BigHugger
sk Skill · mukul975

performing-jwt-none-algorithm-attack

Execute and test the JWT none algorithm attack, crafting tokens with the alg header set to none using PyJWT and an intercepting proxy (Burp Suite/mitmproxy) to bypass signature verification and forge arbitrary claims. Use during authorized penetration tests or security assessments of applications that use JWT for authentication or authorization, to validate that the server rejects unsigned tokens.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
pythonPythonweb-securitypenetration-testingauthentication-bypassowaspsignature-bypasstoken-manipulationnone-algorithmjsonjwt
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python