JWT Authentication Bypass via kid Header Path Traversal

Поделиться
HTML-код
  • Опубликовано: 15 ноя 2024

Комментарии • 7

  • @MichaelCooter
    @MichaelCooter Год назад +1

    FIRST ! I am appreciative of all the JWT attack coverage.

  • @ShahriyarRzayev
    @ShahriyarRzayev Год назад +2

    One possible way is also in Burp Suite -> JSON Web Token -> Attack -> Sign with Empty Key -> Send to /admin.

    • @mukto2004
      @mukto2004 14 часов назад

      didnt worked for me gave unauthorized response

  • @sumanth5121
    @sumanth5121 4 месяца назад

    hey bro it seems my jwt editor extension is not working. whenever i try to resign with the key i generated it just doesnt get resigned.
    i found another way to solve this.

  • @niranjantechintelugu2968
    @niranjantechintelugu2968 Год назад

    I have one Jwt token.. It was free token... And and i need to modify that to vip token... Is this possible to edit??? If signature changed the server said token not provided in return response

    • @intigriti
      @intigriti  Год назад +1

      Are you referring to a lab? 🧐