JWT Algorithm Confusion Explained: Forging Tokens with RS256 to HS256
How JWT algorithm confusion works, why switching RS256 to HS256 lets an attacker sign their own tokens with a public key, and how to shut it down in your own code.
~/blog/index
Thoughts from the team, lessons from competitions, research commentary, and the kind of notes that do not quite fit inside a formal publication or writeup.
Showing 4 posts
How JWT algorithm confusion works, why switching RS256 to HS256 lets an attacker sign their own tokens with a public key, and how to shut it down in your own code.
A note to Albanians in Kosovo, Albania, and abroad: if you want to learn, contribute, compete, or simply be around the team, there is room for you here.
An introduction to the new KSAL site, what each section is for, how the team will manage posts, and how members can contribute to it over time.
A look at how KSAL organizes before, during, and after a CTF — from category assignments to writeup handoffs and what we have learned about running it well.
No blog posts match this filter yet.
Try a different search term or clear the topic filter.