TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

I hacked my company's SSO provider

20 点作者 MattSayar2 个月前

6 条评论

EQYV2 个月前
This is a completely unacceptable vulnerability in any software purporting itself to be an identity provider. OP, name and shame this provider. I do not want to find myself using it.
l0b02 个月前
Nice find! As for the provider, since they missed this extremely basic step (don&#x27;t trust the client!!) I would expect they have <i>many</i> more undiscovered vulnerabilities.
globular-toast2 个月前
This is honestly the kind of mistake I&#x27;d expect a child to make. It shows a complete lack of understanding of how the web works. And this was put into production by a so-called security company? I think a name and shame is appropriate here. This isn&#x27;t excusable, it&#x27;s just straight up incompetence.
meitham2 个月前
I wish the article provided the name of the vendor!
pbalau2 个月前
You did not hack anything and that is far from being a security vulnerability, on the side of the SSO.
nubinetwork2 个月前
Never trust the (web) client, sanitize&#x2F;validate the shit out of everything, and stop using JavaScript...