Skip to content

Instantly share code, notes, and snippets.

@locitar
locitar / jwt_forge.py
Last active January 4, 2024 17:24 — forked from wulfgarpro/jwt_forge.py
HTB "Under Construction" CVE-2015-9235 PoC
"""
CVE-2015-9235 PoC, known as
"JWT HS/RSA key confusion vulnerability".
This PoC was used to solve the HTB challenge
"Under Construction" on HackTheBox (HTB).
USAGE:
==
Token was obtained by logging into the