JWT Authentication Bypass via kid Header Path Traversal
👩🎓👨🎓 Learn about JSON Web Token (JWT) vulnerabilities. In order to verify the signature, the server uses the 'kid' (key ID) parameter in JWT header to fetch the relevant key from its filesystem. To solve the lab, we'll forge a JWT that provides access to the admin panel, then delete the user carlos. Overview: 0:00 Intro 0:13 Recap 0:38 JWT header parameter injections 1:30 Injecting self-signed JWTs via the kid parameter 3:30 Other interesting JWT header parameters 5:02 Lab: JWT authentication bypass via kid header path traversal 6:11 Solution #1: python 7:32 Solution #2: burp suite 10:45 Solution #3: jwt_tool 13:39 How to prevent JWT attacks 14:22 Additional best practice for JWT handling 14:44 Conclusion If you're struggling with the concepts covered in this lab, please review the Introduction to JWT Attacks video first: • Introduction to JWT Attacks 🧠 For more information, check out https://portswigger.net/web-security/jwt 🔗 @PortSwiggerTV challenge: https://portswigger.net/web-security/... 🧑💻 Sign up and start hacking right now - https://go.intigriti.com/register 👾 Join our Discord - https://go.intigriti.com/discord 🎙️ This show is hosted by / _cryptocat ( @_CryptoCat ) & / intigriti 👕 Do you want some Intigriti Swag? Check out https://swag.intigriti.com 🐍 Python scripts demonstrated in this series can be found here: https://github.com/Crypto-Cat/CTF/tre...

JWT Authentication Bypass via Algorithm Confusion

Attacking JWT - Header Injections

JWT Explained: The Digital ID Card Behind Every Login

JWT Authentication Bypass via jwk Header Injection

Cracking JSON Web Tokens

7 Authentication Concepts Every Developer Should Know

JWT Authentication Bypass via jku Header Injection

Most Devs Get API Authentication Wrong ?

How Agents Quietly Break Architecture

JSON Web Token Vulnerabilities

Directory Traversal Attacks Made Easy

researcher accidentally finds 0-day affecting his entire internet service provider

Anthropic is Completely F*cked.

Vintage Mediterranean Summer Painting Screensaver l Frame TV ART

JWT authentication bypass via algorithm confusion | PortSwigger Academy tutorial

I Hacked This Temu Router. What I Found Should Be Illegal.

I Made an Antivirus That Secretly Attacks Scammers

"Hack ANY Cell Phone" - Hacker Shows How Easy It Is To Hack Your Cell Phone

Authentication Bypass Via JWK Header Injection | JWT Hacking

