webmedium

Хьюстон, у нас течь (Houston, We Have a Leak)

hackerlab

Task: Bypass authentication on CyberCorp website. Solution: Discovered unauthenticated Kibana via subdomain enumeration, found JWT tokens and employee chat in logs revealing algorithm confusion vulnerability, forged JWT using public RSA key as HMAC secret (CVE-2016-10555).

$ ls tags/ techniques/
jwt_algorithm_confusionelk_stack_enumerationsubdomain_discoveryhmac_with_public_key

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]