BigHugger
sk Skill · mukul975

testing-for-json-web-token-vulnerabilities

Tests JWT implementations for algorithm confusion, "none" algorithm bypass, kid/jku parameter injection, and weak secret exploitation using jwt_tool and Burp Suite's JWT Editor extension, aiming to achieve authentication bypass and privilege escalation. Use when assessing JWT-based auth/session management, OAuth2/OIDC token handling, or SSO systems during a security engagement.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
bashPythonkid-injectionjku-attacktoken-forgeryauthentication-bypassalgorithm-confusionjson-web-tokenjwt
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python