---
title: "Pentesting Keycloak – Part 2: Identifying Misconfiguration Using Risk Management Tools"
description: This is part 2/2 of “Pentesting Keycloak”, this section will cover:
image: https://csacyber.com/hubfs/keyboard-pentest-1-800x500-1.jpg
---

[Skip to content](https://csacyber.com/blog/pentesting-keycloak-part-2#main-content)

[![CSA Cyber - Cyber Security Solutions to Protect your People](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Full%20Logo.png?width=300&height=108&name=CSA%20Cyber%20Logo%20FNL_Full%20Logo.png "CSA Cyber - Cyber Security Solutions to Protect your People")](https://csacyber.com/)

- Services 
    - [Offensive Security Services](https://csacyber.com/offensive-security-services) 
          - [Penetration Testing](https://csacyber.com/penetration-testing)
          - [Red Teaming and attack simulations](https://csacyber.com/offensive-security-services#red-teaming)
          - [Continuous testing](https://csacyber.com/offensive-security-services#continuous-assurance)
          - [Managed offensive security](https://csacyber.com/offensive-security-services#managed-offensive)
    - [Consultancy Services](https://csacyber.com/cyber-consultancy-services) 
          - [Frameworks & assessments](https://csacyber.com/cyber-consultancy-services/frameworks-and-assessments)
          - [Data protection](https://csacyber.com/cyber-consultancy-services#data-protection)
          - [Virtual leadership](https://csacyber.com/cyber-consultancy-services#virtual-leadership)
          - [Technical security consulting](https://csacyber.com/cyber-consultancy-services#technical-consultancy)
          - [Governance, Risk & Compliance (GRC)](https://csacyber.com/cyber-consultancy-services/governance-risk-and-compliance-services)
    - [Extended Managed Security Services](https://csacyber.com/extended-managed-security-services) 
          - [Microsoft Sentinel SIEM](https://csacyber.com/extended-managed-security-services#microsoft-sentinel)
          - [SOC services](https://csacyber.com/extended-managed-security-services#soc-services)
          - [SentinelOne Endpoint Detection & Response (EDR)](https://csacyber.com/extended-managed-security-services#cyber-helpdesk)
    - [Incident Response Services](https://csacyber.com/incident-response-services) 
          - [Emergency Incident Response](https://csacyber.com/urgent/emergency-incident-response)
          - [Incident Response Retainer](https://csacyber.com/incident-response-services)
          - [Cyber Incident Readiness & Response Planning](https://csacyber.com/incident-response-services)
          - [Tabletop Exercises & Live-Range Engagements](https://csacyber.com/incident-response-services)
    - [Specialist Security Services](https://csacyber.com/specialist-services) 
          - [AI Security](https://csacyber.com/cyber-services-for-ai)
          - [Operational Technology (OT)](https://csacyber.com/specialist-services#operational-technology)
          - [Cyber security for Private Equity](https://csacyber.com/specialist-services#mergers-and-acquisitions)
          - [Cyber training and education](https://csacyber.com/specialist-services#training-and-education)
          - [Virtual leadership](https://csacyber.com/specialist-services#leadership)
    - [Cyber Technologies](https://csacyber.com/cyber-technologies) 
          - [SentinelOne Endpoint Detection & Response (EDR)](https://csacyber.com/cyber-technologies#sentinelone)
          - [AppGuard Endpoint & Server Zero Trust Protection](https://csacyber.com/cyber-technologies#appguard)
          - [Qualys Vulnerability Management as a Service (VMaaS)](https://csacyber.com/cyber-technologies#qualys-vmaas)
          - [Lookout Mobile Device Protection](https://csacyber.com/cyber-technologies#lookout)
          - [ThreatER DNS Protection](https://csacyber.com/cyber-technologies#threater-dns)
          - [Cyber Security Awareness & Training platform](https://csacyber.com/cyber-technologies#boxphish)
- [About](https://csacyber.com/about-us) 
    - [Careers](https://csacyber.com/careers)
    - [Certifications](https://csacyber.com/certifications-and-awards)
- [Blog](https://csacyber.com/blog)
- [Support Centre](https://csacyber.com/support)
- Resources 
    - [Case Studies](https://csacyber.com/case-studies)
    - [Downloads & Reports](https://csacyber.com/downloads-and-reports)
    - [Webinars](https://csacyber.com/webinars)
    - [Partners](https://csacyber.com/partners)
    - [Cyber Bundles (IT MSPs)](https://csacyber.com/cyber-bundles)
- [Contact](https://csacyber.com/contact-us)

- Search Search
  
  Search

 July 20, 2023

 8 min read time

# Pentesting Keycloak – Part 2: Identifying Misconfiguration Using Risk Management Tools

![Cyber Security Associates](https://app.hubspot.com/settings/avatar/d41d8cd98f00b204e9800998ecf8427e) [Written by: Cyber Security Associates -](https://csacyber.com/blog/author/cyber-security-associates)

[Penetration Testing](https://csacyber.com/blog/tag/penetration-testing)

![](https://csacyber.com/hubfs/keyboard-pentest-1-800x500-1.jpg)

### Pentesting Keycloak – Part 2 

This is part 2/2 of “Pentesting Keycloak”, this section will cover:

**Reconnaissance**

- Additional Services and Ports
- Interesting Local Files
- Reconnaissance Conclusion

**Exploitation**

- Brute Force Login
- Bypassing/Automating CSRF
- JWT Signing Algorithms
- Make the most out of your scopes/roles
- offline\_access
- uma\_authorization
- profile
- email
- address
- phone

**References**

If you missed the first part, you can use this direct link: [Part One](https://csacyber.com/blog/pentesting-keycloak-part-1-identifying-misconfiguration-using-risk-management-tools)

### Reconnaissance

##### Additional Services and Ports

By default Keycloak starts the following services:

![](https://surecloudcyber.com/assets/img/blog/PenTesting-Keycloak-p2-fig1.png)

The http(s) defines what port Keycloak is listening to. On a production environment this is often set to be 443 on 0.0.0.0

The management-http(s) interface defines the HTTP connection used by Wildfly CLI and web console. This is known as the 'ManagementRealm' and it's protected via a Digest Authorization header. Password complexity is enforced on user creation (8 digits, alpha, numeric and special).

The ajp socket defines the port used for the AJP protocol. This protocol is used by Apache HTTPD server in conjunction mod-cluster when you are using Apache HTTPD as a load balancer.

The txn-\* refers to the recovery environment.

The above ports are all bound to 127.0.0.1 by default, but this can be changed via "-b" parameter at start-up.

## Interesting Local Files

If you had a chance to get a local shell on a machine running Keycloak, the following files might be of interest:

![](https://surecloudcyber.com/assets/img/blog/PenTesting-Keycloak-p2-fig2.png)

Properties declaration of users and groups for the realm 'ManagementRealm' (port 9990/9993). Further authentication mechanism can be configured as part of the in standalone.xml.

Contains username and password (hashed) to access it. Format is:

username=HEX( MD5( username ':' realm ':' password))

Permissions were correctly set to allow only the local user to write on the file:

-rw- --- ---

![](https://surecloudcyber.com/assets/img/blog/PenTesting-Keycloak-p2-fig3.png)

Properties declaration of users for the realm 'ApplicationRealm' (port 8080/8443). This includes the following protocols: remote ejb, remote jndi, web, remote jms. Contains username and password (hashed) to access it. Format is:

username=HEX( MD5( username ':' realm ':' password))

Permissions were correctly set to allow only the local user to write on the file:

-rw- --- ---

![](https://surecloudcyber.com/assets/img/blog/PenTesting-Keycloak-p2-fig4.png)

The above contain definitions to the data source (database username and password).

Keycloak comes with its own embedded Java-based relational database called H2. This is the default database that Keycloak will use to persist data and really only exists so that you can run the authentication server out of the box. A client might have changed it to other DBMS.

The physical position of the H2 database (also containing the user's password) is:

$Keycloak\_install\_dir/standalone/data/keycloak\*

And can be accessed locally (when Keycloak is not locking it), via the command:

java -jar $Keycloak\_install\_dir/modules/system/layers/base/com/h2database/h2/main/h2-\*.jar

This will open the H2 database console on http://127.0.1.1:8082 - Use the following configuration to access it (default password is sa:sa)

![](https://surecloudcyber.com/assets/img/blog/h2_db_login.png)

User's hashes can be extracted via query: 'SELECT \* FROM CREDENTIAL'

![](https://surecloudcyber.com/assets/img/blog/H2_db_content.png)

Hash format is pbkdf2-sha256 with 27500 iterations.

Finally, log files are available in:

$Keycloak\_install\_dir/standalone/log/

$ ls -lha standalone/log/  
totale 644K  
drwxrwxr-x 2 user user 4.0K Sep 9 08:45 .  
drwxr-xr-x 8 user user 4.0K Aug 23 09:38 ..  
-rw-rw-r-- 1 user user 0 Aug 23 09:38 audit.log  
-rw-rw-r-- 1 user user 103K Sep 9 10:42 server.log

## Reconnaissance Conclusion

At the end of this reconnaissance stage you should have obtained:

- A list of valid realms
- A list of realms that allow self-registration (if any)
- A list of valid client ids for each realm
- A list of valid scopes for each realm
- A list of valid email addresses for the realm(s) we have access to
- A list of enabled identity providers for each realm
- A list of additional service reachable from your perspective (local, adjacent or remote)
- Basic knowledge of Keycloak's file structure

## Exploitation

##### Brute Force Login

Keep in mind that Keycloak has a brute force protection, which is not enabled by default.

In case user enabled it, you'll have 30 invalid attempt before being locked out (in a default configuration). Perform this attack at the end of your test, to avoid asking the client to manually re-enable your account.

![](https://surecloudcyber.com/assets/img/blog/bruteforcelogin.png)

##### Bypassing/Automating CSRF

The login page uses a Cross-Site Request Forgery (CSRF) token that needs to be extracted and used in the automated attack. For this task, we will use the Burp Intruder Recursive Grep.

 1\. Submit a login request in the page and send it to Burp Intruder  
2\. Add the payload positions in the value of 'session\_code' and 'password' parameters. Select the Pitchfork Attack Type.

![](https://surecloudcyber.com/assets/img/blog/csrf_bypass1.png)

![](https://surecloudcyber.com/assets/img/blog/csrf_bypass2.png)

 3\. In the Payload Tab, the first Payload Type should be Recursive Grep. The second Payload Type should be Simple List (with your passwords to try for a specific user).  
4\. Move to the "Options" tab and add a new element to "Grep - Extract" menu. We will need to extract the "session\_code" from the response:

![](https://surecloudcyber.com/assets/img/blog/csrf_bypass3.png)

 5\. Check "Extract the following items from responses" and also uncheck "Make unmodified baseline request" in the "Attack Results" section

![](https://surecloudcyber.com/assets/img/blog/csrf_bypass4.png)

 6\. In the "Resource Pool" tab, create one new pool with 1 maximum concurrent request

![](https://surecloudcyber.com/assets/img/blog/csrf_bypass5.png)

 7\. Go back to the "Payloads" tab and add the "initial payload for first request", which should be a clean, unused, session\_code - You can grab one just by refreshing the login page.

![](https://surecloudcyber.com/assets/img/blog/csrf_bypass6.png)

Start the attack and you'll see a 302 Status code if you've found the correct password for the user.

![](https://surecloudcyber.com/assets/img/blog/csrf_bypass7.png)

## JWT Signing Algorithms

By default, Keycloak sets RS256 as a signing algorithm for JWT, which is already a great standard. However, it also offers additional, stronger, options:

![](https://surecloudcyber.com/assets/img/blog/jwt_algo.png)

It might be worth to raise an information risk issue to make the client aware of this possibility. Please note: EdDSA is not yet implemented in Keycloak, and that's the strongest algorithm to use (as today). Alternatively, RS512 or ES512 are the next best choices.

If HS\* is in use, it should be noted that the secret is randomly generated by the system and it could be between 16 and 512 bytes (it cannot be easily cracked).

## Make The Most Out of Your Scopes/Roles

In the reconnaissance part, we were able to identify roles and scopes available for our testing account. In this section, we're going to make advantage of them with practical examples

##### offline\_access

Offline access is a feature described in OpenID Connect specification . The idea is that during login, your client application will request an Offline token instead of a classic Refresh token. The application can save this offline token in a database or on disk and can use it later even if user is logged out. This is useful if your application needs to do some "offline" actions on behalf of user even when the user is not online. An example is a periodic backup of some data every night.

Therefore, having an offline\_access scope on your user account is never a good idea, since it generates a long living refresh token that should only be used for server-to-server applications.

##### Request an offline token (method 1)

This first method requires you to add the additional 'offline\_access' scope in the URL of the login page.

![](https://surecloudcyber.com/assets/img/blog/offline_access1.png)

Perform the login and the /token endpoint will generate a refresh\_token that does not expire:

![](https://surecloudcyber.com/assets/img/blog/offline_access2.png)

We can generate a valid session token from the offline refresh\_token via the following request:

![](https://surecloudcyber.com/assets/img/blog/keycloak-p2-img1.png)

##### Request an offline token (method 2)

If you instead have client\_id and client\_secret of a client using 'confidential' access type, you can request an offline token via:

![](https://surecloudcyber.com/assets/img/blog/keycloak-p2-img2.png)

##### uma\_authorization

Keycloak Authorization Services is based on User-Managed Access or UMA for short. UMA is a specification that enhances OAuth2 capabilities in the following ways:

##### Privacy

Nowadays, user privacy is becoming a huge concern, as more and more data and devices are available and connected to the cloud. With UMA and Keycloak, resource servers can enhance their capabilities in order to improve how their resources are protected in respect to user privacy where permissions are granted based on policies defined by the user.

##### Party-to-Party Authorization

Resource owners (e.g.: regular end-users) can manage access to their resources and authorize other parties (e.g: regular end-users) to access these resources. This is different than OAuth2 where consent is given to a client application acting on behalf of a user, with UMA resource owners are allowed to consent access to other users, in a completely asynchronous manner.

##### Resource Sharing

Resource owners are allowed to manage permissions to their resources and decide who can access a particular resource and how. Keycloak can then act as a sharing management service from which resource owners can manage their resources.

Keycloak is a UMA 2.0 compliant authorization server that provides most UMA capabilities.

To add a specific resource type, we can use the following request:

![](https://surecloudcyber.com/assets/img/blog/keycloak-p2-img3.png)

By default, the owner of a resource is the resource server. If you want to define a different owner, such as an specific user, you can send a request as follows:

![](https://surecloudcyber.com/assets/img/blog/keycloak-p2-img4.png)

To list the security permissions we can visit (with a valid token):

![](https://surecloudcyber.com/assets/img/blog/keycloak-p2-img5.png)

##### Profile

OPTIONAL. This scope value requests access to the End-User’s default profile Claims, which are: name, family\_name, given\_name, middle\_name, nickname, preferred\_username, profile, picture, website, gender, birthdate, zoneinfo, locale, and updated\_at.

![](https://surecloudcyber.com/assets/img/blog/profile.png)

##### Email

![](https://surecloudcyber.com/assets/img/blog/email.png)

##### Address

OPTIONAL. This scope value requests access to the address Claim.

![](https://surecloudcyber.com/assets/img/blog/address.png)

##### Phone

OPTIONAL. This scope value requests access to the phone\_number and phone\_number\_verified Claims.

![](https://surecloudcyber.com/assets/img/blog/phone.png)

All of the above can be updated by the API endpoint available at

![](https://surecloudcyber.com/assets/img/blog/keycloak-p2-img6.png)

## References

[\[1\] Using Client Scope with RedHat SSO Keycloak](https://www.janua.fr/using-client-scope-with-redhat-sso-keycloak/)

[\[2\] Server Administration Guide - Keycloak features and concepts](https://www.keycloak.org/docs/latest/server_admin/index.html#threat-model-mitigation)

[\[3\] Authorization Services Guide - Authorization services overview](https://www.keycloak.org/docs/latest/authorization_services/)

Related Posts

## You may also like this

[Similar Articles](https://csacyber.com/blog)

[![](https://csacyber.com/hs-fs/hubfs/20230510-N1005919-Edit1.jpg?width=624&height=427&name=20230510-N1005919-Edit1.jpg)](https://csacyber.com/blog/fluidone-group-appoints-charly-davis-as-managing-director-of-csa-cyber-to-advance-its-security-first-strategy)

 August 24, 2026

 2 min read

### [FluidOne Group appoints Charly Davis as Managing Director of CSA Cyber to advance its security-first strategy](https://csacyber.com/blog/fluidone-group-appoints-charly-davis-as-managing-director-of-csa-cyber-to-advance-its-security-first-strategy)

 Experienced industry leader joins FluidOne to strengthen integrated cyber, IT and secure networking...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![](https://csacyber.com/hs-fs/hubfs/Untitled%20design.jpg?width=624&height=427&name=Untitled%20design.jpg)](https://csacyber.com/blog/csa-cyber-and-fluidone-named-as-suppliers-on-g-cloud-15)

 August 20, 2026

 9 min read

### [CSA Cyber and FluidOne named as suppliers on G-Cloud 15](https://csacyber.com/blog/csa-cyber-and-fluidone-named-as-suppliers-on-g-cloud-15)

 CSA Cyber (CSA), part of the FluidOne Group, has been named as a supplier on Government Commercial...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![](https://csacyber.com/hs-fs/hubfs/Engineered%20to%20Endure%20Campaign%20Assets%20(2).png?width=624&height=427&name=Engineered%20to%20Endure%20Campaign%20Assets%20(2).png)](https://csacyber.com/blog/why-organisations-lose-security-visibility-without-realising-it)

 August 20, 2026

 6 min read

### [Why organisations lose security visibility without realising it](https://csacyber.com/blog/why-organisations-lose-security-visibility-without-realising-it)

 Before an organisation can understand risk, maintain control or respond effectively to emerging...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![CSA Cyber Logo FNL\_Full Logo](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Full%20Logo.png?width=3463&height=1248&name=CSA%20Cyber%20Logo%20FNL_Full%20Logo.png "CSA Cyber Logo FNL_Full Logo")](https://csacyber.com/)

Established in 2013, Cyber Security Associates Limited trading as CSA Cyber provides cyber consultancy and cyber managed services which help to detect, protect and educate against the ever-changing cyber threat. We have built our team from a foundation of Government (ex-Military) and Commercially experienced specialists all holding current and relevant cyber certifications. Today our core services are based around a 24/7 Security Operations Centre (SOC) based in Gloucester.

#### News & Resources

- [Blog](https://csacyber.com/blog)
- [Case Studies](https://csacyber.com/case-studies)
- [Downloads & Reports](https://csacyber.com/downloads-and-reports)
- [Webinars](https://csacyber.com/webinars)
- [Careers](https://csacyber.com/careers)
- [Cyber Bundles (IT MSPs)](https://csacyber.com/cyber-bundles)

#### Quick Links

- [About Us](https://csacyber.com/about-us)
- [Certifications](https://csacyber.com/certifications-and-awards)
- [Our Parent Company](https://www.fluidone.com)
- [Partners](https://csacyber.com/partners)
- [Contact Us](https://csacyber.com/contact-us)
- [Anti Bribery Policy](https://csacyber.com/hubfs/CSAAnti-BriberyPolicy.pdf)
- [Complaints Policy](https://csacyber.com/hubfs/CSAComplaintsPolicy.pdf)
- [Corporate Social Responsibility Policy](https://csacyber.com/hubfs/CSACorporateSocialResponsibilityPolicy.pdf)
- [Slavery and Human Trafficking Statement](https://csacyber.com/hubfs/CSASlaveryandHumanTraffickingStatement.pdf)
- [NCSC CHECK Status Verification](https://www.ncsc.gov.uk/organisation/csa-cyber/check-penetration-testing)
- [CREST Approved Certification Verification](https://www.crest-approved.org/member_companies/csa-cyber/)

#### Contact Information

**United Kingdom - London**

Cyber Security Associates Ltd

5 Hatfields, London, SE1 9PG

 

**United Kingdom - Gloucester**

Cyber Security Associates Ltd

Unit 11, Wheatstone Court, Waterwells Business Park, GL2 2AQ

 

**Phone:** [+44(0) 300 303 4691](tel:03003034691)

**Email:** [hello@csacyber.com](mailto:hello@csacyber.com)

 

**United States of America**

Cyber Security Associates Inc.

6010 W. Spring Creek Pkwy, Plano, Texas, 75024

 

**Phone:** [+1 469 750 1695](tel:14697501695) 

**Email:** [hello@csacyber.com](mailto:hello@csacyber.com)

 

[![trust-pilot](https://csacyber.com/hs-fs/hubfs/trust-pilot.png?width=178&height=104&name=trust-pilot.png)](https://uk.trustpilot.com/review/csa.limited)

 

---

- [Website Terms of Use](https://csacyber.com/website-terms-of-use)
- [Website Privacy Policy](https://csacyber.com/privacy-notice)
- [Website Cookie Policy](https://csacyber.com/cookie-policy)

 Copyright 2026. Cyber Security Associates Ltd [Follow us on Facebook](https://www.facebook.com/CSALIMITED/) [Follow us on LinkedIn](https://www.linkedin.com/company/csa-cyber/) [Follow us on Twitter](https://twitter.com/cybersecurityis) [Follow us on Facebook](https://www.youtube.com/@cybersecurityassociateslim) [Follow us on Facebook](https://www.instagram.com/cybersecurityassociates)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Cyber Security Associates",
    "url" : "https://csacyber.com/blog/author/cyber-security-associates"
  },
  "dateModified" : "2024-12-07T13:26:35.469Z",
  "datePublished" : "2023-07-20T04:15:00.000Z",
  "headline" : "Pentesting Keycloak – Part 2: Identifying Misconfiguration Using Risk Management Tools",
  "image" : [ "https://csacyber.com/hubfs/keyboard-pentest-1-800x500-1.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://csacyber.com/blog/pentesting-keycloak-part-2",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://csacyber.com/hubfs/csacyber-logo-black-01.svg"
    },
    "name" : "Cyber Security Associates Ltd"
  }
}
```