Jump to content
YOUR-AD-HERE
HOSTING
TOOLS

Locked JWT Tool - A Toolkit For Testing, Tweaking And Cracking JSON Web Tokens


itsMe

Recommended Posts

This is the hidden content, please

 

jwt_tool.py is a toolkit for validating, forging and cracking JWTs (JSON Web Tokens).

Its functionality includes:

  •     Checking the validity of a token
  •     Testing for the RS/HS256 public key mismatch vulnerability
  •     Testing for the alg=None signature-bypass vulnerability
  •     Testing the validity of a secret/key/key file
  •     Identifying weak keys via a High-speed Dictionary Attack
  •     Forging new token header and payload values and creating a new signature with the key or via another attack method


This is the hidden content, please

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.