Lab: JWT authentication bypass via kid header path traversal

preview_player
Показать описание
This lab uses a JWT-based mechanism for handling sessions. In order to verify the signature, the server uses the kid parameter in JWT header to fetch the relevant key from its filesystem.

To solve the lab, forge a JWT that gives you access to the admin panel at /admin, then delete the user carlos.

You can log in to your own account using the following credentials: wiener:peter

Рекомендации по теме
Комментарии
Автор

can you give us next 2 jwt lab video fast. I am waiting for your video.

PixelPulse_Playbook
welcome to shbcf.ru