JWT kid Injection

Bookmarked!

This exercise covers the exploitation of an issue in the usage of JWT token

PRO Medium 1-2 Hrs. 2961 Blue Badge
Course

This course explores the exploitation of a vulnerability in the use of JSON Web Tokens (JWT) for authentication, specifically focusing on manipulating the <code>kid</code> parameter to gain administrator access. This exercise was originally a challenge in the complex and highly-regarded BitcoinCTF Capture-The-Flag competition.

Skills covered
Injection Authentication Cryptography Operating System
Topics
JWT
cwe-310
Included with PRO
Full course content 3 videos

Ready to practice?

Get access to this lab and 600+ hands-on exercises with a PRO subscription.