JSON Web Token Attacks: LAB #7 - JWT Authentication Bypass Via Algorithm Confusing

  Рет қаралды 4,026

Emanuele Picariello

Emanuele Picariello

Күн бұрын

Пікірлер: 6
@emanuelepicariello
@emanuelepicariello 2 жыл бұрын
Please Leave A Like And Eventually Subscribe
@acronproject
@acronproject Жыл бұрын
Thanks
@ahhackherewegoagain1044
@ahhackherewegoagain1044 2 жыл бұрын
I've done everything i've saw from you but i still got an unauthorized response what can i do?
@emanuelepicariello
@emanuelepicariello 2 жыл бұрын
Hi, If you followed correctly all the steps you should not have any problems. But maybe you could have mistaken something. I highlight you some things that are coming on my mind. Do you set algo to “HS256” and sub to “administrator”? Also remember to sign the request. This maybe could be the reason. If not, please feel free to ask more questions, but be sure that all the steps are right.
@ahhackherewegoagain1044
@ahhackherewegoagain1044 2 жыл бұрын
@@emanuelepicariello Hi, Thanks for your answer , yeah i did all of that My steps were; I copy the public key from jwks.json I add it into a new RSA key in a format of JWK then copy the PEM I base64 encode PEM than paste it in a new symmetric key as k parameters value I then change the alg: to HS256 , sub to administrator sign the request with the don't modify header option selected and send the request . I am still getting an unauthorized response .
@emanuelepicariello
@emanuelepicariello 2 жыл бұрын
@@ahhackherewegoagain1044 It seems you are doing right. Maybe there could me a problem in this case minute: 3:02, when you insert the PEM into the decoder try to cancel the empty line if is present, the one below “--END PUBLIC KEY--“. I don’t remember if in this lab or other I was having problem with that line. Last thing try to check the link if it is correct, last try 😅 paste the cookie into the browser and try from there. Let me know
JWT Authentication Bypass via Algorithm Confusion
12:24
Intigriti
Рет қаралды 7 М.
Cheerleader Transformation That Left Everyone Speechless! #shorts
00:27
Fabiosa Best Lifehacks
Рет қаралды 16 МЛН
小丑女COCO的审判。#天使 #小丑 #超人不会飞
00:53
超人不会飞
Рет қаралды 16 МЛН
Арыстанның айқасы, Тәуіржанның шайқасы!
25:51
QosLike / ҚосЛайк / Косылайық
Рет қаралды 700 М.
Hack JWT using JSON Web Tokens Attacker BurpSuite extensions
17:23
thehackerish
Рет қаралды 46 М.
JWT Authentication Bypass via kid Header Path Traversal
15:11
Difference between cookies, session and tokens
11:53
Valentin Despa
Рет қаралды 679 М.
Attacking JWT - Header Injections
18:28
The Cyber Mentor
Рет қаралды 15 М.
Hackers Bypass Google Two-Factor Authentication (2FA) SMS
12:47
John Hammond
Рет қаралды 1,1 МЛН
JWT Authentication Bypass via Flawed Signature Verification
10:56
JWT | JSON Web Token | Bug Bounty | Penetration Testing
9:50
Cheerleader Transformation That Left Everyone Speechless! #shorts
00:27
Fabiosa Best Lifehacks
Рет қаралды 16 МЛН