Collected research
Abusing JWT public keys without the public key
The article recovers an RSA public modulus from two known JWT message-signature pairs by taking GCDs of signature-derived values, then recreates the deterministic PKCS #1/PEM key encoding. It uses that reconstructed public key against PyJWT's RSA-to-HMAC algorithm-confusion flaw to forge authenticated tokens without first obtaining the published key.
Record
- Researcher
- @SilentSignalHU
- Published by
- Silent Signal Techblog
- Date
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of @SilentSignalHU, first published at the original source. Preserved copies are kept so the citation survives its host.