JWT X

Bookmarked!

This exercise covers how to use the jku header to bypass an authentication based on JWT.

PRO Hard < 1 Hr. 785 Green Badge
Course

In this exercise, you will learn how to exploit the <code>jku</code> header in JWT tokens to forge a token and gain admin privileges. We will utilize an Open Redirect vulnerability to bypass URL restrictions and manipulate the JWT.

Skills covered
Injection Authentication Authorisation Cryptography Operating System Network
Topics
JWT
cwe-310
Included with PRO
Full course content 2 videos

Ready to practice?

Get access to this lab and 600+ hands-on exercises with a PRO subscription.