22.6 Lab: JWT authentication bypass via kid header path traversal - Karthikeyan Nagaraj | 2024

  Рет қаралды 35

Cyberw1ng

Cyberw1ng

15 күн бұрын

A Simple writeup is posted on Medium - / cyberw1ng
Disclaimer:
The content shared in this video is intended for educational purposes only. The demonstrations, tutorials, and information presented are meant to highlight common vulnerabilities in cybersecurity systems and are performed in controlled environments, such as the Portswigger Labs, with explicit permission. The primary goal is to enhance knowledge and awareness of potential security threats and vulnerabilities.
Please be aware that attempting to exploit or replicate these techniques without proper authorization may violate applicable laws and regulations. The creator of this content does not encourage any illegal activities, and the responsibility for any misuse or consequences arising from these demonstrations lies solely with the viewer.
Always ensure that you have the appropriate permissions before conducting security testing on any system. It is recommended to seek professional advice and authorization from the relevant parties before attempting any penetration testing, ethical hacking, or security research.
The creator disclaims any liability for the misuse or misinterpretation of the information provided in this video. Viewers are encouraged to use this knowledge responsibly and ethically.
Description - Portswigger Lab
This lab uses a JWT-based mechanism for handling sessions. In order to verify the signature, the server uses the kid parameter in JWT header to fetch the relevant key from its filesystem. To solve the lab, forge a JWT that gives you access to the admin panel at /a dmin, then delete the user carlos. You can log in to your own account usingg the following credentials: wiener:peter | Karthikeyan Nagaraj
#cybersecurity #walkthrough #career

Пікірлер
JWT Authentication Bypass via jku Header Injection
13:40
Intigriti
Рет қаралды 3,7 М.
Do you have a friend like this? 🤣#shorts
00:12
dednahype
Рет қаралды 47 МЛН
What is Directory Traversal?
6:31
Intigriti
Рет қаралды 40 М.
Become a Penetration Tester without experience
9:14
UnixGuy | Cyber Security
Рет қаралды 37 М.
FREE Path To Become An Ethical Hacker (2024 Roadmap)
17:11
The Infosec Academy
Рет қаралды 370 М.
👎Главный МИНУС планшета Apple🍏
0:29
Demin's Lounge
Рет қаралды 498 М.
Carregando telefone com carregador cortado
1:01
Andcarli
Рет қаралды 2 МЛН
The power button can never be pressed!!
0:57
Maker Y
Рет қаралды 54 МЛН