Hack JWT using JSON Web Tokens Attacker BurpSuite extensions

Поділитися
Вставка
  • Опубліковано 4 лют 2025

КОМЕНТАРІ • 50

  • @ajaykumark107
    @ajaykumark107 4 роки тому +9

    Idea for next video: Burp bounty Extension. All videos currently on youtube have no voice over. Please cover this extension in depth as you did for JWT tokens. Great job again!

  • @sundar3357
    @sundar3357 4 роки тому +6

    You are explaining everything well. Thanks man.

  • @uliun2344
    @uliun2344 4 роки тому

    Suite is pronounced as "sweet".
    Thanks for the great content.

  • @cricketworld4165
    @cricketworld4165 7 місяців тому

    in this process we find upcoming period or number sir!!

  • @whatiknowtech
    @whatiknowtech 4 роки тому +1

    Quick one sir , how do I craft a new timestamp in the JWT payload. Gained a new Subscriber , thank you very much kindly do in depth tutorials on burp extensions .

  • @0x0313-p
    @0x0313-p 4 роки тому +1

    Can u upload all the vulnerability related JWT and garphQL

  • @ajaykumark107
    @ajaykumark107 4 роки тому +1

    Please create more content!!

  • @theotimeforestier7647
    @theotimeforestier7647 3 роки тому

    Very well explained

  • @ashpakpinjari9214
    @ashpakpinjari9214 4 роки тому +2

    Bro make video on burpbounty,burp collaborator everywhere and X-Forwarded-For extension. Awaiting for your video.

  • @muddassirkhan5953
    @muddassirkhan5953 4 роки тому +1

    is all the token is base64 encode or it depends on the application?

    • @thehackerish
      @thehackerish  4 роки тому +1

      You will always find the same structure. It doesn't depend on the application, it is a standard.

  • @housewiring1136
    @housewiring1136 4 місяці тому

    Nice 👍

  • @Nirusvlogs
    @Nirusvlogs 3 роки тому

    Nice. So what the secure way to implement JWT token.

    • @thehackerish
      @thehackerish  3 роки тому

      Validate the signature. Use strong keys for HSxxx, prefer RSA, etc

    • @Nirusvlogs
      @Nirusvlogs 3 роки тому

      @@thehackerish Thank you so much! But while hacking your removing the signature if use RSA also still you can hack using xss or csfr attacks right. I am having this issuein my website. I want your advise😀

    • @thehackerish
      @thehackerish  3 роки тому

      @@Nirusvlogs JWT will protect against CSRF if not put in a cookie. However, XSS would exfiltrate the JWT. In this case, you can implement proof-of-possession tools.ietf.org/html/rfc7800.

  • @JuanBotes
    @JuanBotes 3 роки тому

    thanks

  • @hackerproxy19
    @hackerproxy19 4 роки тому

    one video cover the all (burp suite extensions), can you

    • @thehackerish
      @thehackerish  4 роки тому

      That would result in a very loooong video which I cannot make unfortunately.

  • @anik6393
    @anik6393 4 роки тому

    You are the best one😘.

  • @capleprajapati5575
    @capleprajapati5575 4 роки тому

    1) For the highlighted request with comment as "Contains a JWT", it shows token in Response and not in the Request. Why the request is not having JWT? Also the request which has token is not highlighted with Contains a JWT.
    2) The JWT token comes after we login with correct UserID and Password. It does not show before we login into the page. Is this correct? Is this how it is supposed to be?

    • @thehackerish
      @thehackerish  4 роки тому

      1- The extension detects whenever there is a JWT token either in the request or the response.
      2- Yes, JWT tokens are usually used after authentication, in this case using a username and a password

  • @nihagurung8980
    @nihagurung8980 3 роки тому

    My laptop says “AuthSdkError: The JWT was issued in the future”..
    Can you please help me?

    • @thehackerish
      @thehackerish  3 роки тому

      set the iat field of the JWT to a correct timestamp I guess.

  • @zer0six472
    @zer0six472 2 роки тому

    I know am a little late but great video thank you very much well explained 🙏🤘

  • @pooloverflow
    @pooloverflow 3 роки тому

    nice content

  • @cyberpirate007
    @cyberpirate007 4 роки тому

    Bro make a video on WAF bypass extension plzzz

  • @laggybot1327
    @laggybot1327 3 роки тому

    very nice

  • @Stas1983ful
    @Stas1983ful 2 роки тому

    Sorry, How add in burp in request JSON WEB TOKENS?

  • @crazyfun782
    @crazyfun782 4 роки тому +1

    Take ❤️❤️❤️❤️

  • @ca7986
    @ca7986 4 роки тому

    ♥️

  • @gowanotv4050
    @gowanotv4050 2 роки тому

    Bad token; invalid alg

  • @neeleshneelesh7964
    @neeleshneelesh7964 3 роки тому

    Hi can you hack carrom pool gems and coins please