Abusing JWT (JSON Web Tokens) - Sven Morgenroth - PSW #673

Published: Nov. 7, 2020, 10 a.m.

b'

Learn how JWTs are implemented, both the correct way and the insecure way. Spoiler alert, most implement them insecurely. Sven will also show you some of the common attacks against JWTs, for use in your next penetration test, bug bounty, or conversation with your developers!

\\xa0

This segment is sponsored by Netsparker. Visit https://securityweekly.com/netsparker to learn more about them!

\\xa0

Visit https://www.securityweekly.com/psw for all the latest episodes!

Show Notes: https://wiki.securityweekly.com/psw673

'