[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fzJdwqotZ16qk9IW_9QUPp-PjF8mmxPQ1GVbxVQmR7mU":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":56,"createdAt":56,"_status":55},1263,"What are the main defense recommendations against this SAML certificate attack?","The primary defenses are applying patches to prevent attackers from obtaining vCenter local administrator privileges, and securing vCenter backup files to avoid leakage. By blocking access to the `data.mdb` file or the local admin account, the attack chain is effectively broken.","\u003Cp>The primary defenses are applying patches to prevent attackers from obtaining vCenter local administrator privileges, and securing vCenter backup files to avoid leakage. By blocking access to the `data.mdb` file or the local admin account, the attack chain is effectively broken.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fvsphere-development-guide-6-vcenter-saml-certificates\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-main-defense-recommendations-against-this-saml-certificate-attack-1777479945383","defense recommendations, patching, backup leakage, vCenter security",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":52,"updatedAt":53,"createdAt":54,"_status":55},297,"vSphere Development Guide 6 - vCenter SAML Certificates","vsphere-development-guide-6-vcenter-saml-certificates","Learn how to exploit vCenter SAML certificates for admin access, optimize scripts for vSphere 6, and implement defense strategies to secure your VMware environment.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>A recent exploitation technique I learned: Using administrator privileges on vCenter to extract the IdP certificate from \u002Fstorage\u002Fdb\u002Fvmware-vmdir\u002Fdata.mdb, create a SAML request for an administrator user, and finally authenticate using the vCenter server to obtain a valid administrator cookie.\u003C\u002Fp>\u003Cp>Intuitive understanding: From local administrator privileges on vCenter to administrator access to the VCSA management panel.\u003C\u002Fp>\u003Cp>Learning materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.horizon3.ai\u002Fcompromising-vcenter-via-saml-certificates\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fhorizon3ai\u002Fvcenter_saml_login\u003C\u002Fp>\u003Cp>This article will improve the code based on the learning materials, enhance its versatility, and provide defense recommendations in conjunction with exploitation ideas.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Method reproduction\u003C\u002Fli>\u003Cli>Script optimization\u003C\u002Fli>\u003Cli>Exploitation ideas\u003C\u002Fli>\u003Cli>Defense Recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Method Reproduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Testing on Kali System\u003C\u002Fp>\u003Cp>Install Openssl:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>apt install python3-openssl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>1. Obtain Database File from vCenter\u003C\u002Fh3>\u003Cp>Path: \u002Fstorage\u002Fdb\u002Fvmware-vmdir\u002Fdata.mdb\u003C\u002Fp>\u003Cp>vCenter Administrator Privileges Required\u003C\u002Fp>\u003Ch3>2. Run the Script\u003C\u002Fh3>\u003Cp>Download URL:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fhorizon3ai\u002Fvcenter_saml_login\u002Fblob\u002Fmain\u002Fvcenter_saml_login.py\u003C\u002Fp>\u003Cp>Command Parameter Example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python3 .\u002Fvcenter_saml_login.py -t 192.168.1.1 -p data.mdb\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Command Line Return Result:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>JSESSIONID=XX533CDFA344DE842517C943A1AC7611\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>3. Log in to the VCSA management panel\u003C\u002Fp>\u003Cp>Access https:\u002F\u002F192.168.1.1\u002Fui\u003C\u002Fp>\u003Cp>Set Cookie: JSESSIONID=XX533CDFA344DE842517C943A1AC7611\u003C\u002Fp>\u003Cp>Successfully logged into the management panel as administrator\u003C\u002Fp>\u003Ch2>0x03 Script Optimization\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Typically, the size of data.mdb is at least 20MB\u003C\u002Fp>\u003Cp>To reduce interaction traffic, choose to modify vcenter_saml_login.py to be usable directly under vCenter\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Python is installed by default on vCenter\u003C\u002Fp>\u003Cp>Specifically, the following issues need to be considered when modifying the script:\u003C\u002Fp>\u003Ch3>1. Remove the reference to the third-party package bitstring\u003C\u002Fh3>\u003Cp>The approach I adopted is to streamline the content of the third-party package bitstring and directly insert it into the Python script\u003C\u002Fp>\u003Ch3>2. Avoid using f-string formatting\u003C\u002Fh3>\u003Cp>Python 3.6 introduced a new f-string formatting feature\u003C\u002Fp>\u003Cp>vCenter 6.7 uses Python 3.5.6, which does not support the 'f' prefix for formatted string literals\u003C\u002Fp>\u003Cp>The approach I adopted was to use the format method for string formatting\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cn = stream.read(f'bytes:{cn_len}').decode()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Replaced with:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cn = stream.read('bytes:{}'.format(cn_len)).decode()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The complete code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>vCenter_ExtraCertFromMdb.py can be uploaded to vCenter and executed directly. After execution, the following four important parameters will be obtained:\u003C\u002Fp>\u003Cul>\u003Cli>domain, displayed in the command line\u003C\u002Fli>\u003Cli>idp_cert, saved as idp_cert.txt\u003C\u002Fli>\u003Cli>trusted_cert_1, saved as trusted_cert_1.txt\u003C\u002Fli>\u003Cli>trusted_cert_2, saved as trusted_cert_2.txt\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Next, a SAML request can be created for the administrator user on any host, using the vCenter server for authentication to obtain a valid administrator cookie. The complete code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Parameter description is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>target: URL of the VCSA management panel\u003C\u002Fli>\u003Cli>hostname: Corresponds to the CN in the certificate Subject attribute of the VCSA management panel\u003C\u002Fli>\u003Cli>domain: Can be obtained from data.mdb using vCenter_ExtraCertFromMdb.py\u003C\u002Fli>\u003Cli>idp_cert path: Can be obtained from data.mdb using vCenter_ExtraCertFromMdb.py\u003C\u002Fli>\u003Cli>trusted_cert_1 path: Can be obtained from data.mdb using vCenter_ExtraCertFromMdb.py\u003C\u002Fli>\u003Cli>trusted_cert_2 path: Can be obtained from data.mdb using vCenter_ExtraCertFromMdb.py\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x04 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. From vCenter local administrator privileges to VCSA management panel administrator access\u003C\u002Fh3>\u003Cp>Prerequisite: Gained vCenter local administrator privileges through a vulnerability\u003C\u002Fp>\u003Cp>Exploitation effect:\u003C\u002Fp>\u003Cp>Obtain administrator access to the VCSA management panel, enabling interaction with virtual machines manageable by vCenter\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>At this point, administrator users can also be added via the LDAP database using the method described in 'vSphere Development Guide 5 - LDAP', enabling interaction with virtual machines manageable by vCenter.\u003C\u002Fp>\u003Ch3>2. Obtain data.mdb from vCenter backup files\u003C\u002Fh3>\u003Cp>Prerequisite: Need to obtain the correct data.mdb file\u003C\u002Fp>\u003Cp>Exploitation effect:\u003C\u002Fp>\u003Cp>Gain administrator access to the VCSA management panel, enabling interaction with virtual machines manageable by vCenter\u003C\u002Fp>\u003Ch2>0x05 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Apply patches to prevent attackers from obtaining vCenter local administrator privileges\u003C\u002Fp>\u003Cp>2. Avoid leakage of vCenter backup files in use\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces optimization ideas for vcenter_saml_login, enhances its generality, and provides defense recommendations based on exploitation approaches.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",3,"published","2026-02-02T07:25:19.682Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"vSphere vCenter SAML Certificates Exploit & Defense Guide","vSphere, vCenter, SAML certificates, exploit, VCSA, administrator access, security, defense, VMware, penetration testing",false,[],{"docs":41,"hasNextPage":51},[4,42,43,44,45,46,47,48,49,50],1262,1261,1260,1259,1258,1257,1256,1255,1254,true,{"title":30,"description":30,"image":30},"2026-07-24T02:07:12.323Z","2026-07-23T16:02:42.134Z","draft","2026-07-23T16:17:44.989Z"]