filmov
tv
Advanced Web Application Penetration Testing JWT Security Issues
Показать описание
Presented by: Adrien de Beaupré
JWTs are an important part of how modern APIs are used, they assert your identify to the application. You will see them in SOAP, REST, and GraphQL. Many decisions about authorization and access are based on the claims contained within the JWT. If there are vulnerabilities within the framework used to create them, or in implementation decisions, the impact can be high.
In this webcast , I will discuss how JWTs are generated and used. Security issues can include information disclosure, authentication bypass, authorization control bypass, password cracking, JWT reuse, algorithms such as None, and algorithm exchange. I will demonstrate the None algorithm attack, cracking the secret key used to sign the JWT, and algorithm exchange.
JWTs are an important part of how modern APIs are used, they assert your identify to the application. You will see them in SOAP, REST, and GraphQL. Many decisions about authorization and access are based on the claims contained within the JWT. If there are vulnerabilities within the framework used to create them, or in implementation decisions, the impact can be high.
In this webcast , I will discuss how JWTs are generated and used. Security issues can include information disclosure, authentication bypass, authorization control bypass, password cracking, JWT reuse, algorithms such as None, and algorithm exchange. I will demonstrate the None algorithm attack, cracking the secret key used to sign the JWT, and algorithm exchange.
Mastering Advanced Web Application Penetration Testing: Techniques & Tools
Web Application Penetration Testing - A Practical Methodology
Hacking Web Applications (2+ hours of content)
Ethical Hacking 101: Web App Penetration Testing - a full course for beginners
Real web application pentest, NOT a CTF!
I AUTOMATED a Penetration Test!?
Roadmap to become a pentester
Bug Bounty Course 2024 Updated
Advanced Web Application Penetration Testing JWT Security Issues
What is Web Application Penetration Testing? | Web Application Hacking & Security Course
Automated Hacking Tool?! | OWASP ZAP Tutorial
Simple Penetration Testing Tutorial for Beginners!
Course Preview: Advanced Web Application Penetration Testing with Burp Suite
complete penetration testing course in 11 hours | penetration testing training
Conduct a Penetration Test Like a Pro in 6 Phases [Tutorial]
Testing for SQL injection vulnerabilities with Burp Suite
Web Application Penetration Testing: Steps, Methods, & Tools | PurpleSec
What makes SEC642: Advanced Web App Penetration Testing such a great course?
Why should students take SEC642: Advanced Web App Penetration Testing?
Modern Web Application Penetration Testing Part 1, XSS And XSRF Together
Learn WebApp Pentesting: 2023 edition
Simple Penetration Testing Tutorial for Beginners!
Beginner to Advanced Bug Bounty Hunting Course | 2022
SANS Webcast: What’s covered in the our Adv. Web App Pen Testing Course (SEC642)?
Комментарии