Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Active Test / JWT Token #71

Open
DeliciousBounty opened this issue Aug 31, 2022 · 3 comments
Open

Active Test / JWT Token #71

DeliciousBounty opened this issue Aug 31, 2022 · 3 comments
Labels
New active check New active check

Comments

@DeliciousBounty
Copy link
Collaborator

We are looking for contributors!

JWT attacks involve a user sending modified JWTs to the server to accomplish a malicious goal.
Typically, the goal is to circumvent authentication and access controls by impersonating another authenticated user.
This active check simulates a real attack based JWT token on the API.
Fore more info:
https://portswigger.net/web-security/jwt
https://infosecwriteups.com/attacks-on-json-web-token-jwt-278a49a1ad2e
https://book.hacktricks.xyz/pentesting-web/hacking-jwt-json-web-tokens

@DeliciousBounty DeliciousBounty added the New active check New active check label Sep 1, 2022
@RazMag RazMag added the bounty label Sep 4, 2022
@aayush-vish
Copy link

Wanted to Work on this Issues

@DeliciousBounty
Copy link
Collaborator Author

Hey @aayush-vish !
Great, this active test is still available. You can join us on our discord server if you have any question :)
https://discord.gg/nswBjZRt

@DeliciousBounty
Copy link
Collaborator Author

Hello @aayush-vish , do you need any help for this issue?

@RazMag RazMag removed the bounty label Oct 25, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
New active check New active check
Projects
None yet
Development

No branches or pull requests

3 participants