How does the attacker use the extracted SAML certificates to gain administrator access?
After extracting the IdP certificate and trusted certificates from data.mdb, the attacker creates a SAML authentication request for an administrator user on any host, then authenticates against the vCenter server. The server returns a valid JSESSIONID cookie that, when set in the browser, provides full administrator access to the VCSA management panel. --- **Related reading:** - [vSphere Development Guide 6 - vCenter SAML Certificates](/news/vsphere-development-guide-6-vcenter-saml-certificates) — original article - [Penetration Techniques - Deleting Single Windows Log Entries](/news/penetration-techniques-deleting-single-windows-log-entries) - [Penetration Technique: Remote Access to Exchange PowerShell](/news/penetration-technique-remote-access-to-exchange-powershell) - [Zimbra SOAP API Development Guide 2](/news/zimbra-soap-api-development-guide-2)
Related article:
vSphere Development Guide 6 - vCenter SAML Certificates