security

Published on November 27th, 2017 📆 | 3773 Views ⚑

0

GOLDEN SAML attack technique forges authentication to cloud apps


iSpeech.org

Golden SAML could be exploited by an attacker to create fake enterprise identities and access to valuable cloud resources.

Security experts at CyberArk Labs have devised a post-intrusion attack technique dubbed Golden SAML that could be exploited by an attacker to create fake enterprise identities and forge authentication to gain access to valuable cloud resources in a federated environment.

The attackers can impersonate any users gaining theĀ highest privileges by forging SAML ā€œauthentication object.ā€

SAML is an open standard for exchanging authentication and authorization data between an identity provider and a service provider.

ā€œThe vector enables an attacker to create a golden SAML, which is basically a forged SAML ā€œauthentication object,ā€ and authenticate across every service that uses SAML 2.0 protocol as an SSO mechanism.ā€ states theĀ analysisĀ published byĀ CyberArk.

ā€œIn a golden SAML attack, attackers can gain access to any application that supports SAML authentication (e.g. Azure, AWS,Ā vSphere, etc.) with any privileges they desire and be any userĀ onĀ the targeted application (even one that is non-existent in the application in some cases).ā€

The Golden SAML name reminds us of another notorious attack known as golden ticket, devised by Benjamin Delpy who developed the popular hacking toolĀ Mimikatz.

ā€œThe name resemblance is intended, since the attack nature is rather similar. Golden SAML introduces to a federation the advantages that golden ticket offers in a Kerberos environment ā€“ from gaining any type of access to stealthily maintaining persistency.ā€ continues the analysis.

The Golden Ticket attack could be launched by attackers to gain full control of an IT infrastructure by manipulating the Windows Server Kerberos authentication framework.

In a similar way, theĀ Golden SAML attack leverages the Security Assertion Markup Language 2.0 (SAML) protocol. Each SAML assertionĀ is trusted and signed via a specific RSA key stored with an identity provider environment.

To carry on the such attack, the attackersĀ will need the private key that signs the SAML objects along withĀ an Active Directory Federation Services user account, token-signing private key, an identity provider (IdP) public certificate and an IdP name.





 

ā€œHereā€™s a list of the requirements for performing a golden SAML attack.Ā The mandatory requirements are highlighted in purple. For the other non-mandatory fields, you can enter whatever you like.ā€

  • Token-signing private key
  • IdP public certificate
  • IdP name
  • Role name (role to assume)
  • Domain\username
  • Role session name in AWS
  • Amazon account ID

[adsense size='1' ]

The prerequisites of such attacks are important and make this technique not easy to beĀ used in a real attackĀ scenario.

The experts explained that mitigate the Golden SAMLattack is not simple.

ā€œThis attack doesnā€™t rely on a vulnerability in SAML 2.0. Itā€™s not a vulnerability in AWS/ADFS, nor in any other service or identity provider.

Golden ticket is not treated as a vulnerability because an attacker has to have domain admin access in order to perform it. Thatā€™s why itā€™s not being addressed by the appropriate vendors. The fact of the matter is, attackers are still able to gain this type of access (domain admin), and they are still using golden tickets to maintain stealthily persistent for even years in their targetā€™s domain.ā€ concluded the researchers.

ā€œAs for the defenders, we know that if this attack is performed correctly, it will be extremely difficult to detect in your network.Ā ā€œ

CyberArk released aĀ new tool dubbedĀ shimitĀ that implements Golden SAML attack.



Comments are closed.