Challenges → Web Exploitation

JWT None Algorithm

Hard 250 pts 🚩 0 solves ⏱ Avg. time to solve: —

Challenge Question

This verification service trusts a signed token to say who you are, and it takes the token's own claim about which signing algorithm was used at face value. Not every algorithm actually requires a signature to be trusted. Forge a token that verifies as someone you're not.
Access Challenge →

Submit Flag

Log in or sign up to submit a flag.

Details

Recent Solvers

No one has solved this yet. Be the first!

Discuss in the forum →