Back to writeups
Oct 25, 2025
2 min read
...

JWT Security

Vulnerabilidades comunes en JSON Web Tokens: algoritmos débiles, firmas sin validar y cómo mitigarlas.

Web Application Pentesting > Authentication > JWT Security

Diamond Model

Task 1

Introduction

  1. I am ready to learn about JWTs!
No answer needed

Task 2

Token-Based Authentication

  1. What is the common header used to transport the JWT in a request?
Authorization: Bearer

Task 3

JSON Web Tokens

  1. HS256 is an example of what type of signing algorithm?
Symmetric
  1. RS256 is an example of what type of signing algorithm?
Asymmetric
  1. What is the name used for encrypted JWTs?
JWE

Task 4

Sensitive Information Disclosure

  1. What is the flag for example 1?
THM{9cc039cc-d85f-45d1-ac3b-818c8383a560}

Task 5

Signature Validation Mistakes

  1. What is the flag for example 2?
THM{6e32dca9-0d10-4156-a2d9-5e5c7000648a}
  1. What is the flag for example 3?
THM{fb9341e4-5823-475f-ae50-4f9a1a4489ba}
  1. What is the flag for example 4?
THM{e1679fef-df56-41cc-85e9-af1e0e12981b}
  1. What is the flag for example 5?
THM{f592dfe2-ec65-4514-a135-70ba358f22c4}

Task 6

JWT Lifetimes

  1. What is the flag for example 6?
THM{a450ae48-7226-4633-a63d-38a625368669}

Task 7

Cross-Service Relay Attacks

  1. What is the flag for example 7?
THM{f0d34fe1-2ba1-44d4-bae7-99bd555a4128}

Task 8

Conclusion

  1. I understand how to exploit weak JWT implementations and how to secure them!
No answer needed

¿Te resultó útil este contenido?

Compártelo con otros desarrolladores que puedan encontrarlo interesante

Newsletter

Un proyecto pequeño, construido y explicado

Cada dos semanas: algo que construí, por qué lo decidí así y los números reales. Sin relleno, y te puedes dar de baja cuando quieras.

Si prefieres no dejar tu correo, también publico todo por RSS.

Comentarios