ATTACKING JWT FOR BEGINNERS!

แชร์
ฝัง
  • เผยแพร่เมื่อ 27 ก.ย. 2024
  • I'm a bug bounty hunter who's learning everyday and sharing useful resources as I move along. Subscribe to my channel because I'll be sharing my knowledge in new videos regularly.
    BUY ME A COFFEE:
    www.buymeacoff...
    SOCIAL MEDIA:
    Connect with me on LinkedIn: / farah-hawa-a012b8162
    Follow me on Twitter: / farah_hawa01
    Follow me on Instagram: / farah_hawa01
    Links for resources mentioned:
    LAB CLONED FROM:
    github.com/h-a...
    CODE USED TO GENERATE SIGNATURE:
    github.com/far...
    BURP EXTENSION:
    portswigger.ne...
    BRUTE FORCING TOOLS:
    jwtbrute: github.com/jma...
    JWT cracker: github.com/bre...
    BLOGS ABOUT JWT:
    www.sjoerdlang...
    If you have a PentesterLab subscription:
    pentesterlab.c...
    Video editor: Sahil Juneja

ความคิดเห็น • 207

  • @FarahHawa
    @FarahHawa  4 ปีที่แล้ว +38

    The burp extension, code to change the signature and the lab which was used are all linked in the description!

    • @kunalraut1689
      @kunalraut1689 3 ปีที่แล้ว

      But what if the server doesn't accepts the request made to it having the Symmetric Algorithm(parameter) or doesn't accept any altered requests and just neglects it. Then its of no use for us to alter the 'alg' to something else and we have to deal with it the way it excepts(Asymmetric Algorithm)?
      And btw well explained! Thank You.

  • @MattiaCampagnano
    @MattiaCampagnano 4 ปีที่แล้ว +6

    As a pentester, I tell you you girl rock. Well done, keep up the good work!

  • @whitehat3937
    @whitehat3937 4 ปีที่แล้ว +4

    Hy please don't stop making videos. You are doing great job. I want indian women also be a part of this community 🙂

  • @manikgoenka8720
    @manikgoenka8720 4 ปีที่แล้ว

    Just randomly crashed into this channel yesterday and now I am a subscriber........you are doing a great job Farah.......looking forward to explore this field.

  • @jatindersingh7047
    @jatindersingh7047 7 หลายเดือนก่อน

    Just wanted to drop some appreciation your way! Your content has been an absolute lifesaver for beginners diving into the world of cybersecurity. I would love to see more videos on web vulnerabilities and diving deeper into those crucial interview questions which are not very common, but frequently asked in the interview. Keep up the fantastic work!" :)

  • @afifmalghani755
    @afifmalghani755 4 ปีที่แล้ว +27

    Once again, the best beginner friendly content out there. Keep it up.

  • @thecoder7984
    @thecoder7984 3 ปีที่แล้ว

    Farah your are an role model and example of millions of Indian women.👍👍👍

  • @jashan8636
    @jashan8636 4 ปีที่แล้ว +1

    You're the best. I'm beginner in cybersecurity and I was wondering if anyone could help me where to start. Your videos gave me some direction. carry on👍👍👍

  • @adryelgainza1686
    @adryelgainza1686 2 ปีที่แล้ว

    Awesome! Lots of videos showed how to do it but they did not explain the vulnerability like you. Thank you!

  • @corporatemurrell
    @corporatemurrell 4 ปีที่แล้ว +1

    What an amazing video! Great music and sound effects, superb graphics and editing, fresh technical content in a bite sized package, and such a pleasant voice. You're setting the bar really high, and I hope you continue you to do so! Good job!

  • @tirtheshpawar1020
    @tirtheshpawar1020 4 ปีที่แล้ว

    One humble request, please try and make a full playlist covering bug bounty hunting concepts with attacks, it can be a series of videos maybe 1-2 videos per week.You pitch your content really well. God bless you!

  • @haksting
    @haksting 4 ปีที่แล้ว +1

    10/10
    Awesome quality of video
    Very informative
    Nic editing
    👍

  • @Abiishek
    @Abiishek 4 ปีที่แล้ว +2

    Welcome Back 🙌
    Stay positive!!

  • @Unhacker
    @Unhacker 2 ปีที่แล้ว

    Good stuff, one of the better JWT hacker vids. Another interesting angle to explore is JWTs as an injection/RCE vector, completely outside the context of bypassing authentication. Good times.

  • @yajusgakhar6969
    @yajusgakhar6969 2 ปีที่แล้ว

    Thanks to you I could complete a challenge that had been bothering me. Cheers!

  • @AryanPant2004
    @AryanPant2004 9 หลายเดือนก่อน

    Thank you thank you thank you mam , please keep on teaching

  • @amishmane
    @amishmane 4 ปีที่แล้ว

    Thanks Farah. Just a suggestion that a zoomed coding screen would really be helpful.

  • @urrahman196
    @urrahman196 4 ปีที่แล้ว

    Great tutorial I must say. Could you Please make a guideline type or learning path type video to Start in Cybersecurity field. What are the topics and which resources should follow as a beginner? Thanks

  • @fenilfaldu8740
    @fenilfaldu8740 3 ปีที่แล้ว +1

    I love your content, but can you make a video on nftoken

  • @apnimashoori2762
    @apnimashoori2762 4 ปีที่แล้ว +1

    how to find the hs256 key ?

  • @fypage.
    @fypage. 4 ปีที่แล้ว

    Your way more interesting than most teachers probably because you so young I would expect you to know much so that's good

  • @ilyasayusuf5447
    @ilyasayusuf5447 3 ปีที่แล้ว

    Is the header really important ?
    I mean why would they show the attacker the alg they are using.
    Maybe make the signature unpredictable like this?
    hs256(bs64url(fakeheader)+secretkey+bs64url(body)+bs64url(secretkey),secretkey);
    am i doing it better or it is bad practice?

  • @darshanjogi5781
    @darshanjogi5781 4 ปีที่แล้ว

    Useful video please make full playlist on how to use burpsuit.i think You explain it better than others

  • @roshanrajkumar7827
    @roshanrajkumar7827 3 ปีที่แล้ว

    Amazing...but it’s too fast..I got few doubts ...how can I contact?

  • @ElektroDrrrEL
    @ElektroDrrrEL 4 ปีที่แล้ว

    content is super high quality - thank you, Farah!

  • @pastryelite1440
    @pastryelite1440 4 ปีที่แล้ว

    Nice video with Great Explanation... looking forward to watch more videos....🥳

  • @theprateekmahajan
    @theprateekmahajan 4 ปีที่แล้ว

    Hey farah,
    Great of you. Would you make a video on your journey till today for the very begginers who wants to Kickstart their career.

  • @ZaidKhan-nk7xr
    @ZaidKhan-nk7xr 4 ปีที่แล้ว

    Please make a tutorial on Burp Suite

  • @kamar1380
    @kamar1380 4 ปีที่แล้ว +1

    Again Thank for this awesome video...👍
    Pls don't stop making such a awesome video..

  • @raanonyms7926
    @raanonyms7926 4 ปีที่แล้ว

    wow, you are doing awesome. please keep on posting such walkthrough.

  • @jissjose1382
    @jissjose1382 4 ปีที่แล้ว

    The best video 👌 out there.Looking forward for more attacks and contents from you..

  • @MehediHasan-rc1lo
    @MehediHasan-rc1lo 3 ปีที่แล้ว

    No such file or directory: 'public.pem' error generate from your script. How can I solve this error?

  • @techrims3908
    @techrims3908 4 ปีที่แล้ว +1

    Really Great Information Farah Didi | Thank You So Much | 💝🙏💌

  • @asnyeamin5766
    @asnyeamin5766 4 ปีที่แล้ว +1

    This video is really beginner friendly...❤
    Already feels like i become a hacker..haha
    Bt Can you please add subtitle in your videos??? That will be really helpfu..
    And thanks a lot..

  • @gilbertolopez5894
    @gilbertolopez5894 4 ปีที่แล้ว

    Thanks for dedicating content for beginners !! You are my hero, I want to be just like you when I grow up :)

  • @rohitblaze9015
    @rohitblaze9015 4 ปีที่แล้ว

    Your video is really good for beginner but can you go a little slow and a bit more description? Then it would be perfect.

  • @viveksdf
    @viveksdf 4 ปีที่แล้ว

    Hello Farah, Great video I would love to watch more this kind of content and a video how you started in this field a journey video would be great

  • @sharathputta1703
    @sharathputta1703 4 ปีที่แล้ว

    Please continue to post new things you are learning. I could see interesting stuff in your channel. please keep on post new things

  • @LexiLominite
    @LexiLominite 2 ปีที่แล้ว

    May i know what video editor do you use ?

  • @SahilKumar-ww7xn
    @SahilKumar-ww7xn 4 ปีที่แล้ว

    All right but can you tell me how to change the token manually plz becoZ we don't have option which you used in your burp suite.Thank u

    • @FarahHawa
      @FarahHawa  4 ปีที่แล้ว

      You can download the extension. I have mentioned the link for it in the description.

    • @SahilKumar-ww7xn
      @SahilKumar-ww7xn 4 ปีที่แล้ว

      @@FarahHawa but how we add it on burp suite in kali Linux.

    • @FarahHawa
      @FarahHawa  4 ปีที่แล้ว

      @@SahilKumar-ww7xn Use the Extender tab

    • @SahilKumar-ww7xn
      @SahilKumar-ww7xn 4 ปีที่แล้ว

      @@FarahHawa Thanks a lot. Waiting for next vedio 😍🤟

  • @suchomir4493
    @suchomir4493 2 ปีที่แล้ว

    Hello, you are amainzing, I do ctf 153+1 with you!!! Many greetings from Poland!

  • @hassan12141
    @hassan12141 4 ปีที่แล้ว

    Great content but
    Why u don't upload videos regularly

  • @vijaySingle143
    @vijaySingle143 3 ปีที่แล้ว

    Huge respect Farah , thank you .

    • @FarahHawa
      @FarahHawa  3 ปีที่แล้ว

      you're welcome 😇

  • @bharathpatel1757
    @bharathpatel1757 4 ปีที่แล้ว

    Thanks for this . And really it's helping me alot as a beginner .

  • @tahan1tonmoy
    @tahan1tonmoy 4 ปีที่แล้ว

    Very basic attacks but nicely explained 👍

  • @parthibanakt7090
    @parthibanakt7090 2 ปีที่แล้ว

    Great and simple..!

  • @URKCS-hj9xe
    @URKCS-hj9xe 3 ปีที่แล้ว

    Hi, Please tell me how to get "/tmp/public.pem" which you mentioned in 5:00 min.

    • @crocheteur3290
      @crocheteur3290 3 ปีที่แล้ว +1

      4:29 - She copied the text to save it in a file named public.pem

  • @alexmridul2403
    @alexmridul2403 3 ปีที่แล้ว

    It's great
    Really OP
    I love the way you teach

  • @MdSajid-fb9ul
    @MdSajid-fb9ul 4 ปีที่แล้ว

    Explained very well. Hats off

  • @dhruvkandpal9909
    @dhruvkandpal9909 4 ปีที่แล้ว

    Great job! Really learning a lot out here. Keep up the good work! Happy hacking!

  • @alialmasslmany5240
    @alialmasslmany5240 4 ปีที่แล้ว

    thank you so much farah

  • @slbpriank91
    @slbpriank91 4 ปีที่แล้ว

    You are legend! Hopefully one day i can be good and work together with you

  • @ImranShaikh-kt7ey
    @ImranShaikh-kt7ey 4 ปีที่แล้ว +11

    Turn off your face camera while performing demonstration Does not appear clear

    • @shreyanshdesai3152
      @shreyanshdesai3152 4 ปีที่แล้ว

      or she can get camera angle changed if she want to show face (don't put cam behind laptop)

  • @mr_ehmed
    @mr_ehmed 4 ปีที่แล้ว

    i am not able to modify tokken through JSON Web Tokens extension :/

  • @baravind719
    @baravind719 3 ปีที่แล้ว

    What if we have HS256?

  • @anuragbhoir8516
    @anuragbhoir8516 4 ปีที่แล้ว

    Well this is very helpful ❤️ thank you and waiting for your next video

  • @souhaillepacifique7572
    @souhaillepacifique7572 4 ปีที่แล้ว

    Great video thank you 💝🇲🇦 following you from Morocco ✌ keep it up

  • @b3ast407
    @b3ast407 4 ปีที่แล้ว

    Thanks Farah!! Learnt something new

  • @mscor4ever139
    @mscor4ever139 3 ปีที่แล้ว

    great work , you deserve the best

  • @faysalahmed7251
    @faysalahmed7251 4 ปีที่แล้ว

    Gr8 job, keep it up

  • @sail6114
    @sail6114 4 ปีที่แล้ว

    Good one, finally I understood the concept 👍

  • @ishanpatel8386
    @ishanpatel8386 3 ปีที่แล้ว

    Hey farah, I hope you're doing well. I just wanted to ask one small thing which is confusing me, JWT are used for "authorisation" which means after we're logged in it is used to check if we're the same user which logged in vis "authentication". So my question is you used jwt authentication in your thumbnail but jwts are used for authorisation, I just want you to clear this confusion because I think I'm missing something

  • @simranpreetsingh5502
    @simranpreetsingh5502 4 ปีที่แล้ว

    Hi Farah, That was an amazing video ! Just out of curiosity is there a way we can know how session ID's are generated by bruteforcing or any other means, any help around this would be helpful ! Thanks much :D

  • @muhammedsillah111
    @muhammedsillah111 4 ปีที่แล้ว

    keep up the good work really love the video

  • @swapnilpawar2311
    @swapnilpawar2311 4 ปีที่แล้ว

    Simple Explanation, Good video

  • @skeepersfrance947
    @skeepersfrance947 3 ปีที่แล้ว

    Hey, I have a question. What do you do when you find a site using HS256 algo, do you suggest them to go for RS256 or just let it be?

  • @ThePomelo09
    @ThePomelo09 4 ปีที่แล้ว

    Ty +1 subscriber! Hi from Argentina.

  • @Status_Zones.
    @Status_Zones. 4 ปีที่แล้ว

    Nice video!atlast some hope ..that i can also find bugs..

  • @PrasadMhatre
    @PrasadMhatre 4 ปีที่แล้ว

    Good tutorial

  • @amansanghai1201
    @amansanghai1201 4 ปีที่แล้ว

    Hey, are you doing all this in windows or in Linux? It seems like you r using windows

  • @amanali9501
    @amanali9501 3 ปีที่แล้ว

    How to get they lab 🧪 environment

    • @FarahHawa
      @FarahHawa  3 ปีที่แล้ว

      Check the description!

  • @vijaykannanhere
    @vijaykannanhere 4 ปีที่แล้ว

    Keep it up Farah!

  • @subhradipmukherjee5440
    @subhradipmukherjee5440 4 ปีที่แล้ว

    I have a querry , In the payload section u changed user id to "admin" to get admin access , but it isn't necessary that user id of admin is always "admin". It can "admin1234" or "ad_min00" or anything else which can't be guessed easily, so how to know what is victims user id or particularly admin user id?

    • @viveksdf
      @viveksdf 4 ปีที่แล้ว

      Brute force it with a user id list

  • @rachitjain5008
    @rachitjain5008 4 ปีที่แล้ว +1

    Thanks Farah...

  • @soniamalik4929
    @soniamalik4929 3 ปีที่แล้ว

    Keep growing di

  • @desafiotic5477
    @desafiotic5477 3 ปีที่แล้ว

    Muchas gracias, gran video, me ayudo mucho.

  • @bkg2190
    @bkg2190 ปีที่แล้ว

    👍very nice video🙂

  • @niteshmore255
    @niteshmore255 4 ปีที่แล้ว

    OWASP ZAP or Burp suit is good to be na show thread website

  • @rudalkumar2177
    @rudalkumar2177 4 ปีที่แล้ว

    Plz help me I am new in this field. But I have done bca. I wanna learn bug bounty. Plz guide me. I need your help .

  • @flowwithmusic787
    @flowwithmusic787 4 ปีที่แล้ว

    Very well explained. ✌

  • @BAPSOFFICIAL
    @BAPSOFFICIAL 4 ปีที่แล้ว +1

    why are you block me on twitter?

  • @vaibhavgaikwad4291
    @vaibhavgaikwad4291 4 ปีที่แล้ว

    Great.... it was sooooo helpful :)

    • @vaibhavgaikwad4291
      @vaibhavgaikwad4291 4 ปีที่แล้ว

      Mam please accept my LinkedIn request i have some doubts

  • @swapnildevkate5112
    @swapnildevkate5112 4 ปีที่แล้ว

    Love from far, from ethical learner

  • @shivendratiwari3238
    @shivendratiwari3238 4 ปีที่แล้ว

    Make a beginner level tutorial for Basic Authentication

  • @127.
    @127. 4 ปีที่แล้ว

    Is this inspired by Black Hills?

  • @vaibhavgaikwad4291
    @vaibhavgaikwad4291 4 ปีที่แล้ว

    Hey i am having problem ..i am getting 302 for 2 of them

    • @FarahHawa
      @FarahHawa  4 ปีที่แล้ว +1

      github.com/h-a-c/jwt-lab You can set up your own lab using this

    • @vaibhavgaikwad4291
      @vaibhavgaikwad4291 4 ปีที่แล้ว

      Hey what if there are other parameters like userid, email, iat and exp smthing what to do in this case, which fields to change?

    • @vaibhavgaikwad4291
      @vaibhavgaikwad4291 4 ปีที่แล้ว

      I can't attach screenshot here😂😂that is the main problem otherwise you might have got it easily what i want to say

    • @FarahHawa
      @FarahHawa  4 ปีที่แล้ว

      @@vaibhavgaikwad4291 auth0.com/docs/tokens/json-web-tokens/json-web-token-claims you’ll find your answers here

  • @faysalahmed7251
    @faysalahmed7251 4 ปีที่แล้ว

    Very good tutorial,

  • @pratikkhalane1653
    @pratikkhalane1653 4 ปีที่แล้ว +10

    You need to turn off the camera , when you demonstrate the situation.

  • @boneytech3965
    @boneytech3965 4 ปีที่แล้ว

    Please upload more tutorial...
    ..

  • @0xsolo920
    @0xsolo920 4 ปีที่แล้ว

    Useful video 👍

  • @sumanthsai2254
    @sumanthsai2254 4 ปีที่แล้ว

    thanks for the video

  • @silenttravelerRahul
    @silenttravelerRahul 4 ปีที่แล้ว

    Can we get the code to change the signature

    • @FarahHawa
      @FarahHawa  4 ปีที่แล้ว +1

      It’s mentioned in the description!

  • @HaxorBird
    @HaxorBird 4 ปีที่แล้ว

    Amazing!

  • @zeeshandaimi3218
    @zeeshandaimi3218 4 ปีที่แล้ว

    Nice video!

  • @bibekdhakal5353
    @bibekdhakal5353 4 ปีที่แล้ว

    keep up the good work, and dont think about quieting youtube because of some shitty comment sister. And once again thanks for posting such a wonderful video.

  • @mimrankhan9974
    @mimrankhan9974 3 ปีที่แล้ว

    how old are you kid?

  • @rainshen6628
    @rainshen6628 4 ปีที่แล้ว

    With subtitles, it might be better

  • @zeuscybersec659
    @zeuscybersec659 4 ปีที่แล้ว

    Waiting for Christi Vlad to comment😂

  • @gokul5582
    @gokul5582 2 ปีที่แล้ว

    I ❤ YOU

  • @boobalandharani4848
    @boobalandharani4848 2 ปีที่แล้ว

    i am beginner to this pentesting. what is bearer token. whether it can see in request or response while intercept in burp. and also any link for this topic to study.
    Oauthauthentication is used in bearer token?