a name and shame is appropriate here. This isn&#x27;t excusable, it&#x27;s just straight up incompetence.
meitham2 months ago
I wish the article provided the name of the vendor!
pbalau2 months ago
You did not hack anything and that is far from being a security vulnerability, on the side of the SSO.
nubinetwork2 months ago
Never trust the (web) client, sanitize&#x2F;validate the shit out of everything, and stop using JavaScript...