Exercises › Tags › JWT
Exercises tagged “JWT”
18
exercises tagged JWT
Browse all exercises
| Exercise | Avg. Time | Difficulty | Solved by | Tier | |
|---|---|---|---|---|---|
|
|
API JWT REVOCATION
This exercise covers how to bypass a weak JWT Revocation Mechanism.
|
< 1 Hr. | 529 | PRO | |
|
|
JSON Web Token XV: CVE-2022-39227
This exercise covers the exploitation of polyglot token against python_jwt (CVE-2022-39227)
|
< 1 Hr. | 52 | PRO | |
|
|
JWT Algorithm Confusion with ECDSA Public Key Recovery
This exercise covers the exploitation of algorithm confusion when no public key is available with a ECDSA key
|
1-2 Hr. | 55 | PRO | |
|
|
CVE-2022-21449
This exercise covers the exploitation of CVE-2022-21449 against a Java Application relying on JWT
|
< 1 Hr. | 192 | PRO | |
|
|
JWT Algorithm Confusion with RSA Public Key Recovery
This exercise covers the exploitation of algorithm confusion when no public key is available
|
< 1 Hr. | 243 | PRO | |
|
|
JWT XII
This exercise covers how to use the x5u header to bypass an authentication based on JWT.
|
< 1 Hr. | 720 | PRO | |
|
|
JWT XI
This exercise covers how to use the jku header to bypass an authentication based on JWT.
|
< 1 Hr. | 715 | PRO | |
|
|
JWT X
This exercise covers how to use the jku header to bypass an authentication based on JWT.
|
< 1 Hr. | 812 | PRO | |
|
|
JWT IX
This exercise covers how to use the jku header to bypass an authentication based on JWT.
|
< 1 Hr. | 940 | PRO | |
|
|
JWT VIII
This exercise covers how to use the jku header to bypass an authentication based on JWT.
|
< 1 Hr. | 1017 | PRO | |
|
|
JWT VII
This exercise covers the exploitation of a website using JWT for session without verifying the signature
|
< 1 Hr. | 3582 | PRO | |
|
|
JWT VI
This exercise covers the exploitation of an injection in the kid element of a JWT. This injection can be used to bypass the signature mechanism
|
< 1 Hr. | 2643 | PRO | |
|
|
JWT V
This exercise covers the exploitation of a trivial secret used to sign JWT tokens.
|
< 1 Hr. | 3208 | PRO | |
|
|
CVE-2018-0114
This exercise details
the exploitation of a vulnerability in Cisco's node-jose, a JavaScript library created to manage JWT
|
< 1 Hr. | 1942 | PRO | |
|
|
JWT IV
This exercise covers the exploitation of a vulnerability similar to the recent CVE-2017-17405 impacting Ruby Net::FTP
|
< 1 Hr. | 2790 | PRO | |
|
|
JWT kid Injection
This exercise covers the exploitation of an issue in the usage of JWT token
|
< 1 Hr. | 3020 | PRO | |
|
|
JWT Algorithm Confusion
This exercise covers the exploitation of an issue with some implementations of JWT
|
< 1 Hr. | 3907 | PRO | |
|
|
JSON Web Token None Algorithm
This exercise covers the exploitation of a signature weakness in a JWT library.
|
< 1 Hr. | 10385 | PRO |
Browse by Tag
Didn't find what you were after?
Tell us what you would like to see covered and we will look into it.
support@pentesterlab.com