Hack The Box: (Awkward) To retrieve an LFI with JWT token

What is JWT? For those who are not familiar with JSON tokens, it’s a method to securely exchange data, especially an LFI attack in which the application uses a JSON object. The purpose of the method is to be used within an authorization in which the objects need to be signed, verified, and also been trusted. Demonstration with attack method using the JWT with LFI attacks. The demonstration is taken from the walkthrough over here Firstly, we are required to download the jwt2john.py into our attacker’s machine We also can use the jwt token to crack the password just like […]

The post Hack The Box: (Awkward) To retrieve an LFI with JWT token appeared first on Threatninja.net.

February 27, 2023
Read More >>

Banning TikTok

Congress is currently debating bills that would ban TikTok in the United States. We are here as technologists to tell you that this is a terrible idea and the side effects would be intolerable. Details matter. There are several ways Congress might ban TikTok, each with different efficacies and side effects. In the end, all the effective ones would destroy the free Internet as we know it.

There’s no doubt that TikTok and ByteDance, the company that owns it, are shady. They, like most large corporations in China, operate at the pleasure of the Chinese government. They collect extreme levels of information about users. But they’re not alone: Many apps you use do the same, including Facebook and Instagram, along with seemingly innocuous apps that have no need for the data. Your data is bought and sold by data brokers you’ve never heard of who have few scruples about where the data ends up. They have digital dossiers on most people in the United States…

February 27, 2023
Read More >>