Skip to content

Commit 01eb8d8

Browse files
Update jwt_hacking.md
1 parent 884003a commit 01eb8d8

File tree

1 file changed

+8
-0
lines changed

1 file changed

+8
-0
lines changed

intro_hacking/5-api/walkthrough/jwt_hacking.md

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,3 +2,11 @@
22
- This is your first hacking lab, you didn't learn how to crack passwords and secrets, the jwt secret is: random
33
- After you get the secret construct the admin JWT. you can use the python script: jwt/prepare_jwt.py
44
- Use Postman / Burp / Swagger to log in as admin
5+
6+
### How I hacked the JWT secret
7+
- Download dictionary: https://github.com/wallarm/jwt-secrets/blob/master/jwt.secrets.list
8+
- Ran hashcat
9+
10+
```
11+
hashcat -m 16500 eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJleHAiOjE3NjM0NzQ4NzYsImlhdCI6MTc2MzQ3NDgxNiwic3ViIjoic3VwZXJnaXJsIn0.ExfWvqQK85Ufnt6f22Q0FvdmcZjIggFTtIpo2AlXKVg ../../../../../../Downloads/jwt.secrets.list
12+
```

0 commit comments

Comments
 (0)