Pentesting notes
search
⌘Ctrlk
Pentesting notes
  • 🏠/home/kabaneridev/.pt-notes
  • πŸ†Certification Preparation
    • βœ…CPTS - Completed
    • πŸ“˜CWEE Preparation
      • Injection Attacks
      • Attacking Authentication Mechanisms
        • JWT
          • Attacking Signature Verification
          • Attacking the Signing Secret
          • Algorithm Confusion
          • Further JWT Attacks
          • JWT Tools & Prevention
        • OAuth
        • SAML
      • Advanced XSS and CSRF Exploitation
      • Abusing HTTP Misconfigurations
      • HTTP Attacks
      • HTTPS/TLS Attacks
      • Blind SQL Injection
      • Whitebox Pentesting
      • Modern Web Exploitation
      • [Deserialization Attacks]
    • βœ…PJPT - Completed
  • πŸ”§Core Knowledge Areas
    • πŸ”Information Gathering
    • 🐧Linux Privilege Escalation
    • πŸͺŸWindows Privilege Escalation
    • πŸ› οΈTools & Utilities
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. πŸ†Certification Preparationchevron-right
  2. πŸ“˜CWEE Preparationchevron-right
  3. Attacking Authentication Mechanisms

JWT

Attacking Signature Verificationchevron-rightAttacking the Signing Secretchevron-rightAlgorithm Confusionchevron-rightFurther JWT Attackschevron-rightJWT Tools & Preventionchevron-right
PreviousAttacking Authentication Mechanismschevron-leftNextAttacking Signature Verificationchevron-right

Last updated 3 months ago