The XSS Rat
CWAP · Module 09 — JWT & Authentication

Attack 1 — alg:none unsigned bypass

Animated, step-by-step: how a server that reads its algorithm from the token hands you an admin session.
Module 09JWTAuth bypassCritical

◤ Attacker workstation

🐀
you
idle

◤ On the wire

◤ Server

key material
waiting
attacker
server
hunter@cwap — bash
0:00 / 0:00 step 1 / 1