JWT VIII

Bookmarked!

This exercise covers how to use the jku header to bypass an authentication based on JWT.

PRO Hard 1-2 Hrs. 989 Green Badge
Course

In this exercise, you will learn how to exploit the <code>jku</code> header in JWT tokens to forge a token and become an admin. This involves creating a public key that the application will trust and signing the token with the corresponding private key.

Skills covered
Injection Authentication Cryptography Operating System Network
Topics
JWT
cwe-310
Included with PRO
Full course content 3 videos

Ready to practice?

Get access to this lab and 600+ hands-on exercises with a PRO subscription.