Pentesting notes
Ctrlk
  • 🏠/home/kabaneridev/.pt-notes
  • πŸ†Certification Preparation
    • βœ…CPTS - Completed
    • πŸ“˜CWEE Preparation
      • Injection Attacks
      • Attacking Authentication Mechanisms
        • JWT
          • Attacking Signature Verification
          • Attacking the Signing Secret
          • Algorithm Confusion
          • Further JWT Attacks
          • JWT Tools & Prevention
        • OAuth
        • SAML
      • Advanced XSS and CSRF Exploitation
      • Abusing HTTP Misconfigurations
      • HTTP Attacks
      • HTTPS/TLS Attacks
      • Blind SQL Injection
      • Whitebox Pentesting
      • Modern Web Exploitation
      • [Deserialization Attacks]
    • βœ…PJPT - Completed
  • πŸ”§Core Knowledge Areas
    • πŸ”Information Gathering
    • 🐧Linux Privilege Escalation
    • πŸͺŸWindows Privilege Escalation
    • πŸ› οΈTools & Utilities
Powered by GitBook
On this page
  1. πŸ†Certification Preparation
  2. πŸ“˜CWEE Preparation
  3. Attacking Authentication Mechanisms

JWT

Attacking Signature VerificationAttacking the Signing SecretAlgorithm ConfusionFurther JWT AttacksJWT Tools & Prevention
PreviousAttacking Authentication MechanismsNextAttacking Signature Verification

Last updated 2 months ago