JWT attacks
Vulnerabilities
Secret keys
Public available keys
Brute-forcing keys
hashcat -m 16500 -a 0 <jwt> <wordlist>Header parameter injection
Injecting self signed JWTs
Via jwk parameter (Burp Suite)
Via jku parameter
Via kid parameter
Other interesting JWT header parameters
Last updated