Offensive jwt
/SKILLJWT attack methodology for penetration testers. Covers algorithm confusion (alg:none, RS256→HS256), weak HMAC secret brute force, kid parameter injection (SQLi, path traversal), jku/x5u/jwk header inj
--- name: offensive-jwt description: "JWT attack methodology for penetration testers. Covers algorithm confusion (alg:none, RS256→HS256), brute-force attacks on weak HMAC secrets, kid parameter injection (SQLi, path traversal), jku/x5u/jwk header injection, JWKS cache poisoning, JWS/JWE confusion, timing attacks, and mobile JWT storage extraction. Use when testing JWT-based authentication, hunting for auth bypass via token manipulation, or evaluating JWT implementation security in web or mobile apps." --- ## Overview Comprehensive JWT attack checklist for offensive security engagements. Follow the steps in order; apply each technique to the current target context and track which items have been completed. ## Quick Reference: Misconfigurations to Check - Algorithm set to none : signature verification bypassed entirely - Algorithm switching between RSA and HMAC (confusion attack) - Weak or guessable HMAC secret (vulnerable to brute-force attacks) - kid, jku, jwk, x5u header parameters accepted without validation - Expired or tampered tokens accepted by the server - Sensitive data stored unencrypted in the payload Useful tool: [JWT Tool](https://github.com/ticarpi/jwt_tool) ## Mechanisms JWTs (RFC 7519) consist of three Base64URL-encoded parts: header.payload.signature. Signing algorithms: | Algorithm | Type | Notes | |-----------|------|-------| | HS256/384/512 | Symmetric HMAC | Shared secret; confusion target | | RS256/384/512 | Asymmetric RSA | Public key can be misused as HMAC secret | | ES256/384/512 | Asymmetric ECDSA | | | PS256/384/512 | RSASSA-PSS | | | EdDSA (Ed25519/Ed448) | Asymmetric | | | none | Unsigned | Critically insecure | Additional pitfalls: - JWS/JWE confusion: the server accepts an encrypted token (JWE) when a signed token (JWS) is expected, or fails open upon encountering an unexpected typ / cty - JWKS retrieval: SSRF via jku / x5u, insecure TLS, poisoned key caching, kid collisions - Token binding (DPoP, mTLS): if implemented incorrectly, allows replay attacks from other clients ## Hunt: Identifying JWT Usage 1. Check Authorization: Bearer <token> headers in all requests 2. Look for cookies containing JWT structures (eyJ...) 3. Examine browser local/session storage 4. Decode the token at jwt.io or via the BurpSuite JWT extension : inspect claims and header parameters 5. Note any kid, jku, jwk, x5u fields in the header : these are attack surfaces ## Vulnerability Map `` JWT Vulnerabilities ├── Algorithm Bypass │ ├── alg:none attack │ └── RS256→HS256 confusion (public key as HMAC secret) ├── Weak Secret Key → Brute force ├── kid Parameter Injection │ ├── SQL injection via kid │ └── Path traversal via kid ├── Header Injection │ ├── jwk (inline fake key) │ ├── jku/x5u (remote attacker-controlled JWKS) │ └── JWKS cache poisoning └── Missing / Broken Validation ├── No signature check ├── Expired tokens accepted └── iss/aud/exp not validated ` ## Vulnerabilities ### Algorithm Vulnerabilities - **alg:none** : Some libraries disable signature validation when alg is none or a case variant ( None , NONE , nOnE) - **Algorithm Confusion (RS256→HS256)** : Server uses RSA public key as HMAC secret when attacker switches alg to HS256; attacker re-signs token with the public key - **Key ID ( kid ) Manipulation** : Exploiting kid to load wrong keys or inject file paths / SQL; enforce strict lookups ### Signature Vulnerabilities - **Weak HMAC Secrets** : Brute-forceable with dictionary or hashcat - **Missing Signature Validation** : Token accepted without any verification - **Broken Validation** : Implementation errors in signature checking logic ### Implementation Issues - **Missing Claims Validation** : exp , nbf , aud , iss not verified - **Insufficient Entropy** : Predictable JWT IDs or tokens - **No Expiration** : Tokens valid indefinitely - **Insecure Transport** : Token sent over HTTP - **Debug Leakage** : Detailed error messages expose implementation ### Header Injection Attacks - **JWK Injection** : Supply a custom attacker-controlled public key via the jwk header - **JKU Manipulation** : Point jku` (JWK Set URL) to an attacker-controlled JWKS endpoint - x5u Misuse : Load untrusted X.509 ke