|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Cryptocurrency News Video
What's this eyJ Token? | JWT Breakdown Part 1
Mar 24, 2024 at 09:51 pm Seven Seas Security
Hacking JWTs! Portswigger Web Security Academy JWT authentication bypass via unverified signature - https://portswigger.net/web-security/jwt/lab-jwt-authentication-bypass-via-unverified-signature
▹ SKIP TO LAB - 5:12
▹ Watch me Live on Twitch - https://twitch.tv/garr_7
▹ Shoutout to Shikairi for the Editing! - https://twitter.com/_shikairi
#JWThacking #hacker #bugbounty #website
▹ Additional References for Further Exploration:
Fireship Session vs Token Authentication - https://www.youtube.com/watch?v=UBUNrFtufWo
JWT Parkour by Louis from PentesterLab - https://www.youtube.com/watch?v=zWVRHK3ykfo
JWT RFC - https://datatracker.ietf.org/doc/html/rfc7519
------------------------------------------------------------------------------
In this series, we take a look at Web Security Academy's JWT Labs and break them down. The goal is to break down the concepts to not only get to the solution, but talk about methodology and the mental steps we take in order to discover these vulnerabilities in the wild.
Timestamps:
0:00 New to hacking? What's eyJ all about?
0:28 What is a JWT?
1:47 Components of a JWT
3:35 Why even use a JWT over traditional, Cookie-based auth?
4:30 Where do issues arise with JWTs?
5:12 JWT Methodology and Lab START
9:51 Recap on JWTs
6:07 Outro
Disclaimer:info@kdj.com
The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!
If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.






























