webmedium
Хьюстон, у нас течь (Houston, We Have a Leak)
hackerlab
Task: Bypass authentication on CyberCorp website. Solution: Discovered unauthenticated Kibana via subdomain enumeration, found JWT tokens and employee chat in logs revealing algorithm confusion vulnerability, forged JWT using public RSA key as HMAC secret (CVE-2016-10555).
$ ls tags/ techniques/
jwt_algorithm_confusionelk_stack_enumerationsubdomain_discoveryhmac_with_public_key
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]