You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I have this working in beta currently, and it works on keys with common configurations.
I'm cleaning it up to make it work against more keys, and to integrate better with the rest of the tool.
Should be pushing to live soon.
Hi!
@silentsignal recently published an article on how to reconstruct RSA keys from RSA signatures, and how it can be useful with key-confusion attacks on JWT.
They published rsa_sign2n, which can be used to recreate RSA keys from JWTs. It would be useful to have this attack implemented in jwt_tool.
Thank you for this tool, and for the very detailed wiki!
The text was updated successfully, but these errors were encountered: