How I Hacked JWT Tokens and Became Everyone on the Internet (Temporarily)
作者在测试社交平台"SocialFlow"时发现其API存在安全漏洞,意外获取了所有用户的JSON Web Tokens,从而获得了全平台账户的访问权限,揭示了该平台"军事级安全"承诺的脆弱性。 2025-10-31 06:32:23 Author: infosecwriteups.com(查看原文) 阅读量:8 收藏

Iski

Hey there!😁

Free Link 🎈

Press enter or click to view image in full size

Image by AI

You know that moment when you find a spare key under someone’s doormat and think “Wow, people actually do this?” Well, I found the digital equivalent last week. Except instead of a physical key, it was JSON Web Tokens, and instead of one house, it was every user’s account on the entire platform. All because someone left the key to the kingdom under a virtual doormat labeled “security.” 🗝️

It all started when I was testing “SocialFlow,” a new social media platform that was getting hype for its “military-grade security.” I had a basic user account and was ready to poke around. Little did I know I was about to become the master of keys…

Act 1: The Accidental Discovery — Token Troubles 🔍

After my standard recon (I should really make a keyboard shortcut for subfinder | httpx | gau by now), I found SocialFlow's API. I created two test accounts and started capturing traffic in Burp.


文章来源: https://infosecwriteups.com/how-i-hacked-jwt-tokens-and-became-everyone-on-the-internet-temporarily-1e05f961048d?source=rss----7b722bfd1b8d--bug_bounty
如有侵权请联系:admin#unsafe.sh