Skip to content

IAM

Kerberos

Moved to dedicated section at https://kbase.ayoma.me/iam-kerberos/

JWT

  • jku can be changed to a different URL, so that the validator will pick the key material from attacker controlled endpoint. (Ref: AttackDefense - JWT CTF)

References

OAuth2

Bug Reports