Get in Touch

Course Outline

Introduction

  • Overview of JWT structure.
  • Common use cases for JWT.

JWT Validation

  • Symmetric token signature.
  • Asymmetric token signature.
  • Validating tokens.
  • Validating claims.

Compromised JWTs

  • Handling stolen JWTs.
  • JWT storage methods.
  • Invalidating JWTs.

Managing a Cryptographic Key

  • Overview of secret keys.
  • Embedding the public key.
  • Embedding a URL containing the key.

JWT Hacking Techniques

  • Brute force approaches.
  • Altering the algorithm from RS256 to HS256.
  • The 'none' algorithm approach.

Summary and Next Steps

Requirements

  • Fundamental knowledge of web services.

Audience

  • Developers.
 7 Hours

Testimonials (5)

Related Categories