WRITEUP · PUBLIC JS · ENTRA JWT · 2026 · @YNSMROZTAS

Hardcoded access token in public JavaScript

● live clk --:--:-- insights.lab.carrier.test

Same string-hunt used in AndroScope PREPARE — JWT regex against a public dashboard bundle. Vendor host, employee, tenant and token body stripped.

js // livepublic
radar--:--:--
AndroScope string hunt Entra ID FH-ID · secrets redacted
01 Problem

A production JS bundle shipped a live employee Entra token with Admin in the roles claim.

02 Move

Unauth GET on the dashboard, pull script src, JWT regex — the same hunt AndroScope runs on DEX strings.

03 Evidence

Filename date matched iat. Claims: mailbox class, tid, aud, Admin. Token body not published.

04 Outcome

Expired copy. Still an SDLC failure. Fix: strip literals, rotate, scan the host.

Summary

A Microsoft Entra ID access token sat in a JavaScript file that anyone could fetch. No login. The payload carried an employee display name, corporate mailbox, object id, tenant id, application id, and roles that included Admin.

The token in the lab copy was already expired. That does not close the finding. Shipping a live employee token into a production bundle is a build-process failure. The filename itself encoded the issue date (maps2x260309.js ↔ 9 March 2026).

Class: secret in public JS. Same JWT pattern AndroScope flags in DEX / assets. Fix: delete the literal, rotate, scan the rest of the host.

Lab frame

Terminal rebuilt from the capture. Host, mailbox and token body replaced.

Redacted terminal: JWT grep on public JS
curl + JWT regex against the public dashboard bundle — token and vendor stripped

Affected lab asset

What the hunt printed

# page embed JWT?
curl -s "$R/field_dashboard/" | grep -oE 'eyJ[A-Za-z0-9_-]{20,}' | head

# pull JS bundles
curl -s "$R/field_dashboard/" | grep -oE 'src="[^"]+\.js[^"]*"'

# hunt the dated bundle
curl -s "$R/field_dashboard/maps/maps2x260309.js" | grep -oE 'eyJ[A-Za-z0-9_-]{20,}'

eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsImtpZCI6In[REDACTED].eyJhdWQiOiI[REDACTED].[SIG REDACTED]

mitsec@insights.lab.carrier.test:

Decoded claims of interest

ClaimLab value
name[REDACTED]
preferred_usernameanalyst.one@lab.carrier.test
rolesAdmin, Internal_Users, External_Users
scptest.read
tid / aud / oid[REDACTED]
iat → exp2026-03-09 23:31 → 2026-03-10 00:37 UTC

Fix

YUNUS EMRE ÖZTAŞ · MITSEC · RESPONSIBLE DISCLOSURE · LAB NAMES ONLY