HACKR.GG
LabsTokenForge Login
JWT AttacksMedium

TokenForge Login

TokenForge's auth server accepts JWTs with alg set to 'none'. Log in as a regular user, forge an admin token by removing the signature.

Step-by-step walkthrough
// Objective

Forge a JWT with alg:none and an admin payload to bypass authentication.

ToolkitBrowserBurp Suitejwt_toolbase64
// Machine control
Checking session...
// Submit flag