Silent HMAC Key Contamination: Uncovering a Logic Flaw in Burp's JWT Editor Extension
JWT Editor was shortlisted for “Best Auth & Access Control” in PortSwigger’s 2026 Burp Suite Extension Awards. This is the story of finding a silent bug inside it.
Usually, when something goes wrong, your first instinct is to look at yourself. What did I do wrong? Which step did I miss? It takes a lot to get to the point where you seriously consider that the mistake isn’t yours at all: it’s the tool’s.
It’s a bit like a developer insisting their code is broken because of VS Code itself. Especially when everyone around you is saying the opposite, and your own eyes keep telling you the same thing they’re saying. But sometimes you have to hold onto an old piece of advice:
Once you eliminate the impossible, whatever remains, no matter how improbable, must be the truth.Arthur Conan Doyle (Sherlock Holmes)
This is the story of how...
Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE