JWT IX

Bookmarked!

This exercise covers how to use the jku header to bypass an authentication based on JWT.

PRO Hard < 1 Hr. 911 Green Badge
Course

In this exercise, you will learn how to exploit the <code>jku</code> header in JWT tokens to become an admin by forging a token. This involves creating a malicious JWK file, uploading it to the server, and bypassing URL restrictions.

Skills covered
Injection Authentication
Topics
JWT
cwe-310
Included with PRO
Full course content 2 videos

Ready to practice?

Get access to this lab and 600+ hands-on exercises with a PRO subscription.