How to Exploit "Json Web Token"(JWT) vulnerabilities | Full Practical

Поделиться
HTML-код
  • Опубликовано: 11 ноя 2024

Комментарии • 45

  • @LinuxSploitOfficial
    @LinuxSploitOfficial  3 года назад +3

    Become Part of LinuxSploit by clicking SUBSCRIBE button

  • @marshal_demi
    @marshal_demi Год назад +1

    Thanks, Boss. The first part helped me in a CTF

  • @corpsecoder5216
    @corpsecoder5216 3 года назад +2

    This is awesome you went into depth on how Jwt works thank you

    • @LinuxSploitOfficial
      @LinuxSploitOfficial  3 года назад +2

      Glad it was helpful!

    • @corpsecoder5216
      @corpsecoder5216 3 года назад +1

      @@LinuxSploitOfficial Yea your the only you tuber that goes into details of the attack also can you do a vid on linux enumeration bless you

  • @sushantkamble004
    @sushantkamble004 3 года назад +4

    Superb explanation bro need more videos on these critical bugs 👍🏻

  • @jerrytech1901
    @jerrytech1901 3 года назад +1

    thanks, man....waiting for more videos like this...

  • @StudiofrogPl
    @StudiofrogPl Год назад +1

    amazing stuff, thank you.

  • @syedpc7833
    @syedpc7833 4 года назад +3

    WELL EXPLAINED!

  • @Sstrik
    @Sstrik Месяц назад

    Perfect video

  • @sushantdhopat
    @sushantdhopat 3 года назад +1

    Amazing video!👍

  • @grgnizz
    @grgnizz 4 года назад +3

    great content,subscribed, hope to see the same quality content

  • @kietpoki3
    @kietpoki3 3 года назад +1

    thank, really useful

  • @flippy3461
    @flippy3461 3 года назад +1

    Great content, keep it up.

  • @FauziBhai
    @FauziBhai 3 года назад +1

    Great video

    • @LinuxSploitOfficial
      @LinuxSploitOfficial  3 года назад +2

      Thanks for the visit

    • @FauziBhai
      @FauziBhai 3 года назад +1

      @@LinuxSploitOfficial Keep it up great learning content. Now bro making video on DOM XSS because its so confusing.

  • @dr_tomato771
    @dr_tomato771 3 года назад +1

    When i write the same python code 4:09 in Window i get another output . Idk why ! :(

    • @LinuxSploitOfficial
      @LinuxSploitOfficial  3 года назад +2

      you also need public key to generate valid token,
      here is the script: github.com/farah-hawa/Jwt-code

  • @vishalkothari8065
    @vishalkothari8065 3 года назад +2

    Where can we get the public key in order to get the admin token ?

    • @LinuxSploitOfficial
      @LinuxSploitOfficial  3 года назад +2

      It could be exposed in JavaScript or exposed like www.example.com/secret/key.pub . waybackurl, gobuster could be helpful to find it.

    • @vishalkothari8065
      @vishalkothari8065 3 года назад +1

      @@LinuxSploitOfficial okay, just a request if u can address in any of your upcoming video how to protect it as a part of software development is concerned, so as to avoid its exploitation. Like that would be great 🔥

  • @smandoece
    @smandoece 3 года назад +1

    Thank you for your video, it is really helpful! If we want to make the python script appropriate for RS256 algorithm encryption, not HS256, what modules should we use and how should we modify the code in order to produce the corresponding signature? Thanks a lot.

  • @c09yc47
    @c09yc47 3 года назад +1

    Which lab are you using

  • @macspexs7710
    @macspexs7710 3 года назад +1

    Are there any online websites or tools that can convert RSA to HMAC JSON Token

    • @LinuxSploitOfficial
      @LinuxSploitOfficial  3 года назад +2

      Python Code used to generate signature: github.com/farah-hawa/Jwt-code

  • @healthplus8073
    @healthplus8073 3 года назад +1

    Please Can you host the code that used to crack the jwt ??

    • @LinuxSploitOfficial
      @LinuxSploitOfficial  3 года назад +2

      LAB: github.com/h-a-c/jwt-lab​ Code used to generate signature: github.com/farah-hawa/Jwt-code​

    • @healthplus8073
      @healthplus8073 3 года назад +1

      @@LinuxSploitOfficial Thank You

  • @anik6393
    @anik6393 3 года назад +1

    Well done bro❤️make more bro

  • @Hackedpw
    @Hackedpw 3 года назад +1

    Ok

  • @borderline7742
    @borderline7742 Год назад +1

    impossible to watch with annoying robot voice

    • @LinuxSploitOfficial
      @LinuxSploitOfficial  Год назад +2

      I apologize for the inconvenience caused by the annoying robot voice. Should i considered trying out wellsaidlabs.com/ for a more realistic AI voice over for my RUclips content?
      Please let me know what you think about it.