cyber-exploiting-jwt-algorithm-confusion-attack
[LAB-GATED; discovery is not runtime authorization; offensive/dual-use — authorized-lab gate] Exploits JWT algorithm confusion vulnerabilities where the server''s token verification library accepts the algorithm specified in the JWT header rather than enforcing a fixed algorithm. The tester manipulates the alg header to switch from RS256 to HS256 (using the RSA public key as the HMAC secret), sets alg to none to bypass signature verification, or exploits kid/jku/x5u header injection to sup
Datos de origen
- Repositorio
- nexuslinkproductions/yuri-os
- Última actividad en el origen
- 2 de agosto de 2026 a las 20:10
- Idioma detectado de SKILL.md
- inglés
- Estrellas
- 2
- Forks
- 0
Opciones de instalación
De forma predeterminada está seleccionado el prompt que primero revisa el origen. Puedes cambiar a un comando directo o descargar una copia local.
Revisa los archivos de origen
Lee SKILL.md y los archivos complementarios que muestra SkillsMP antes de decidir si quieres instalarlo.