Auth 0x06

PUT JESSAMY JWT AS SESSION/COOKIE

Cookie: session=eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0=.eyJ1c2VyIjoiamVzc2FteSIsInJvbGUiOiJhZG1pbiJ9.

IT WILL SEND TWO REQUEST AT THE SAME TIME

First it will send the PUT request to jeremy account using his JWT

(jeremy JWT --> jeremy bio change)

Then in the burpsuite it will pass the Jessamy JWT then it will bypass the jeremy account and change his bio

( jessamy JWT --> jeremy bio change)

BUT in the account2.php it will not work

Since the system will check for the JWT and username

(jeremy JWT === jeremy username)

Authorize

(jessamy JWT === jeremy username) -------WRONG

Thats why it says enforced

Last updated