Web Hack List

Collected research

Abusing JWT public keys without the public key

The article recovers an RSA public modulus from two known JWT message-signature pairs by taking GCDs of signature-derived values, then recreates the deterministic PKCS #1/PEM key encoding. It uses that reconstructed public key against PyJWT's RSA-to-HMAC algorithm-confusion flaw to forge authenticated tokens without first obtaining the published key.

Record

Researcher
@SilentSignalHU
Published by
Silent Signal Techblog
Date

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of @SilentSignalHU, first published at the original source. Preserved copies are kept so the citation survives its host.