webProeasy

rigidType

hackerlab

Task: Flask app with JWT authentication, source code provided. Solution: JWT None Algorithm Attack - the jwt.decode() allows 'none' algorithm and has verify_signature=False, enabling token forgery with admin privileges.

$ ls tags/ techniques/
JWT None Algorithm AttackJWT Signature Verification BypassToken Forgery

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups