module

VMware vCenter Forge SAML Authentication Credentials

Disclosed
Apr 20, 2022

Description

This module forges valid SAML credentials for vCenter server
using the vCenter SSO IdP certificate, IdP private key, and
VMCA certificates as input objects; you must also provide
the vCenter SSO domain name and vCenter FQDN. The module will
return a session cookie for the /ui path that grants access to
the SSO domain as a vSphere administrator. The IdP trusted
certificate chain can be retrieved using Metasploit post
exploitation modules or extracted manually from
/storage/db/vmware-vmdir/data.mdb using binwalk.
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.