onsecru / jwt-hacking-challenges
APIs to practise diverse techniques to hack JWT Signatures
☆64Updated last year
Related projects ⓘ
Alternatives and complementary repositories for jwt-hacking-challenges
- GraphQL security workshop labs☆102Updated 4 months ago
- Enhanced fork with logging, OpenAPI 3.0 and Python 3 for security monitoring workshops☆42Updated 9 months ago
- A Burp Suite extension for CSRF proof of concepts.☆46Updated last year
- A reverse whois tool based on Whoxy API.☆158Updated 7 months ago
- Fetch the details of assets hosted on AWS.☆86Updated 11 months ago
- ☆25Updated 4 years ago
- Sometimes we want to fuzz a set of sub-domain URLs with a common wordlist. Fuzzing them one by one is a tedious task, not to mention the …☆51Updated 3 years ago
- Burp Suite extension that offers a toolkit for testing GraphQL endpoints.☆186Updated 3 months ago
- An open source tool to aid in command line driven generation of bug bounty reports based on user provided templates.☆205Updated 4 years ago
- ☆71Updated last year
- DNS and Target HTTP History Local Storage and Search☆63Updated 3 years ago
- ☆71Updated 4 years ago
- Some Tutorials and Things to Do while Hunting That Vulnerability.☆72Updated 4 years ago
- ☆57Updated 4 months ago
- A custom built DNS bruteforcer with multi-threading, and handling of bad resolvers.☆57Updated 2 years ago
- ☆146Updated last year
- Quickly Search Large DNS Datasets☆59Updated 5 years ago
- xss development frameworks, with the goal of making payload writing easier.☆136Updated 3 months ago
- This repository contains all the Talk slides that I have given at various security conferences, events & meetups.☆35Updated 3 years ago
- ☆65Updated last year
- DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider☆138Updated 3 years ago
- Script to test open Akamai ARL vulnerability.☆70Updated 3 years ago
- A Python based scanner to find potential SSRF parameters in a web application.☆71Updated 3 years ago
- You can find hardcoded Api-Key,Secret,Token Etc..☆78Updated 2 years ago
- Damn Vulnerable Java (EE) Application☆130Updated 10 months ago
- Target practice for ffuf☆59Updated 3 years ago
- Let's check if your target is vulnerable for client side prototype pollution.☆63Updated 10 months ago
- Bruteforce a JWT against a list of passwords☆72Updated 7 years ago
- The project aims at creating target-specific wordlists for any web application that you are testing.☆63Updated 2 years ago
- Easily schedule commands to run multiple times at set intervals (like a cronjob, but with one command)☆84Updated 3 years ago