How I Hacked JWT Tokens and Became Everyone on the Internet (Temporarily)
一位安全测试人员在测试名为“SocialFlow”的新社交媒体平台时,意外发现了一个严重的安全漏洞。该平台声称拥有“军事级安全”,但测试人员通过分析API和捕获流量,发现了JSON Web Tokens(JWT)被不当使用的情况。这使得他能够获取所有用户的账户访问权限,相当于找到了数字世界的万能钥匙。 2025-10-31 06:32:23 Author: infosecwriteups.com(查看原文) 阅读量:6 收藏

Iski

Hey there!😁

Free Link 🎈

Press enter or click to view image in full size

Image by AI

You know that moment when you find a spare key under someone’s doormat and think “Wow, people actually do this?” Well, I found the digital equivalent last week. Except instead of a physical key, it was JSON Web Tokens, and instead of one house, it was every user’s account on the entire platform. All because someone left the key to the kingdom under a virtual doormat labeled “security.” 🗝️

It all started when I was testing “SocialFlow,” a new social media platform that was getting hype for its “military-grade security.” I had a basic user account and was ready to poke around. Little did I know I was about to become the master of keys…

Act 1: The Accidental Discovery — Token Troubles 🔍

After my standard recon (I should really make a keyboard shortcut for subfinder | httpx | gau by now), I found SocialFlow's API. I created two test accounts and started capturing traffic in Burp.


文章来源: https://infosecwriteups.com/how-i-hacked-jwt-tokens-and-became-everyone-on-the-internet-temporarily-1e05f961048d?source=rss----7b722bfd1b8d---4
如有侵权请联系:admin#unsafe.sh