italia / spid-sp-test

SAML2 SPID/CIE Service Provider validation tool
European Union Public License 1.2
38 stars 17 forks source link

Added "X509Certificate" response configuration parameter and XSW/XSLT pentest #99

Closed peppelinux closed 2 years ago

peppelinux commented 3 years ago

feat: added "X509Certificate" configuration parameter to have x509 exposed in the Response feat: added response check #5 to exploit this brand new feature

feat: XSW1 wrapping attack response check feat: XSW2 wrapping attack response check feat: XSW3 wrapping attack response check feat: XSW4 wrapping attack response check feat: XSW5 wrapping attack response check feat: XSW6 wrapping attack response check feat: XSW7 wrapping attack response check feat: XSW8 wrapping attack response check feat: XSLT attack response check