Cracking JSON Web Tokens

Поділитися
Вставка
  • Опубліковано 3 лют 2025

КОМЕНТАРІ • 96

  • @crusader_
    @crusader_ 2 роки тому +84

    Please Make an hour long video if need be. I'll watch it.

  • @IamFrancoisDillinger
    @IamFrancoisDillinger 2 роки тому +57

    Idc if a JWT video turned into an entire course, I'd buy it....and watch it. More JWT content!

  • @mfsbo
    @mfsbo Рік тому +1

    This is one of the best demo code I have seen with video explaining clearly. Keep doing more of these. ❤

  • @MirkoVukusic
    @MirkoVukusic Рік тому +6

    Very clear explanation. I'm all for deep dive too. Make it a series if needed.

  • @aaftabahmed6876
    @aaftabahmed6876 2 роки тому +3

    yes , I am excited to see more content on this ..... Like you said header injection and all . I 'll be waiting for next video.

  • @OriginalSchles
    @OriginalSchles 2 роки тому +6

    Yes please make a deep dive of JWT attacks!

  • @LimaOneNiner
    @LimaOneNiner 2 роки тому +7

    You're a great instructor. Keep it up

  • @xjamps
    @xjamps 2 роки тому +9

    JWT Deep dive please!! Thank you!

  • @SplitUnknown
    @SplitUnknown 2 роки тому +13

    Please make full deepdrive on jwt

  • @clarkflavor
    @clarkflavor 7 місяців тому +1

    Would absolutely freaking love a JWT deep dive 🤩

  • @tusharabbott
    @tusharabbott 2 роки тому +6

    Would love to see JWT Deep Dive

  • @cervece41
    @cervece41 2 роки тому +1

    I would definitely watch a jwt deep dive, looking forward to it!!

  • @nagrajcool
    @nagrajcool Рік тому

    Yes would love more content on JWT

  • @pabloreydaniel
    @pabloreydaniel 2 роки тому +2

    you are awesome!!. very clear and informative. deep dive into jwts!!. keep up!!.

  • @youcef2851
    @youcef2851 2 роки тому +7

    that was great and simple thank you

    • @youcef2851
      @youcef2851 2 роки тому

      @darkside_hackers.... you guys still exist ?

  • @JohnoScott
    @JohnoScott Рік тому

    This is an important topic to me. Would love another video that goes deeper.

  • @faisalalhoqani6151
    @faisalalhoqani6151 Рік тому

    It's a great demonstration we will be happy if you go deep into it. We have to know how to protect our work.

  • @69k_gold
    @69k_gold 9 днів тому

    I just wanna point out that at 3:48, you should have read the secret from an environment variable. I know it's security 101 and this is just for demo purposes, but some beginners might use this as their starter code to make their projects and they could end up hard coding the secret that way

  • @hashamkhan7951
    @hashamkhan7951 2 роки тому

    Yes, we love watching more videos

  • @a5tr00
    @a5tr00 Рік тому

    yes please!
    Btw, very comprehensive way of explaining things! 👍

  • @vinod.j7469
    @vinod.j7469 Рік тому

    Yes sir make a jwt deepdown I loved to watch, its very useful to me

  • @SonAyoD
    @SonAyoD Рік тому

    Super insightful! We need a deep dive!

  • @dimuthdeja7859
    @dimuthdeja7859 Рік тому

    Good explained it. Please make more videos. I am not miss it.

  • @SlowMowLife
    @SlowMowLife Рік тому

    Yes we would like to, thank you for the effort!

  • @e-francis
    @e-francis Рік тому

    Willing to watch a JWT deep dive

  • @Kinoti9
    @Kinoti9 Рік тому

    Great video, excellent explanation, I would definitely watch however long the video might be.

  • @ahmed_pinger
    @ahmed_pinger 2 роки тому +1

    Awesome Video ♥️♥️, please deep dive video

  • @angryman9333
    @angryman9333 Рік тому

    Wow idk it was the fact u were using JS or im already familiar with this kinda stuff, all i know i really enjoyed watching.

  • @RonalsonFilho
    @RonalsonFilho 2 роки тому +1

    JWT deep dive FTW!

  • @Enigma_0x1
    @Enigma_0x1 2 роки тому

    We are willing to watch it and have the patience, so please make it lol

  • @friedpizza262
    @friedpizza262 Рік тому

    Always using jwts but never taken the time to learn more about them. I'm all in for a deep dive!

  • @BHFJohnny
    @BHFJohnny Рік тому

    I am absolutely for a JWT deep dive 👍

  • @valghyna7668
    @valghyna7668 2 роки тому

    Nicely put together

  • @pentestingpurpose9571
    @pentestingpurpose9571 Рік тому

    Yes please, those videos are very usefull.

  • @nightninja8128
    @nightninja8128 2 роки тому +1

    3 hour video about JWTs sounds great. Also, what application were you using to test?

  • @oah8465
    @oah8465 Рік тому

    fantastic video, can you share the git-hub repo so we can tinker around with the code

  • @Dude29
    @Dude29 Рік тому

    Great video!

  • @OneIDtech
    @OneIDtech Рік тому

    Make a video on how best to secure jwt from these attacks.

  • @ca7986
    @ca7986 2 роки тому

    Amazing content! 🤟

  • @Dygear
    @Dygear Рік тому +1

    This is a great video! Do you have any experience using JWTs in place of cookies?

  • @karthiklingala5673
    @karthiklingala5673 2 роки тому

    Please make a video on algorithm confusion and header injection

  • @bonesseben5682
    @bonesseben5682 2 роки тому

    Please do!!!! So cool. I promise to watch ;-)

  • @2332Werter
    @2332Werter Рік тому

    please, make the complete vdeo.

  • @hazed69
    @hazed69 2 роки тому

    We would love to watch jwt deep dive

  • @chinmaydivekar8837
    @chinmaydivekar8837 2 роки тому

    Please make deep video on JWT security testing.

  • @tiagosutter8821
    @tiagosutter8821 Рік тому

    Great content, thank you

  • @Vlad1998996
    @Vlad1998996 2 роки тому

    go on. It's very useful

  • @BronkoBanane
    @BronkoBanane Рік тому

    Deep dive, deep dive, deep dive!
    Plz 🤪

  • @learnwithabdulbari
    @learnwithabdulbari Рік тому

    YEs i want to watch it

  • @briantoo4390
    @briantoo4390 Рік тому

    Nice Video

  • @ogunsanmimichael
    @ogunsanmimichael Рік тому

    Quick question, if I get access to someone else's token and use this token to make requests to a server, will the server recognise that I am not the original owner of the token?

  • @TheGameCrafter
    @TheGameCrafter Рік тому

    I'd watch it

  • @rakhisingh9797
    @rakhisingh9797 Рік тому

    bro pls tell what can do to secure jwt token?

  • @ibrahimmuhammad4194
    @ibrahimmuhammad4194 2 роки тому

    Thank you!

  • @ASecurityPro
    @ASecurityPro 2 роки тому

    More JTW please

  • @whiteshadow7810
    @whiteshadow7810 Рік тому

    Thanks dude , but i'm as a developer , we create secret key from hash 32bite so t think is to hard to crack JWT

  • @OMER3-1-3
    @OMER3-1-3 2 роки тому

    More JWT content!

  • @VishalPatelblogjocker
    @VishalPatelblogjocker Рік тому

    What is solution to prevent brute force?

  • @OpeLeke
    @OpeLeke Рік тому

    great tutorial

  • @angryman9333
    @angryman9333 Рік тому

    Please Deep Dive JWT

  • @piptutor
    @piptutor 2 роки тому

    JWT deep dive please

  • @PAIN_HANDLE
    @PAIN_HANDLE 2 роки тому +1

    Can you make a video on Linux server administrator

  • @souvickdas5564
    @souvickdas5564 2 роки тому

    In algorithm part we can exploit by specifying "no algorithm"

    • @st8113
      @st8113 Рік тому

      The widely used jwt libraries force you to specify an algorithm for verification.

  • @b.i_khalil
    @b.i_khalil Рік тому

    JWT DEEP DIVE PLEASE❤

  • @ukaszgeras6600
    @ukaszgeras6600 2 роки тому

    more jwt. please

  • @sergeantosiris
    @sergeantosiris 2 роки тому

    Awesome

  • @enperuprithvi
    @enperuprithvi 4 місяці тому

    jwt tool link?

  • @gosnooky
    @gosnooky Рік тому

    I feel better now that my application uses a 64-character alphanumeric string

  • @stephenarthur1119
    @stephenarthur1119 2 роки тому

    5:02 *request :)

  • @rosehacksyoutube
    @rosehacksyoutube 2 роки тому

    More JWT

  • @rodolfocabralneves8279
    @rodolfocabralneves8279 Рік тому

    How about I use JWT in a HTTPS connection ?

    • @d3line
      @d3line Рік тому

      Https protects against random computers intercepting the traffic, but does nothing to protect your cookies/jwt/whatever else from user manipulation

  • @jayeshtharani
    @jayeshtharani 2 роки тому

    How to prevent JWT from decoding?

    • @st8113
      @st8113 Рік тому

      JWTs are meant to be decoded.
      You CAN encrypt an entire JWT, but this isn't super common.

    • @jayeshtharani
      @jayeshtharani Рік тому

      @@st8113 thanks.

  • @mikehill3426
    @mikehill3426 Рік тому

    Vocal fry is a thing.

  • @SplitUnknown
    @SplitUnknown 2 роки тому

    ♥️

  • @yaswanthkumar409
    @yaswanthkumar409 2 роки тому

    JWT deep dive

  • @privilegedesign8745
    @privilegedesign8745 2 роки тому

    Make long video jwt

  • @ChristianScott-wj6qm
    @ChristianScott-wj6qm Місяць тому

    Use me as a ” deep dive , deep dive !” Button

  • @gihanrangana6248
    @gihanrangana6248 2 роки тому

    what if we encrypt the jwt token with crypto
    ex: const token = crypto.AES.encrypt(jwt.sign({...payload},'secret'),'enc-secret')
    const decode = crypto.AES.decrypt(token,'enc-secret')
    just an idea

    • @gihanrangana6248
      @gihanrangana6248 2 роки тому

      or we can encrypt the payload and put it inside the token

    • @d3line
      @d3line Рік тому

      @@gihanrangana6248 well, you get an encrypted and signed thing. What for? The issue is not "not enough encryption", the issue is weak secrets. And generally bad design of JWT and JWT libraries, but that's regarding other attacks.
      I really dislike JWTs, way too large of an attack surface, and a huge issue with revoking access once a token is granted, but too much hype.

  • @COLMANRYAN62
    @COLMANRYAN62 11 місяців тому

    Great Video!

  • @abhishekmorla1
    @abhishekmorla1 2 роки тому

    JWT deep dive please