HAKATEMIA
03Modules

JWT and Encryption Key Cracking

Easy30MIN

Weak secret

The security of JWT relies entirely on the attacker not guessing the secret or encryption key used in its signature.

This we can test with various tools such as hashcat or JTR (john the ripper) which are designed to attempt to guess the secret of the JWT at a staggering speed.

1 / 6
Hakatemia Pro

Learn to hack — start here

Hundreds of interactive courses, virtual labs and CTF challenges in your browser. Start a free trial — no card required.