During a web application test, a tester discovers that the application uses JSON Web Tokens (JWT) for authentication. The tester intercepts a JWT and changes the algorithm header to 'none' with an empty signature. Which attack is being attempted?
A JWT alg:none attack works by changing the token's `alg` header field to `none`, signaling that the token is unsecured. Vulnerable JWT libraries that accept this value will skip signature verification entirely, allowing an attacker to forge tokens with arbitrary claims, such as elevating privileges, without knowing the secret key. This directly exploits the server's failure to enforce strict algorithm allowlists.
Why this answer
Setting algorithm to 'none' is a JWT algorithm confusion attack where the server accepts unsigned tokens.