✍️
Writeups and Walkthroughs
search
⌘Ctrlk
HomeGitHubPortfolio Twitter/X Medium Cont@ct
✍️
Writeups and Walkthroughs
  • ✍️Writeups and Walkthroughs
  • THM
  • HackTheBox
  • Vulnhub
  • DockerLabs
  • DVWA
  • Mutillidae II
  • Secure Bank
  • PortSwigger - Web Security Academy
    • slidersBurp Suite Configarrow-up-right
    • iInformation Disclosure
    • eEssential skills
    • sServer-side vulnerabilities
    • jJWT Attacks
      • 1Json Web Tokens (JWT)
      • 2Exploiting JWT
        • flask-vialJWT authentication bypass via unverified signature
        • vial-virusJWT authentication bypass via flawed signature verification
        • vialJWT authentication bypass via weak signing key
        • To-Do
          • vialsJWT authentication bypass via jwk header injection - %
          • flaskJWT authentication bypass via jku header injection - %
          • flask-vialJWT authentication bypass via kid header path traversal - %
    • aAPI Testing
    • dDeserialization Insecure
  • HomeMade Labs
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. PortSwigger - Web Security Academychevron-right
  2. jJWT Attackschevron-right
  3. 2Exploiting JWT

To-Do

vialsJWT authentication bypass via jwk header injection - %chevron-rightflaskJWT authentication bypass via jku header injection - %chevron-rightflask-vialJWT authentication bypass via kid header path traversal - %chevron-right
PreviousJWT authentication bypass via weak signing keychevron-leftNextJWT authentication bypass via jwk header injection - %chevron-right