Skip to content
Back to skills

Jwt Algorithm Confusion

ASecurity

Identify and exploit Algorithm Confusion vulnerabilities in JSON Web Tokens (JWT). This skill details how to bypass signature verification by changing the signing algorithm from asymmetric (RS256) to symmetric (HS256) and using the public key as the symmetric secret.

  • 22 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 12, 2026
ai-agentsgobashawstestingapisecurity

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned September 12, 2026

npx -y skills add ShulkwiSEC/bb-huge --skill jwt-algorithm-confusion --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Jwt Algorithm Confusion?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Jwt Algorithm Confusion
[![Security: A β€” Skills Directory](https://www.skillsdirectory.com/api/skills/shulkwisec-jwt-algorithm-confusion/badge)](https://www.skillsdirectory.com/skills/shulkwisec-jwt-algorithm-confusion)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: jwt-algorithm-confusion
description: >
  Identify and exploit Algorithm Confusion vulnerabilities in JSON Web Tokens (JWT). This skill 
  details how to bypass signature verification by changing the signing algorithm from asymmetric (RS256) 
  to symmetric (HS256) and using the public key as the symmetric secret.
domain: cybersecurity
subdomain: bug-hunting
category: APIs
difficulty: advanced
estimated_time: "2 hours"
mitre_attack:
  tactics: [TA0006, TA0004]
  techniques: [T1550.004]
platforms: [web, api]
tags: [jwt, api-security, logic-flaws, authentication, cryptography, bug-hunting]
tools: [burp-suite, json-web-tokens]
version: "1.0"
author: CyberSkills-Elite
license: Apache-2.0
---

# JWT Algorithm Confusion

## When to Use
- When testing APIs or web applications that use JWTs for session management or authentication.
- To attempt to forge arbitrary JWTs (e.g., escalating to 'admin') when the application utilizes an asymmetric signature algorithm (like RS256) and the application's public key can be obtained.


## Prerequisites
- Authorized scope and target URLs from bug bounty program
- Burp Suite Professional (or Community) configured with browser proxy
- Familiarity with OWASP Top 10 and common web vulnerability classes
- SecLists wordlists for fuzzing and enumeration

## Workflow

### Phase 1: Reconnaissance (Finding the Public Key)

```text
# Concept: JWT Algorithm Confusion ```

### Phase 2: Intercepting and Modifying the JWT Header

```json
// {
  "alg": "HS256",
  "typ": "JWT"
}
```

### Phase 3: Modifying the Payload (Privilege Escalation)

```json
// {
  "user": "attacker",
  "role": "admin",
  "iat": 1716260400
}
```

### Phase 4: Signing the Forged JWT

```bash
# jwt_tool.py [ENCODED_HEADER].[ENCODED_PAYLOAD] -S hs256 -k public_key.pem
```

#### Decision Point πŸ”€
```mermaid
flowchart TD
    A[Forge JWT ] --> B{Server Accepts? ]}
    B -->|Yes| C[Exploit API ]
    B -->|No| D[Check None Alg ]
    C --> E[Document Flaw ]
```


## πŸ”΅ Blue Team Detection & Defense
- **Enforce Algorithm Verification**: **Library Updates**: **Public Key Secrecy (Symmetric fallback)**: Key Concepts
| Concept | Description |
|---------|-------------|
## Output Format
```
Jwt Algorithm Confusion β€” Assessment Report
============================================================
Target: [Target identifier]
Assessor: [Operator name]
Date: [Assessment date]
Scope: [Authorized scope]
MITRE ATT&CK: [Relevant technique IDs]

Findings Summary:
  [Finding 1]: [Severity] β€” [Brief description]
  [Finding 2]: [Severity] β€” [Brief description]

Detailed Results:
  Phase 1: [Phase name]
    - Result: [Outcome]
    - Evidence: [Screenshot/log reference]
    - Impact: [Business impact assessment]

  Phase 2: [Phase name]
    - Result: [Outcome]
    - Evidence: [Screenshot/log reference]
    - Impact: [Business impact assessment]

Risk Rating: [Critical/High/Medium/Low/Informational]
Recommendations:
  1. [Immediate remediation step]
  2. [Long-term hardening measure]
  3. [Monitoring/detection improvement]
```


## πŸ“š Shared Resources
> For cross-cutting methodology applicable to all vulnerability classes, see:
> - [`_shared/references/elite-chaining-strategy.md`](../_shared/references/elite-chaining-strategy.md) β€” Exploit chaining methodology and high-payout chain patterns
> - [`_shared/references/elite-report-writing.md`](../_shared/references/elite-report-writing.md) β€” HackerOne-optimized report writing, CWE quick reference
> - [`_shared/references/real-world-bounties.md`](../_shared/references/real-world-bounties.md) β€” Verified disclosed bounties by vulnerability class

## References
- PortSwigger: [JWT algorithm confusion](https://portswigger.net/web-security/jwt/algorithm-confusion)
- Auth0: [Critical vulnerabilities in JSON Web Token libraries](https://auth0.com/blog/critical-vulnerabilities-in-json-web-token-libraries/)

Files in this skill

  • SKILL.md3.8 KB
  • evals/evals.json532 B
  • scripts/process.py7.8 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…