refined-iron-20465
02/05/2024, 1:00 PMrefined-kangaroo-48640
02/06/2024, 3:42 PMrefined-kangaroo-48640
02/06/2024, 3:42 PMrefined-iron-20465
02/21/2024, 11:05 PMrefined-iron-20465
02/21/2024, 11:16 PMrefined-iron-20465
02/27/2024, 1:09 AMrefined-kangaroo-48640
02/27/2024, 9:12 AMrefined-iron-20465
02/27/2024, 3:10 PM?login_challenge=...
• Perform step 5 in browser session B (attacker) and enter the credentials of the attacker's account. This makes a POST request to the IdP, obtaining a 302 response. Copy the Location from the response header.
• Perform step 7 in browser session A and you're logged into the attacker's account.refined-kangaroo-48640
02/27/2024, 3:38 PMrefined-iron-20465
02/27/2024, 3:59 PM