webPromedium

Lab 350 — VaultKeeper

hackadvisor

Task: VaultKeeper enterprise secrets management platform uses RS256 JWT authentication with exposed public key. Solution: JWT Algorithm Confusion attack (CVE-2016-10555) — changed alg from RS256 to HS256 and signed with the RSA public key as HMAC secret to forge admin token.

$ ls tags/ techniques/
jwt_algorithm_confusionhmac_with_public_keydecoy_flag_identificationrole_based_access_control_bypassjwk_to_pem_conversion

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups