API & JWT Attacks

advanced Hands-on lab 50 min 3 tasksSubscription

Attack REST APIs and JSON Web Tokens: endpoint enumeration, mass assignment, and JWT forgery via the alg:none trick and weak-HMAC cracking with jwt_tool and hashcat.

This lab is available with a Purple Edge subscription. Sign in to view the full overview and start the lab.

Part of these paths

Unlock this lab

Launch the lab in your browser. Real Kali, Ubuntu and Windows targets, guided step by step. No setup, no VM downloads.

Updated 2026-06-06