top of page
rsa jwt key confusion

RSA JWT Key Confusion

  • 12 Steps
  • 4 Participants

About

Complete JWT Secrets and Algorithm Confusion so you already treat `alg` as attacker-controlled. Key confusion is the next use of that control: swap RS256 for HS256 and sign with the RSA public key instead of a shared secret. In this module of the Applied Cryptography learning path, you practice that swap on a Ciberbots key portal that issues RS256 tokens and publishes `public.pem` for partners. Upon completion of the module, students will be able to: - Download an RSA public key and explain why it is public. - Describe RS256 versus HS256 verification. - Forge HS256 over the PEM bytes against this lab's confused verifier. For inquiries, please write us at https://www.darkrelay.com/cybersecurity-course-inquiry

Overview

Price

2 Plans Available, From ₹2,399.00

Share

bottom of page