Web Auth JWT

Attack JWT/session authentication. Load when auth uses a JWT (three base64url parts, header.payload.signature), Authorization: Bearer, or you see alg/kid/jku fields. Signals: eyJ... tokens, "alg":"none"/"HS256"/"RS256", kid header, JWKS endpoints, role/admin claims.

NoorQureshi 5ac17a7 2 files · 4.9 KB Updated

File contents

NoorQureshi/SploitAgent/tree/main/skills/web/web-auth-jwt commit 5ac17a7809

Frequently asked questions

npx skillmds@latest add noorqureshi/web-auth-jwt