Skip to main content

api-auth-and-jwt-abuse

API authentication and JWT abuse playbook. Use when testing bearer tokens, API keys, claim trust, header spoofing, rate limits, and API auth boundary weaknesses.

Informações da origem

Repositório
Kur1sulab/blackbox
Última atividade na origem
12 de agosto de 2026 às 15:17
Idioma detectado do SKILL.md
inglês
Estrelas
3
Forks
1

Opções de instalação

Por padrão, está selecionado o prompt que primeiro revisa a origem. Você pode mudar para um comando direto ou baixar uma cópia local.

Revise os arquivos de origem

Leia o SKILL.md e os arquivos complementares exibidos pelo SkillsMP antes de decidir se vai instalar.

Exibindo SKILL.md

SKILL.md
Instruções da origem · Visualização somente leitura
name
api-auth-and-jwt-abuse
description
API authentication and JWT abuse playbook. Use when testing bearer tokens, API keys, claim trust, header spoofing, rate limits, and API auth boundary weaknesses.
# SKILL: API Auth and JWT Abuse — Token Trust, Header Tricks, and Rate Limits > **AI LOAD INSTRUCTION**: Use this skill when APIs rely on JWT, bearer tokens, API keys, or weak request identity signals. Focus on token trust boundaries, claim misuse, header spoofing, and rate-limit bypass. ## 1. TOKEN TRIAGE Inspect: - `alg`, `kid`, `jku`, `x5u` - role, org, tenant, scope, or privilege claims - issuer and audience mismatches - reuse of mobile and web tokens across products ## 2. QUICK ATTACK PICKS | Pattern | First Test | |---|---| | `alg:none` acceptance | unsigned token with trailing dot | | RS256 confusion | switch to HS256 using public key as secret | | `kid` lookup trust | path traversal or injection in `kid` | | remote key fetch trust | attacker-controlled `jku` or `x5u` | | weak secret | offline crack with targeted wordlists | ## 3. HIDDEN FIELDS AND BATCH ABUSE ### Mass assignment field picks ```text role isAdmin admin verified plan tier permissions org owner ``` ### Rate limit and batch abuse picks ```text X-Forwarded-For: 1.2.3.4 X-Real-IP: 5.6.7.8 Forwarded: for=9.9.9.9 ``` GraphQL or JSON batch abuse candidates: - arrays of login mutations - bulk object fetches with varying IDs - repeated password reset or verification calls in one request ## 4. RATE LIMIT BYPASS FAMILIES ```text X-Forwarded-For X-Real-IP Forwarded User-Agent rotation Path case / slash variants ``` ## 5. NEXT ROUTING - For GraphQL batching and hidden parameters: [graphql and hidden parameters](../hack-graphql-and-hidden-parameters/SKILL.md) - For default credential and brute-force planning: [authentication bypass](../hack-authbypass-authentication-flaws/SKILL.md) - For full JWT and OAuth depth: [jwt oauth token attacks](../hack-jwt-oauth-token-attacks/SKILL.md) - For OAuth or OIDC configuration flaws in browser and SSO flows: [oauth oidc misconfiguration](../hack-oauth-oidc-misconfiguration/SKILL.md) - For credentialed browser reads and origin trust bugs: [cors cross origin misconfiguration](../hack-cors-cross-origin-misconfiguration/SKILL.md)
Ver no GitHub