Skip to content
#

jwt-attacks

Here are 6 public repositories matching this topic...

Language: All
Filter by language

144 offensive security skills for recon and pentest. Field-validated techniques from 600+ targets across 45+ sectors. Updated with web enum, email sec, google dorks, cloud IAM, WordPress full compromise chains.

  • Updated Jun 28, 2026
  • Python

A comprehensive JWT attack CLI covering every major vulnerability class — from alg:none bypass to RS256→HS256 algorithm confusion, HMAC secret bruteforce, kid header injection (SQLi + path traversal), jku/x5u spoofing with built-in JWKS server, and full token forgery. Built for bug bounty hunters and red teamers.

  • Updated Apr 14, 2026
  • Python

https://github.com/systemslibrarian/crypto-lab-jwt-forge3:45 PMcrypto-lab-jwt-forge — proper order, most-specific subject first:jwtBrowser-based JWT/JWS demo — paste or generate a token, tamper with claims, swap algorithms, and watch alg:none and HS/RS key-confusion attacks succeed against a vulnerable verifier and fail against a correct one. Re

  • Updated Jun 28, 2026
  • TypeScript

Improve this page

Add a description, image, and links to the jwt-attacks topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the jwt-attacks topic, visit your repo's landing page and select "manage topics."

Learn more