JWT Attacks
Forge or tamper JSON Web Tokens by abusing weak verification.
Tags: jwt, auth, crypto
Level: intermediate
Method
Decode & inspect
Read the header and claims. Note the alg, kid, and any user/role fields. Never trust client-side; the server's verification is the target.
python3 jwt_tool.py <token>Tools: jwt_tool
alg:none & confusion
Try alg:none (unsigned) and RS256→HS256 key confusion (sign with the public key as HMAC secret).
python3 jwt_tool.py <token> -X aTools: jwt_tool
Crack weak secrets
For HS256, brute-force the signing secret offline with a wordlist. Weak secrets are common in dev-leaked configs.
python3 jwt_tool.py <token> -C -d rockyou.txtTools: jwt_tool
kid / jku injection
Test path traversal or SQLi in kid, and attacker-controlled jku/x5u URLs pointing to your own key.
Tools: jwt_tool
Field notes
- Tamper a claim (role:admin) and re-sign to prove impact once you have a bypass.
- Check for JWTs in cookies, Authorization headers, and WebSocket handshakes alike.