SSO Wars: The Token Menace

Black Hat USA 2019

Presented by: Oleksandr Mirosh, Alvaro Munoz
Date: Wednesday August 07, 2019
Time: 10:30 - 10:55
Location: South Pacific

It is the year 2019. Humanity has almost won its long-standing war against Single-Sign On (SSO) bugs. The last of them were discovered and eradicated some time ago and the world is now living in an era of prosperity while the Auth Federation enjoys peaceful CVE-free times. However, while things seem to be running smoothly, new bugs are brewing at the core of major implementation libraries. This is probably the last chance for the evil empire to launch a world scale attack against the Auth Federation.

In this talk, we will present two new techniques:

Alvaro Munoz

Alvaro Muñoz (@pwntester) works as Principal Software Security Researcher with Micro Focus Fortify, Software Security Research (SSR) team. Before joining the research organization, he worked as an Application Security Consultant helping top enterprises to deploy their application security programs. He is passionate about Web Application security where he has focused most of his research. Muñoz has presented at many Security conferences including BlackHat, Defcon, RSA, AppSec EU & US, JavaOne, etc and holds several infosec certifications, including OSCP, GWAPT and CISSP and he is a proud member of int3pids CTF team. He blogs at

Oleksandr Mirosh

Oleksandr Mirosh has over 11 years of computer security experience, including vulnerability research, penetration testing, reverse engineering, fuzzing, developing exploits and consulting. He is working for Fortify Software Security Research team in MicroFocus investigating and analyzing new threats, vulnerabilities, security weaknesses, new techniques of exploiting security issues and development vulnerability detection, protection and remediation rules. In the past, he has performed a wide variety of security assessments, including design and code reviews, threat modelling, testing and fuzzing in order to identify and remove any existing or potentially emerging security defects in the software of various customers.

KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats