1 posts across writeups, research, and technical deep-dives. Filter by tag.
CTF writeup: a JWT jku URL check uses lastIndexOf instead of real parsing, so an @ symbol tricks it into trusting an attacker-hosted JWKS and bypasses auth.