The Epic Tale of a JWT Key Left on a Confluence Wiki Page — Totally Secure, Right?
文章描述了一次渗透测试经历,作者通过Google dorks搜索意外发现目标网站公开暴露的JWT密钥,最终成功利用该漏洞获取敏感信息。 2025-8-10 05:35:58 Author: infosecwriteups.com(查看原文) 阅读量:13 收藏

Devansh Patel

The story of where to hid JWT key 🔑… and from all places they found 🕵️‍♂️ was in the public 🌐.

Press enter or click to view image in full size

This very evening with casual hunting on a target which was on bugbounty platform i tried a lot on it and was almost 2–3 hours and it was 1 hour past midnight, i was about to close my lappy but i thought to just try out google dorks on it so i started with the dorks………

If you can’t read furthur here is a FREE LINK brother….

BTW you can check the Google dork blog

………and it was also going for a failed attempted but then i tried a dork which was for finding Atlassian dashboards for the target but instead of that i found a dashboard which was having some text related to the target but was not of the…


文章来源: https://infosecwriteups.com/the-epic-tale-of-a-jwt-key-left-on-a-confluence-wiki-page-totally-secure-right-141189f1d9c3?source=rss----7b722bfd1b8d---4
如有侵权请联系:admin#unsafe.sh