Deleting the token only removes it from the client. Any copied token still works until it expires.
That’s the tradeoff of stateless auth: the server tracks nothing.
The usual fix is a blocklist, which makes the system stateful again
#SoftwareEngineering #Security
Deleting the token only removes it from the client. Any copied token still works until it expires.
That’s the tradeoff of stateless auth: the server tracks nothing.
The usual fix is a blocklist, which makes the system stateful again
#SoftwareEngineering #Security
Resultado: acceso como administrador y capacidad para ejecutar SQL.
Toda la historia la tienes aquí:
Resultado: acceso como administrador y capacidad para ejecutar SQL.
Toda la historia la tienes aquí:
🔴 Veremos una estrategia para proteger el robo de los JWT creando una firma digital que corresponda exclusivamente al usuario. Video: youtu.be/bXx605f9EBI
🔴 Veremos una estrategia para proteger el robo de los JWT creando una firma digital que corresponda exclusivamente al usuario. Video: youtu.be/bXx605f9EBI
A Swiss Army knife for developers:
• JWT & Base64 encoders/decoders
• JSON formatters & schema validators
• Hash/UUID generators, regex testers & Cron syntax
🔗 https://dev.dailytoolbox.org
#DevTools #Programming #WebDev
A Swiss Army knife for developers:
• JWT & Base64 encoders/decoders
• JSON formatters & schema validators
• Hash/UUID generators, regex testers & Cron syntax
🔗 https://dev.dailytoolbox.org
#DevTools #Programming #WebDev
pixoate.com/jwt-decoder
#JWT #WebDev
pixoate.com/jwt-decoder
#JWT #WebDev
📊 9.3/10
🏢 Hitachi Industrial Equipment Systems
📝 Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key. The Hardcoding of JWT ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-90492
#cybersecurity #infosec #cve #euvd
📊 9.3/10
🏢 Hitachi Industrial Equipment Systems
📝 Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key. The Hardcoding of JWT ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-90492
#cybersecurity #infosec #cve #euvd
다행히 '/AI업무보고' 치니 로그인 기능, 세션 관리 복잡해서 요청한 것, JWT 발급까지 진행된 상황이 딱 나옴.
내일은 토큰 만료 처리하면 될 듯. 이런 게 자동으로 정리됨.
https://github.com/jyoung9154/AIAgent_Report #AI개발 #업무보고서 #광고
다행히 '/AI업무보고' 치니 로그인 기능, 세션 관리 복잡해서 요청한 것, JWT 발급까지 진행된 상황이 딱 나옴.
내일은 토큰 만료 처리하면 될 듯. 이런 게 자동으로 정리됨.
https://github.com/jyoung9154/AIAgent_Report #AI개발 #업무보고서 #광고
Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg:…
https://cvemon.intruder.io/cves/CVE-2026-28802
Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg:…
https://cvemon.intruder.io/cves/CVE-2026-28802
A Swiss Army knife for developers:
• JWT & Base64 encoders/decoders
• JSON formatters & schema validators
• Hash/UUID generators, regex testers & Cron syntax
🔗 https://dev.dailytoolbox.org
#DevTools #Programming #WebDev
A Swiss Army knife for developers:
• JWT & Base64 encoders/decoders
• JSON formatters & schema validators
• Hash/UUID generators, regex testers & Cron syntax
🔗 https://dev.dailytoolbox.org
#DevTools #Programming #WebDev
Microsoft 내부 분석 서비스 Titan 이 로그인 JWT의 서명을 검증하지 않아, 실제 자격 증명 없이 관리자 신원을 사칭하고 SQL을 실행할 수 있었음 테넌트, 대상 서비스, 애플리케이션 검사는 존재했지만 서명 없는 토큰도 통과했으며, upn 을 admin ...
Microsoft 내부 분석 서비스 Titan 이 로그인 JWT의 서명을 검증하지 않아, 실제 자격 증명 없이 관리자 신원을 사칭하고 SQL을 실행할 수 있었음 테넌트, 대상 서비스, 애플리케이션 검사는 존재했지만 서명 없는 토큰도 통과했으며, upn 을 admin ...
#InfoSec #BugBounty #JWT #Microsoft
#InfoSec #BugBounty #JWT #Microsoft
A Swiss Army knife for developers:
• JWT & Base64 encoders/decoders
• JSON formatters & schema validators
• Hash/UUID generators, regex testers & Cron syntax
🔗 https://dev.dailytoolbox.org
#DevTools #Programming #WebDev
A Swiss Army knife for developers:
• JWT & Base64 encoders/decoders
• JSON formatters & schema validators
• Hash/UUID generators, regex testers & Cron syntax
🔗 https://dev.dailytoolbox.org
#DevTools #Programming #WebDev
https://koadt.github.io/oss-oopssec-store/posts/jwt-weak-secret-admin-bypass/
https://koadt.github.io/oss-oopssec-store/posts/jwt-weak-secret-admin-bypass/
www.desarrollolibre.net/blog/laravel...
Técnicas:
Unificación de endpoints
Firma digital de peticiones
Fingerprinting para JWT
Rate Limiting (Límite de peticiones)
www.desarrollolibre.net/blog/laravel...
Técnicas:
Unificación de endpoints
Firma digital de peticiones
Fingerprinting para JWT
Rate Limiting (Límite de peticiones)
パスキーMFATOTPOIDCJWT は何が違うのかブラウザで動く DB エディタにパスキーを入れて学んだこと
パスキーMFATOTPOIDCJWT は何が違うのかブラウザで動く DB エディタにパスキーを入れて学んだこと
https://rowshield.dev/audit?utm_source=bluesky&utm_campaign=developer-education&utm_medium=social
https://rowshield.dev/audit?utm_source=bluesky&utm_campaign=developer-education&utm_medium=social
AI한테 로그인 기능 요청함, 세션 관리 엉망이라 그랬음. JWT 발급까지 완료, 내일 토큰 만료 처리 남았다는 게 정리됐을 듯.
뭘 고쳤고 왜 `try-catch` 넣었는지도 다 나왔을 수 있음.
https://github.com/jyoung9154/AIAgent_Report #개발로그 #퇴근전 #광고
AI한테 로그인 기능 요청함, 세션 관리 엉망이라 그랬음. JWT 발급까지 완료, 내일 토큰 만료 처리 남았다는 게 정리됐을 듯.
뭘 고쳤고 왜 `try-catch` 넣었는지도 다 나왔을 수 있음.
https://github.com/jyoung9154/AIAgent_Report #개발로그 #퇴근전 #광고
Login module for nwidart/laravel-modules: CMS login (CoreUI admin layout) and device-based JWT authentication for mobile APIs.
🔗 https://github.com/huydevct/login-module
Login module for nwidart/laravel-modules: CMS login (CoreUI admin layout) and device-based JWT authentication for mobile APIs.
🔗 https://github.com/huydevct/login-module
It found a bug no linter could: my tenant was already rotating signing keys, and my app only checked the first one.
I wrote up what worked (and the guardrails) for @auth0byokta.bsky.social 👇
auth0.com/blog/integra...
It found a bug no linter could: my tenant was already rotating signing keys, and my app only checked the first one.
I wrote up what worked (and the guardrails) for @auth0byokta.bsky.social 👇
auth0.com/blog/integra...