Exercises › Tags › JWT

Exercises tagged “JWT”

18 exercises tagged JWT Browse all exercises
Exercise Avg. Time Difficulty Solved by Tier
API JWT REVOCATION
This exercise covers how to bypass a weak JWT Revocation Mechanism.
< 1 Hr. easy 529 PRO
JSON Web Token XV: CVE-2022-39227
This exercise covers the exploitation of polyglot token against python_jwt (CVE-2022-39227)
< 1 Hr. hard 52 PRO
JWT Algorithm Confusion with ECDSA Public Key Recovery
This exercise covers the exploitation of algorithm confusion when no public key is available with a ECDSA key
1-2 Hr. hard 55 PRO
CVE-2022-21449
This exercise covers the exploitation of CVE-2022-21449 against a Java Application relying on JWT
< 1 Hr. medium 192 PRO
JWT Algorithm Confusion with RSA Public Key Recovery
This exercise covers the exploitation of algorithm confusion when no public key is available
< 1 Hr. hard 243 PRO
JWT XII
This exercise covers how to use the x5u header to bypass an authentication based on JWT.
< 1 Hr. hard 720 PRO
JWT XI
This exercise covers how to use the jku header to bypass an authentication based on JWT.
< 1 Hr. hard 715 PRO
JWT X
This exercise covers how to use the jku header to bypass an authentication based on JWT.
< 1 Hr. hard 812 PRO
JWT IX
This exercise covers how to use the jku header to bypass an authentication based on JWT.
< 1 Hr. hard 940 PRO
JWT VIII
This exercise covers how to use the jku header to bypass an authentication based on JWT.
< 1 Hr. hard 1017 PRO
JWT VII
This exercise covers the exploitation of a website using JWT for session without verifying the signature
< 1 Hr. easy 3582 PRO
JWT VI
This exercise covers the exploitation of an injection in the kid element of a JWT. This injection can be used to bypass the signature mechanism
< 1 Hr. medium 2643 PRO
JWT V
This exercise covers the exploitation of a trivial secret used to sign JWT tokens.
< 1 Hr. medium 3208 PRO
CVE-2018-0114
This exercise details the exploitation of a vulnerability in Cisco's node-jose, a JavaScript library created to manage JWT
< 1 Hr. hard 1942 PRO
JWT IV
This exercise covers the exploitation of a vulnerability similar to the recent CVE-2017-17405 impacting Ruby Net::FTP
< 1 Hr. medium 2790 PRO
JWT kid Injection
This exercise covers the exploitation of an issue in the usage of JWT token
< 1 Hr. medium 3020 PRO
JWT Algorithm Confusion
This exercise covers the exploitation of an issue with some implementations of JWT
< 1 Hr. medium 3907 PRO
JSON Web Token None Algorithm
This exercise covers the exploitation of a signature weakness in a JWT library.
< 1 Hr. easy 10385 PRO
Didn't find what you were after?

Tell us what you would like to see covered and we will look into it.

support@pentesterlab.com