JWT

JWT attack playbook — algorithm confusion (alg=none, HS/RS confusion), kid path traversal/SQLi, jku/x5u SSRF, weak HS256 cracking, and embedded JWK trickery. Use when the target uses JWTs for auth (header.payload.signature).

pentesterflow 4c3f53e 4 files · 6.5 KB Updated

File contents

pentesterflow/agent/tree/main/skills/jwt commit 4c3f53ea88

Frequently asked questions

npx skillmds@latest add pentesterflow/jwt