Flangvik/TeamFiltration

JWT is not well formed

Closed this issue · 2 comments

Flangvik-

Issue when attempting to exfil after successfully spray. I am getting an IDX12709 error that the JWT is not well formed.

image

Any advice?

Thanks!

Interestingly, this error seems to indicate that the token received in the response of the valid login is not a valid JWT token, which is really weird. Are there any more details you could give without disclosing anything sensitive? Any special SSO or other setup for this client?

The target user is a regular user with federated authentication. The client is hybrid joined. Happy to share screen captures or anything else that may help figure it out.