JWT Token
Last updated
Last updated
Java JDKs 15 to 18 allowing to bypass signature checks
HS256
Small list
Big list
-I
: injection mode
-pc field
: Field (in the payload) to modify
-pv new_value
: Sets the new value of the field
-S
: Signature algorithm
https://www.youtube.com/watch?v=78FIFrOi4Os
SignSaboteur - Burp Extension
-t
: target
-rh
: Headers
-pd
: Payload Data (in this example IP adresses)
-M pb
: Playbook scan
-np
: no pause
-M at: All Tests