JWT Algorithm Confusion

Identify and exploit Algorithm Confusion vulnerabilities in JSON Web Tokens (JWT). This skill details how to bypass signature verification by changing the signing algorithm from asymmetric (RS256) to symmetric (HS256) and using the public key as the symmetric secret.

ShulkwiSEC 5a52975 3 files · 11.7 KB Updated 21 repo stars

File contents

ShulkwiSEC/bb-huge/tree/main/skills/curated/jwt-algorithm-confusion commit 5a5297599d

Frequently asked questions

npx skillmds add shulkwisec/jwt-algorithm-confusion