Web Hack List

Collected research

Three New Attacks Against JSON Web Tokens

Three JWT library flaws: a token encrypted to the public half of a signing key pair is accepted as authentic, a JSON-serialized JWS smuggles unsigned claims past a validator that splits the token on dots, and a PBES2 header with a huge iteration count burns CPU before any authentication tag is checked. The first two forge arbitrary tokens; the third is a denial of service.

Record

Researcher
Tom Tervoort
Published by
i.blackhat.com
Format
Whitepaper
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Tom Tervoort, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .