1 مستودع
Identification of security flaws in how applications process and validate security tokens.
Distinct from Misconfiguration Scanning: Focuses on the runtime processing logic of tokens rather than static configuration files or cluster states.
Explore 1 awesome GitHub repository matching security & cryptography · Token Processing Misconfigurations. Refine with filters or upvote what's useful.
jwt_tool is a security testing toolkit designed for analyzing, tampering with, and auditing JSON Web Tokens to identify cryptographic vulnerabilities and implementation flaws. It serves as a comprehensive suite for security auditing and vulnerability scanning, providing a debugging interface to inspect token headers and payloads. The project distinguishes itself through specialized capabilities for token forgery and secret cracking. It includes a token generator that signs custom tokens using RSA, ECDSA, and symmetric algorithms, and a brute force tool that uses high-speed dictionary attacks
Runs automated playbooks against live applications to identify security flaws in token processing.