SAML attacks TL;DR: XML signature wrapping, comment injection, IdP confusion, replay across SPs. Stub — to be filled in. What it is TODO Preconditions / where it applies TODO Technique TODO Detection and defence TODO References https://book.hacktricks.wiki/en/pentesting-web/saml-attacks/index.html