03Modules
JWT and Encryption Key Cracking
Easy30MIN
Weak secret
The security of JWT relies entirely on the attacker not guessing the secret or encryption key used in its signature.
This we can test with various tools such as hashcat or JTR (john the ripper) which are designed to attempt to guess the secret of the JWT at a staggering speed.
1 / 6
Hakatemia Pro
Learn to hack — start here
Hundreds of interactive courses, virtual labs and CTF challenges in your browser. Start a free trial — no card required.