[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2FEUEhlAiuIv1K33R7xYHSPJev_7j_LovhpCi04oTT4":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":57,"createdAt":57,"_status":56},1253,"What defense recommendations does the article provide to prevent SAML certificate exploitation?","The article recommends applying security patches promptly to prevent attackers from gaining vCenter local administrator privileges in the first place, and avoiding leakage of vCenter backup files that might contain the data.mdb database with the IdP certificate.\n\n---\n**Related reading:**\n- [vSphere Development Guide 6 - vCenter SAML Certificates](\u002Fnews\u002Fvsphere-development-guide-6-vcenter-saml-certificates) — original article\n- [Penetration Techniques - Deleting Single Windows Log Entries](\u002Fnews\u002Fpenetration-techniques-deleting-single-windows-log-entries)\n- [Penetration Technique: Remote Access to Exchange PowerShell](\u002Fnews\u002Fpenetration-technique-remote-access-to-exchange-powershell)\n- [Zimbra SOAP API Development Guide 2](\u002Fnews\u002Fzimbra-soap-api-development-guide-2)","\u003Cp>The article recommends applying security patches promptly to prevent attackers from gaining vCenter local administrator privileges in the first place, and avoiding leakage of vCenter backup files that might contain the data.mdb database with the IdP certificate.\u003Cbr>\u003Cbr>---\u003Cbr>**Related reading:**\u003Cbr>- [vSphere Development Guide 6 - vCenter SAML Certificates](\u002Fnews\u002Fvsphere-development-guide-6-vcenter-saml-certificates) — original article\u003Cbr>- [Penetration Techniques - Deleting Single Windows Log Entries](\u002Fnews\u002Fpenetration-techniques-deleting-single-windows-log-entries)\u003Cbr>- [Penetration Technique: Remote Access to Exchange PowerShell](\u002Fnews\u002Fpenetration-technique-remote-access-to-exchange-powershell)\u003Cbr>- [Zimbra SOAP API Development Guide 2](\u002Fnews\u002Fzimbra-soap-api-development-guide-2)\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fvsphere-development-guide-6-vcenter-saml-certificates\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-defense-recommendations-does-the-article-provide-to-prevent-saml-certificat-1777477528154","defense, patching, backup leakage, vCenter security, SAML certificate",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":53,"updatedAt":54,"createdAt":55,"_status":56},297,"vSphere Development Guide 6 - vCenter SAML Certificates","vsphere-development-guide-6-vcenter-saml-certificates","Learn how to exploit vCenter SAML certificates for admin access, optimize scripts for vSphere 6, and implement defense strategies to secure your VMware environment.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>A recent exploitation technique I learned: Using administrator privileges on vCenter to extract the IdP certificate from \u002Fstorage\u002Fdb\u002Fvmware-vmdir\u002Fdata.mdb, create a SAML request for an administrator user, and finally authenticate using the vCenter server to obtain a valid administrator cookie.\u003C\u002Fp>\u003Cp>Intuitive understanding: From local administrator privileges on vCenter to administrator access to the VCSA management panel.\u003C\u002Fp>\u003Cp>Learning materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.horizon3.ai\u002Fcompromising-vcenter-via-saml-certificates\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fhorizon3ai\u002Fvcenter_saml_login\u003C\u002Fp>\u003Cp>This article will improve the code based on the learning materials, enhance its versatility, and provide defense recommendations in conjunction with exploitation ideas.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Method reproduction\u003C\u002Fli>\u003Cli>Script optimization\u003C\u002Fli>\u003Cli>Exploitation ideas\u003C\u002Fli>\u003Cli>Defense Recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Method Reproduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Testing on Kali System\u003C\u002Fp>\u003Cp>Install Openssl:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>apt install python3-openssl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>1. Obtain Database File from vCenter\u003C\u002Fh3>\u003Cp>Path: \u002Fstorage\u002Fdb\u002Fvmware-vmdir\u002Fdata.mdb\u003C\u002Fp>\u003Cp>vCenter Administrator Privileges Required\u003C\u002Fp>\u003Ch3>2. Run the Script\u003C\u002Fh3>\u003Cp>Download URL:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fhorizon3ai\u002Fvcenter_saml_login\u002Fblob\u002Fmain\u002Fvcenter_saml_login.py\u003C\u002Fp>\u003Cp>Command Parameter Example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python3 .\u002Fvcenter_saml_login.py -t 192.168.1.1 -p data.mdb\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Command Line Return Result:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>JSESSIONID=XX533CDFA344DE842517C943A1AC7611\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>3. Log in to the VCSA management panel\u003C\u002Fp>\u003Cp>Access https:\u002F\u002F192.168.1.1\u002Fui\u003C\u002Fp>\u003Cp>Set Cookie: JSESSIONID=XX533CDFA344DE842517C943A1AC7611\u003C\u002Fp>\u003Cp>Successfully logged into the management panel as administrator\u003C\u002Fp>\u003Ch2>0x03 Script Optimization\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Typically, the size of data.mdb is at least 20MB\u003C\u002Fp>\u003Cp>To reduce interaction traffic, choose to modify vcenter_saml_login.py to be usable directly under vCenter\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Python is installed by default on vCenter\u003C\u002Fp>\u003Cp>Specifically, the following issues need to be considered when modifying the script:\u003C\u002Fp>\u003Ch3>1. Remove the reference to the third-party package bitstring\u003C\u002Fh3>\u003Cp>The approach I adopted is to streamline the content of the third-party package bitstring and directly insert it into the Python script\u003C\u002Fp>\u003Ch3>2. Avoid using f-string formatting\u003C\u002Fh3>\u003Cp>Python 3.6 introduced a new f-string formatting feature\u003C\u002Fp>\u003Cp>vCenter 6.7 uses Python 3.5.6, which does not support the 'f' prefix for formatted string literals\u003C\u002Fp>\u003Cp>The approach I adopted was to use the format method for string formatting\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cn = stream.read(f'bytes:{cn_len}').decode()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Replaced with:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cn = stream.read('bytes:{}'.format(cn_len)).decode()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The complete code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>vCenter_ExtraCertFromMdb.py can be uploaded to vCenter and executed directly. After execution, the following four important parameters will be obtained:\u003C\u002Fp>\u003Cul>\u003Cli>domain, displayed in the command line\u003C\u002Fli>\u003Cli>idp_cert, saved as idp_cert.txt\u003C\u002Fli>\u003Cli>trusted_cert_1, saved as trusted_cert_1.txt\u003C\u002Fli>\u003Cli>trusted_cert_2, saved as trusted_cert_2.txt\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Next, a SAML request can be created for the administrator user on any host, using the vCenter server for authentication to obtain a valid administrator cookie. The complete code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Parameter description is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>target: URL of the VCSA management panel\u003C\u002Fli>\u003Cli>hostname: Corresponds to the CN in the certificate Subject attribute of the VCSA management panel\u003C\u002Fli>\u003Cli>domain: Can be obtained from data.mdb using vCenter_ExtraCertFromMdb.py\u003C\u002Fli>\u003Cli>idp_cert path: Can be obtained from data.mdb using vCenter_ExtraCertFromMdb.py\u003C\u002Fli>\u003Cli>trusted_cert_1 path: Can be obtained from data.mdb using vCenter_ExtraCertFromMdb.py\u003C\u002Fli>\u003Cli>trusted_cert_2 path: Can be obtained from data.mdb using vCenter_ExtraCertFromMdb.py\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x04 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. From vCenter local administrator privileges to VCSA management panel administrator access\u003C\u002Fh3>\u003Cp>Prerequisite: Gained vCenter local administrator privileges through a vulnerability\u003C\u002Fp>\u003Cp>Exploitation effect:\u003C\u002Fp>\u003Cp>Obtain administrator access to the VCSA management panel, enabling interaction with virtual machines manageable by vCenter\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>At this point, administrator users can also be added via the LDAP database using the method described in 'vSphere Development Guide 5 - LDAP', enabling interaction with virtual machines manageable by vCenter.\u003C\u002Fp>\u003Ch3>2. Obtain data.mdb from vCenter backup files\u003C\u002Fh3>\u003Cp>Prerequisite: Need to obtain the correct data.mdb file\u003C\u002Fp>\u003Cp>Exploitation effect:\u003C\u002Fp>\u003Cp>Gain administrator access to the VCSA management panel, enabling interaction with virtual machines manageable by vCenter\u003C\u002Fp>\u003Ch2>0x05 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Apply patches to prevent attackers from obtaining vCenter local administrator privileges\u003C\u002Fp>\u003Cp>2. Avoid leakage of vCenter backup files in use\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces optimization ideas for vcenter_saml_login, enhances its generality, and provides defense recommendations based on exploitation approaches.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",3,"published","2026-02-02T07:25:19.682Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"vSphere vCenter SAML Certificates Exploit & Defense Guide","vSphere, vCenter, SAML certificates, exploit, VCSA, administrator access, security, defense, VMware, penetration testing",false,[],{"docs":41,"hasNextPage":52},[42,43,44,45,46,47,48,49,50,51],1263,1262,1261,1260,1259,1258,1257,1256,1255,1254,true,{"title":30,"description":30,"image":30},"2026-07-24T02:07:12.323Z","2026-07-23T16:02:42.134Z","draft","2026-07-23T16:17:41.492Z"]