Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
XSW — XML Signature Wrapping Burp Suite 확장 기능 | Kitploit
도구/GitHubGitHub/d0ge/xsw
Vulnerability ScannersExploitationWeb Application ExploitationAPI Security TestingWeb SecurityPenetration TestingIdentity & Access Management (IAM)AuthenticationRed Teaming
GitHubd0ge/xsw

XSW

XML Signature Wrapping Burp Suite 확장 기능

239510개월 전Kitploit 검토 완료
저장소 보기

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

XML 서명 래핑(XSW) Burp Suite 확장

XSW Burp Suite 확장은 SAML 엔드포인트에서 서명 래핑 취약점을 자동으로 탐색하는 프로세스를 자동화합니다.

사용 방법

  1. Burp Suite에서 인증 요청을 마우스 오른쪽 버튼으로 클릭하고 "WRAP Attack"을 선택합니다.
  2. 대화 상자 매개변수를 구성하고 테스트를 시작합니다.
  3. 확장은 자동으로 여러 개의 조작된 XML 페이로드를 생성하여 대상 엔드포인트로 전송합니다.
  4. 결과는 추가 분석을 위해 Burp Suite의 Extensions Organizer 탭에 기록됩니다.

설정

  • Name ID - 가장할 사용자 신원(일반적으로 이메일 주소).
  • Assertion URL (target) - 선택 사항. AuthnRequest에 아직 포함되지 않은 경우 대상으로 지정할 Assertion Consumer Service(ACS) URL.
  • Metadata URL (signed XML source) - 선택 사항. 서명된 메타데이터 문서(일반적으로 IdP의 서명된 메타데이터)의 URL.
  • Timeout - 선택 사항. 요청 간 지연 시간(밀리초).
  • Always Refresh Metadata - 선택 사항. 활성화하면 확장이 모든 테스트 케이스에 대해 새로운 서명된 메타데이터 문서를 가져옵니다.

공격

이 확장은 다음을 포함한 여러 클래스의 서명 래핑 취약점을 탐색합니다:

  • Attribute Pollution - libxml2와 REXML 간의 파서 불일치.
  • Namespace Confusion - 네임스페이스 재정의 및 접두사 모호성을 기반으로 한 우회.
  • Void Canonicalization - libxml2 c14n 제한 악용

샘플

Golden-SAMLResponse.xml

참고

이 확장은 SAMLRaider 확장에서 영감을 받았으며, 다음 연구 논문에서 소개된 기법을 기반으로 합니다: The Fragile Lock: Novel Bypasses for SAML Authentication by Zak Fedotkin

데모

다음 gitlab-ee:17.8.4 docker-compose 프로젝트는 데모 목적으로만 문제를 재현하는 데 사용할 수 있습니다. 다음을 자신의 IdP 값으로 교체하세요:

  • idp_cert_fingerprint: "<idp_cert_fingerprint>"
  • idp_sso_target_url: "<idp_sso_target_url>"
version: '3.6'
services:
  gitlab:
    image: gitlab/gitlab-ee:17.8.4-ee.0
    container_name: gitlab
    restart: always
    hostname: 'gitlab.lab.local'
    environment:
      GITLAB_OMNIBUS_CONFIG: |
        external_url 'https://gitlab.lab.local'
        nginx['listen_port'] = 443
        nginx['redirect_http_to_https'] = true
        nginx['ssl_certificate'] = "/etc/ssl/certs/gitlab/server-cert.pem"
        nginx['ssl_certificate_key'] = "/etc/ssl/certs/gitlab/server-key.pem"
        nginx['ssl_protocols'] = "TLSv1.1 TLSv1.2"
        nginx['logrotate_frequency'] = "weekly"
        nginx['logrotate_rotate'] = 52
        nginx['logrotate_compress'] = "compress"
        nginx['logrotate_method'] = "copytruncate"
        nginx['logrotate_delaycompress'] = "delaycompress"
        gitlab_rails['gitlab_shell_ssh_port'] = 2424
        gitlab_rails['omniauth_allow_single_sign_on'] = ['saml']
        gitlab_rails['omniauth_block_auto_created_users'] = false
        gitlab_rails['omniauth_auto_link_saml_user'] = true
        gitlab_rails['omniauth_providers'] = [
          {
            name: "saml",
            label: "Okta login",
            args: {
              assertion_consumer_service_url: "https://gitlab.lab.local/users/auth/saml/callback",
              idp_cert_fingerprint: "<idp_cert_fingerprint>",
              idp_sso_target_url: "<idp_sso_target_url>",
              issuer: "https://gitlab.lab.local",
              name_identifier_format: "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"
            }
          }
        ]
    ports:
      - '80:80'
      - '443:443'
      - '2424:22'
    volumes:
      - '/srv/gitlab/config:/etc/gitlab'
      - '/srv/gitlab/logs:/var/log/gitlab'
      - '/srv/gitlab/data:/var/opt/gitlab'
      - './volume_data/ssl:/etc/ssl/certs/gitlab'
    shm_size: '256m'
도구 다운로드