maSSO: A Weaponized Identity Provider for SSO Security Testing
maSSO is an open-source security testing tool from Doyensec that acts as a malicious but standards-compliant OIDC and SAML 2.0 Identity Provider. It enables security testers to intercept, modify, and re-sign authentication messages, claims, and tokens, making it easier to assess trust boundaries, validate authentication logic, and identify vulnerabilities in Single Sign-On implementations that are difficult to test with conventional IdPs.
Comments
Post a Comment