IdP in the middle attack
Nobody has claimed this yet.
- Dominant language
- No language data
- Stars
- 9
- Forks
- 4
- PR merge metrics
- No merged PRs in 30d
Description
Here's a successful attack that appears (to me) to be an identify provider spoofing attack.
I think that we might need to add this to things like DC API and FedCM.
The quoted success rate is 50%
https://cybersecuritynews.com/threat-actors-impersonating-microsoft-oauth
"The researchers observed that while most campaigns impersonate generic enterprise applications, some attackers customize their lures based on specific software used in targeted industries, demonstrating a sophisticated understanding of their victims’ operational environments. The financial and operational impact has been substantial, with researchers documenting attempted account compromises affecting nearly 3,000 user accounts across more than 900 Microsoft 365 environments. Perhaps most concerning is the campaign’s confirmed success rate exceeding 50%, highlighting the effectiveness of this hybrid attack methodology that combines email-based social engineering with cloud application abuse."
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reading the linked Microsoft OAuth attack report and the DC API and FedCM materials named in the issue. Determine whether the IdP spoofing scenario is addressed and what concrete security or specification change would be needed; done means a scoped proposal with an agreed target and acceptance criteria.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100