akto
akto copied to clipboard
π Write a blog post about JWT None algo attack using Akto
π Introduction
Akto is an open source API security product.
Your task is to write a blog post about testing for JWT None Algo attack using Akto.
π― Requirements
- Your article has to be publicly available.
- Your article must tag Akto in any way (hashtag, embedded, link...).
- Your article should be at least 1000 words long.
- Your article should look nice. π Use titles, subtitles, screenshots, images, gifs, or even memes.
- The blog has to be factually correct. Incorrect submission will be rejected.
- You have to deep dive into the product by signup and using it.
β Task summary:
- [ ] Drop a comment on this issue indicating that youβre working on it.
- [ ] Write a blog post with title
How I tested for JWT None Algo attack using Akto? - [ ] Publish an article on your favorite platform or website. (Medium, Dev.to, Hashnode...)
- [ ] Submit a pull request here.
- [ ] Share your work on social media and tag https://github.com/akto-api-security/akto (Reddit / HackerNews / Twitter / Facebook / Linkedin)
ππΌββοΈ Questions:
If you have questions, need any help, or just want to hang out, make sure to join us on our Discord server.
This task can have multiple assignees.
@Ankita28g I would like to work on this issue please assign it to me.
Assigned to you @Aviraltech. Happy Hackfesting π
Hi @Aviraltech thanks for your submission in Hackfest. π₯ We are reviewing your work. Do these two below:
Join this group on discord for discussions around prizes? π π Please fill this form your PR to be considered for prizes!
This task can have multiple assignees.
This looks interesting too!! how about you assign me this?
i would like to work on this
@aayushii9602 and @beneyalraj assigned to both of you. Make sure you read the requirements before you start
I've published a blog please let me know if its good https://medium.com/@beneyalraj03/how-i-tested-for-jwt-none-algo-attack-using-akto-951d555b903b
@beneyalraj the blog looks good to me.
Some suggestions to make it better:
- In Step 2 (Identifying the Target Endpoint) it is not necessary to use PUT endpoint. Instead talk how to target endpoints with JWT token in request
- In Step 6 (Check the Attempt Tab for the Modified Token) hover on the "authorization" header to show how the token has changed. Maybe use jwt.io to show the none algorithm in the new token
- Talk about https://www.akto.io/test/jwt-none-algorithm in your blog. Akto has test library where anyone can test their API for JWT none algo vulnerability without signing up on Akto and highlight the simplicity of the approach
Make these changes and we are pretty much good to go.
I have made the above changes in the blog post
This looks awesome @beneyalraj. @Ankita28g can you also review this.