We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 884003a commit 01eb8d8Copy full SHA for 01eb8d8
intro_hacking/5-api/walkthrough/jwt_hacking.md
@@ -2,3 +2,11 @@
2
- This is your first hacking lab, you didn't learn how to crack passwords and secrets, the jwt secret is: random
3
- After you get the secret construct the admin JWT. you can use the python script: jwt/prepare_jwt.py
4
- Use Postman / Burp / Swagger to log in as admin
5
+
6
+### How I hacked the JWT secret
7
+- Download dictionary: https://github.com/wallarm/jwt-secrets/blob/master/jwt.secrets.list
8
+- Ran hashcat
9
10
+```
11
+hashcat -m 16500 eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJleHAiOjE3NjM0NzQ4NzYsImlhdCI6MTc2MzQ3NDgxNiwic3ViIjoic3VwZXJnaXJsIn0.ExfWvqQK85Ufnt6f22Q0FvdmcZjIggFTtIpo2AlXKVg ../../../../../../Downloads/jwt.secrets.list
12
0 commit comments