all jwt

Everything I've published,
in one feed.

1 posts across writeups, research, and technical deep-dives. Filter by tag.

1 posts
2025.09.21
CTFWeb SecurityJWT

Amazon AppSec CTF: HalCrypto

CTF writeup: a JWT jku URL check uses lastIndexOf instead of real parsing, so an @ symbol tricks it into trusting an attacker-hosted JWKS and bypasses auth.

6 min
>_ esc