JWT
"kid": "../../../../../../../dev/null" In the JWT payload, change the value of the sub claim to administrator. At the bottom of the tab, click Sign, then select the symmetric key that you generated in the previous section. Make sure that the Don't modify header option is selected, then click OK. The modified token is now signed using a null byte as the secret key.
hashcat -a 0 -m 16500 <YOUR-JWT> /path/to/jwt.secrets.list
Last updated