JWAT… Attacking JSON Web Tokens
Key | Action |
---|---|
K or space | Play / Pause |
M | Mute / Unmute |
C | Select next subtitles |
A | Select next audio track |
V | Show slide in full page or toggle automatic source change |
left arrow | Seek 5s backward |
right arrow | Seek 5s forward |
shift + left arrow or J | Seek 10s backward |
shift + right arrow or L | Seek 10s forward |
control + left arrow | Seek 60s backward |
control + right arrow | Seek 60s forward |
shift + down arrow | Decrease volume |
shift + up arrow | Increase volume |
shift + comma | Decrease playback rate |
shift + dot or shift + semicolon | Increase playback rate |
end | Seek to end |
beginning | Seek to beginning |
Share this media
HLS video stream
You can use an external player to play this stream (like VLC).
HLS video streamWhen subscribed to notifications, an email will be sent to you for all added annotations.
Your user account has no email address.
Information on this media
Links:
Number of views:
162Creation date:
July 2, 2019Speakers:
Louis NyffeneggerCompany:
PentesterLabLicense:
CC BY-SA v4Description
Nowadays, JSON Web Tokens are everywhere. They are used as session tokens or just to pass data between applications or µservices. By design, JWT contains a high number of security and cryptography pitfalls. In this talk, we are going to learn how to exploit (with demos) some of those issues.
Speaker
Louis Nyffenegger (PentesterLab)
Bio
Louis Nyffenegger is a security engineer based in Melbourne, Australia. He performs pentest, architecture and code review. Louis is the founder of PentesterLab, a learning platform for web penetration testing. Recently, Louis talked at Owasp AppsecDay Melbourne and ran 2 workshops at Defcon 2018.
Other media in the channel "2019"
- 984 views, 19 this yearPatrOwl - Orchestrating SecOps with an open-source SOAR platformJuly 3rd, 2019
- 136 views, 1 this yearBetter curl !July 3rd, 2019
- 109 views, 31 this year, 1 this monthManaging a growing fleet of WiFi routers combining OpenWRT, WireGuard, Salt and ZabbixJuly 3rd, 2019
- 33 views, 1 this yearNo IT security without Free SoftwareJuly 3rd, 2019
- 33 viewsD4 Project - Design and Implementation of an Open Source Distributed and Collaborative Security MonitoringJuly 3rd, 2019
- 15 viewsProgramming research, a missed opportunity for secure and libre software?July 3rd, 2019