About
Complete JWT Secrets and Algorithm Confusion so you already treat `alg` as attacker-controlled. Key confusion is the next use of that control: swap RS256 for HS256 and sign with the RSA public key instead of a shared secret. In this module of the Applied Cryptography learning path, you practice that swap on a Ciberbots key portal that issues RS256 tokens and publishes `public.pem` for partners. Upon completion of the module, students will be able to: - Download an RSA public key and explain why it is public. - Describe RS256 versus HS256 verification. - Forge HS256 over the PEM bytes against this lab's confused verifier. For inquiries, please write us at https://www.darkrelay.com/cybersecurity-course-inquiry
Overview
Acceptable Usage Policy
.1 step
Lab Access
.1 step
RSA JWT Key Confusion
.6 steps