vulns.co
/
GKData.io MCP

Back to Playbooks

JWT Attacks

Forge or tamper JSON Web Tokens by abusing weak verification.

Tags: jwt, auth, crypto

Level: intermediate

Method

  1. Decode & inspect

    Read the header and claims. Note the alg, kid, and any user/role fields. Never trust client-side; the server's verification is the target.

    python3 jwt_tool.py <token>

    Tools: jwt_tool

  2. alg:none & confusion

    Try alg:none (unsigned) and RS256→HS256 key confusion (sign with the public key as HMAC secret).

    python3 jwt_tool.py <token> -X a

    Tools: jwt_tool

  3. Crack weak secrets

    For HS256, brute-force the signing secret offline with a wordlist. Weak secrets are common in dev-leaked configs.

    python3 jwt_tool.py <token> -C -d rockyou.txt

    Tools: jwt_tool

  4. kid / jku injection

    Test path traversal or SQLi in kid, and attacker-controlled jku/x5u URLs pointing to your own key.

    Tools: jwt_tool

Field notes

  • Tamper a claim (role:admin) and re-sign to prove impact once you have a bypass.
  • Check for JWTs in cookies, Authorization headers, and WebSocket handshakes alike.

References