JWT / token authentication attacks
SkillSecurityAttack JWT/session authentication. Load when auth uses a JWT (three base64url parts, header.payload.signature), Authorization: Bearer, or you see alg/kid/jku fields. Signals: eyJ... tokens, "alg":"none"/"HS256"/"RS256", kid header, JWKS endpoints, role/admin claims.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the JWT / token authentication attacks skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/web/web-auth-jwt/SKILL.md and read by ahel’s review.
When it applies
The app authenticates with a JSON Web Token and trusts claims inside it (user id, role,
isAdmin). The win is forging a valid-looking token the server accepts.
Why it works
JWTs are only as safe as their signature verification. Implementations routinely skip it,
confuse algorithms, or trust attacker-controlled key hints (kid, jku, x5u). If you can
make the server accept a signature you produced, you own every claim.
Method
Payloads & full variation set:
cheatsheet.mdnext to this file — work the set, not the first line.
- Decode & read claims:
jwt_tool <token>— look forrole,admin,sub, weakexp. - alg=none: strip the signature and set header
{"alg":"none"}; some libs accept it. - Algorithm confusion RS256→HS256: if the server verifies RS256 with the public key,
re-sign HS256 using that public key as the HMAC secret — server verifies with the same key.
jwt_tool -X k -pk public.pem. - Weak HMAC secret: crack HS256 offline —
hashcat -m 16500 token.txt rockyou.txt; if it falls, mint any token. - kid / jku / x5u abuse:
kidpath traversal or SQLi to control the key file;jku/x5upointing at your JWKS so the server fetches your public key and you sign with your private key.
Gotchas
- Editing claims without re-signing fails unless verification is broken — confirm the vuln class first.
exp/nbfmay be enforced even when signature isn't — keep timestamps valid.- Public key sourcing: grab it from
/.well-known/jwks.json, a cert, or TLS if not published.
Verify success
Server accepts a token you forged with elevated claims (e.g. admin panel loads, or an
authenticated endpoint returns another user's data with your minted sub).
References
PortSwigger JWT labs; jwt_tool wiki; Auth0 "Critical vulnerabilities in JWT libraries".
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
web-auth-jwt- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · mukul975
The pick for Vulnerabilitiescode-quality-analyzer
Skill · alibaba
The pick for Vulnerabilitiesowasp-security
Skill · davila7
The pick for Web (OWASP)owasp-web
Skill · nahid-sparktales
The pick for Web (OWASP)gws-shared
Skill · googleworkspace
More in Securitybrandkit
Skill · leonxlnx
More in Security