{"repo":"tyki6/MyJWT","free":true,"listed":false,"github":"https://github.com/tyki6/MyJWT","clone":"git clone https://github.com/tyki6/MyJWT.git","description":"A cli for cracking, testing vulnerabilities on Json Web Token(JWT)","language":"Python","stars":138,"topics":["pentesting","security","security-tools","python","jwt","jsonwebtoken","websec","cli","rawsec","ctf"],"license":"MIT","category":"security-tools","readme_excerpt":"MyJWT Introduction This cli is for pentesters, CTF players, or dev. You can modify your jwt, sign, inject ,etc... Check Documentation for more information. If you see problems or enhancement send an issue.I will respond as soon as possible. Enjoy :) Documentation Documentation is available at http://myjwt.readthedocs.io Table of Contents - Features - Installation - Usage - Examples - Download - Contribute - ChangeLog Features - copy new jwt to clipboard - user Interface (thanks questionary) - color output - modify jwt (header/Payload) - None Vulnerability - RSA/HMAC confusion - Sign a jwt with key - Brute Force to guess key - crack jwt with regex to guess key - kid injection - Jku Bypass - X5u Bypass Installation To install myjwt, simply use pip: To run mywt from a docker image, run: To install myjwt, on git: To install myjwt on BlackArch: Usage Modify JWT Option Type Example help --------------------------- :---------: :--------: ---: --ful-payload JSON {\"user\": \"admin\"} New payload for your jwt. -h, --add-header key=value user=admin Add a new key, value to your jwt header, if key is present old value will be replaced. -p, --add-payload key=value user=admin Add a new key, value to your jwt payload, if key is present old value will be replaced. Check Your JWT (HS alg) Option Type Example help --- --- --- --- --sign text mysecretkey Sign Your jwt with your key --verify text mysecretkey Verify your key. Exploit Option Type Example help --- --- --- --- -none, --none-vulnerabilit","default_branch":null,"files":null,"tree":[],"storefront":"/r/tyki6","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/tyki6/MyJWT/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}