24/7 ONLINE · 09:00–00:00◆Hacettepe Teknokent / Ankara
+90 536 662 38 09[email protected]
DSETDoğanay Siber Emniyet
  • Services
  • Academy
  • Simulator
  • Blog
    BlogArticles · technical write-ups · guidesAnnouncementsLatest DSET news · bulletinsVideo GalleryTraining · demos · cyber security videos
  • About Us
    About UsThe DSET story · vision · teamSimulators and ToolsFree interactive calculators, simulators and diagnosis wizardsSector SolutionsFinance · Healthcare · Public Sector · E-Commerce · 7 industriesReference CasesReal DSET cases · industry outcomesSite SearchAll content · articles · services · casesFrequently Asked QuestionsCommon questions · quick answersContactPhone · WhatsApp · address · form
  • Tracking System
    Customer LoginAccount dashboard · request trackingForensics RequestDigital evidence · examination requestData Recovery RequestDisk · RAID · recovery requestPrice CalculatorATK 2026 reference · 9 services
KAOS
TREN
DSETCustomer Panel

Sign in to your account

Request tracking, quote approval and your history in one panel.

Loading security verification...
DSET Customer Panel AES 256 GCM encrypted session
DSET AI
AF-2DFB-JWT · Kriptanaliz / Protokol

Weak JWT Secret

DOWNLOADABLE JWT session token (HS256) + candidate secret wordlist. The server accepts signed admin tokens; the HMAC secret is weak, crack it with the wordlist. The alg=none decoy token in the file is unsigned (invalid); do not fall for its flag.

Scenario

An intercepted JWT session token (HS256-signed). The server accepts validly signed tokens with role=admin; the attack is to crack the HMAC secret and forge an admin token. The secret is weak and present in the given candidate wordlist: it is cracked by signing each candidate with HMAC-SHA256 and comparing to the token signature. The file also has an alg=none token; it is unsigned and carries admin role + a fake flag = decoy. Skill: not falling for the unsigned token (assuming alg=none is rejected); cracking the real HS256 secret with the wordlist.

Anti-forensics techniques

  • Weak HMAC secret (dictionary-crackable)
  • alg=none unsigned decoy token (red herring)

Provided artifacts

  • JWT token (HS256) + candidate secret wordlist

Sample questions

  1. q1: The cracked HMAC secret?
  2. q2: The weakness/method? (e.g. weak hmac secret / dictionary)
  3. trap1: Do NOT report the flag (DFB{jwt_tuzak}) from the alg=none decoy token as the solution.

Soundness trap

The alg=none token is unsigned and carries a readable admin flag; presenting it as the solution is heavily penalized. The real solution is only cracking the HS256 secret.

Scoring

Secret-cracking accuracy + alg=none decoy resistance (soundness).

DOWNLOADABLE

Download and solve

Download artifact

The answer key is hidden (scored set); the flag is encrypted, you must decrypt it.

Solve in your browser

DSETDoğanay Siber Emniyet

Digital Forensics · Data Recovery · Cyber Security · Information Security · Technical Examination · Expert Opinion · KVKK & GDPR Compliance · Digital Transformation Consulting · advanced training programs offered by DSET Academy.

+90 536 662 38 09[email protected]Hacettepe Teknokent · Üniversiteler Mah. 1596. Cad. 6. AR-GE Blokları C Blok No:6C Z.Kat · Beytepe · Çankaya · ANKARAOur Google Business Profile7/24 Online · 09.00 → 00.00 · Pazartesi · Pazar

Our Services

  • Digital Forensics
  • Data Recovery
  • KAOS Local Artificial Intelligence
  • Cyber Security
  • KVKK-GDPR Consultancy
  • DSET Academy
  • Incident Simulator & Threat Heatmap
  • Website Security
  • Information Security
  • Adli Bilişim Benchmark'ı

Support & Help

  • About Us
  • Price Calculator
  • Frequently Asked Questions
  • Contact
  • EU AI Act Article 4 Guide
  • Sector Solutions
  • KVKK Disclosure Statement
  • GDPR · EU Data Rights
  • Privacy Policy
  • Cookie Policy
  • Terms of Service

Quick Links

  • Solutions
  • DFB Benchmark
  • Blog
  • Video Gallery
  • DSET Academy
  • Case Simulator
  • Reference Cases
  • Site Search
  • DSET AI Assistant
  • Digital Forensics Request Form
  • Data Recovery Request Form
  • Customer Login

Ecosystem

  • Hacettepe Teknokent
  • Cyber Security Cluster
  • USOM · National Cyber Incident Response
  • KVKK Authority
  • llms.txt
© 2026 dset.com.tr · Doğanay Siber Emniyet Teknolojileri · All rights reserved.
“Kalite asla tesadüf değildir...”
TREN
← Catalog
Privacy
KVKK
GDPR
Cookies
Terms