onsecru / jwt-hacking-challengesLinks
APIs to practise diverse techniques to hack JWT Signatures
☆67Updated 2 years ago
Alternatives and similar repositories for jwt-hacking-challenges
Users that are interested in jwt-hacking-challenges are comparing it to the libraries listed below
Sorting:
- GraphQL security workshop labs☆114Updated last week
- Fetch the details of assets hosted on AWS.☆89Updated last year
- Enhanced fork with logging, OpenAPI 3.0 and Python 3 for security monitoring workshops☆44Updated last year
- A very vulnerable implementation of a GraphQL API.☆61Updated 3 years ago
- Tarpit - A Web application seeded with vulnerabilities, rootkits, backdoors & data leaks☆80Updated 3 years ago
- Bucky (An automatic S3 bucket discovery tool)☆197Updated 3 years ago
- someone needs help☆65Updated 3 years ago
- Detectify Crowdsource Challenge☆70Updated 3 years ago
- A blazing fast & feature rich Amazon S3 bucket enumerator.☆99Updated 3 years ago
- A reverse whois tool based on Whoxy API.☆167Updated last year
- Go scripts for checking API key / access token validity☆218Updated 4 years ago
- Cross Origin Resource Sharing MisConfiguration Scanner☆175Updated 3 years ago
- Bruteforce a JWT against a list of passwords☆77Updated 8 years ago
- A Python based scanner to find potential SSRF parameters in a web application.☆70Updated 4 years ago
- xss development frameworks, with the goal of making payload writing easier.☆148Updated last year
- The scripts I write to help me on my bug bounty hunting☆124Updated 3 years ago
- Target practice for ffuf☆67Updated 4 years ago
- DNS and Target HTTP History Local Storage and Search☆64Updated 4 years ago
- A simple way of sending messages from the CLI output to your Slack with webhook.☆116Updated last year
- Awesome information for WebSockets security research☆276Updated 3 years ago
- ☆100Updated last year
- This repository contains all the Talk slides that I have given at various security conferences, events & meetups.☆34Updated 4 years ago
- A combined wordlists for files and directory discovery☆125Updated 4 years ago
- Predict Mongo ObjectIds☆145Updated 7 years ago
- Webapp to search tips on Twitter through #bugbountytips☆72Updated 2 years ago
- ☆36Updated 4 years ago
- You can find hardcoded Api-Key,Secret,Token Etc..☆77Updated 3 years ago
- Fast tool to extract all subdomains from crt.sh website. Output will be up to sub.sub.sub.subdomain.com with standard and advanced search…☆114Updated 3 years ago
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or L…☆131Updated 4 years ago
- ☆129Updated 5 years ago