JWT X

Bookmarked!

This exercise covers how to use the jku header to bypass an authentication based on JWT.

PRO Hard < 1 Hr. 805 Green Badge
Course

In this exercise, you will learn how to exploit the <code>jku</code> header in JWT tokens to forge a token and gain admin privileges. We will utilize an Open Redirect vulnerability to bypass URL restrictions and manipulate the JWT.

Injection Authentication Authorisation Cryptography Operating System Network
JWT
cwe-310
Full course content 2 videos

Ready to practice?

Get access to this lab and 600+ hands-on exercises with a PRO subscription.