null Global Committee elections are coming up! See the election repository for more information.

Abstract

Breaking the token: JWT Attacks

This session will cover fundamental concepts of JWT (JSON Web Tokens), common vulnerabilities, and attacks that exploit weaknesses in token signing and verification mechanisms. Here's what you'll learn:

1. Introduction to JWT

2. Attacks on JWT

- Asymmetric Key Attacks (RSA)
- Symmetric Key Attacks (HMAC)

3. Billion Hash Attack

4. Hands-On Challenge

Speaker

Karm Rajput

Timing

Starts at Saturday October 19 2024, 11:30 AM. The sessions runs for about 1 hour.

Resources