Skip to content

Conversation

@wg4568
Copy link
Contributor

@wg4568 wg4568 commented Jun 25, 2019

I wrote an active scanner rule to detect an exploit that arises from using poorly implemented JWT.

More info: https://www.sjoerdlangkemper.nl/2016/09/28/attacking-jwt-authentication/

Copy link
Member

@kingthorin kingthorin left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the contribution!

Edit: If you could address the two LGTM items as well that'd be wonderful (they're simple, just two lines missing var keyword).

@zaproxy zaproxy deleted a comment from lgtm-com bot Jun 25, 2019
@kingthorin
Copy link
Member

@wg4568 do you plan to address the remaining comment?

1 similar comment
@kingthorin
Copy link
Member

@wg4568 do you plan to address the remaining comment?

Copy link
Member

@kingthorin kingthorin left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks

@thc202
Copy link
Member

thc202 commented Dec 17, 2019

Thanks!

@thc202 thc202 merged commit dae463e into zaproxy:master Dec 17, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants