Lemmy.one
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Branquinho@lemmy.eco.br to cybersecurity@infosec.pubEnglish · 2 years ago

Lua-Resty-JWT Authentication Bypass

insinuator.net

external-link
message-square
0
fedilink
  • cross-posted to:
  • cybersecurity@sh.itjust.works
9
external-link

Lua-Resty-JWT Authentication Bypass

insinuator.net

Branquinho@lemmy.eco.br to cybersecurity@infosec.pubEnglish · 2 years ago
message-square
0
fedilink
  • cross-posted to:
  • cybersecurity@sh.itjust.works
I was writing some challenges for PacketWars at TROOPERS22. One was intended to be a JWT key confusion challenge where the public key from an RSA JWT should be recovered and used to sign a symmetric JWT. For that, I was searching for a library vulnerable to JWT key confusion by default and found lua-resty-jwt. The original repository by SkyLothar is not maintained and different from the librar ...
alert-triangle
You must log in or # to comment.

cybersecurity@infosec.pub

cybersecurity@infosec.pub

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !cybersecurity@infosec.pub

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Community Rules

  • Be kind
  • Limit promotional activities
  • Non-cybersecurity posts should be redirected to other communities within infosec.pub.

Enjoy!

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 10 users / day
  • 10 users / week
  • 10 users / month
  • 812 users / 6 months
  • 28 local subscribers
  • 4.13K subscribers
  • 781 Posts
  • 1.59K Comments
  • Modlog
  • mods:
  • shellsharks@infosec.pub
  • tweedge@infosec.pub
  • BE: 0.19.7
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org