{"repo":"SasanLabs/owasp-zap-jwt-addon","free":true,"listed":false,"github":"https://github.com/SasanLabs/owasp-zap-jwt-addon","clone":"git clone https://github.com/SasanLabs/owasp-zap-jwt-addon.git","description":"OWASP ZAP addon for finding vulnerabilities in JWT Implementations","language":"Java","stars":41,"topics":["jwt","owasp","zaproxy","zap-extension","jwt-scanner","fuzzer","hacktoberfest","scanning","security","security-tools"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"ZAP JWT Add-on This Project contains the JWT Scanner and JWT Fuzzer addon used for finding JWT related vulnerabilities. Why this addon is needed With the popularity of JSON Web Tokens (JWTs) there comes the need to secure their use so that they are not misused because of bad configuration, older libraries, or buggy implementations. So the JWT Support add-on is used to find such vulnerabilities and this blog explains on how to use it. Configuration As the JWT add-on includes a rule for the Active Scanner as well as Fuzzer functionality, there are configuration details which are specific for the JWT add-on. Under ZAP's Options dialog you will find a JWT section as shown below: Explanation Scanner Configuration: In case the application which you are trying to scan is using RSA or more specifically RS algorithm then please configure the public certificate TrustStore path and TrustStore password. These fields are used to find certain vulnerabilities related to RS based JWTs. The Enable Client Configuration Scan option is used to enable client-side validations like JWT being sent to the browser in an insecure or non-recommended way. Fuzzer Configuration: Since JWT is a signed token; fuzzing field values requires resigning the JWT therefore the fuzzer requires an HMac secret key or RSA private key as per the algorithm header field of the JWT. So that the Fuzzer configuration corresponds to the same. Scanner Vulnerability Coverage The JWT add-on's scan rule attempts to identified vul","default_branch":null,"files":null,"tree":[],"storefront":"/r/SasanLabs","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/SasanLabs/owasp-zap-jwt-addon/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}