
JSON Web Token Hack Toolkit
JSON Web Token Hack Toolkit
Ein hochperformantes Toolkit zum Testen, Analysieren und Angreifen von JSON Web Tokens.
cargo install jwt-hack
brew install jwt-hack
sudo snap install jwt-hack
choco install jwt-hack
git clone https://github.com/hahwul/jwt-hack
cd jwt-hack
cargo install --path .
docker pull ghcr.io/hahwul/jwt-hack:latest
docker pull hahwul/jwt-hack:v2.6.0
| Modus | Beschreibung | Unterstützung |
|---|---|---|
| Encode | JWT/JWE-Encoder | Secret-basiert / Schlüsselbasiert / Algorithmus / Benutzerdefinierter Header / DEFLATE-Komprimierung / JWE |
| Decode | JWT/JWE-Decoder | Algorithmus, Issued-At-Prüfung, DEFLATE-Komprimierung, JWE-Struktur |
| Verify | JWT-Verifizierer | Secret-basiert / Schlüsselbasiert (für asymmetrische Algorithmen) |
| Crack | Secret-Cracker | Wörterbuchangriff / Brute-Force / DEFLATE-Komprimierung |
| Payload | JWT-Angriffs-Payload-Generator | none / jku&x5u / alg_confusion (signiert via --public-key) / kid- & Claim-Injection / Claims-Manipulation / Signatur-Malleabilität / JWE-Probes / x5c / cty |
| Scan | Schwachstellen-Scanner | Automatisierte Sicherheitsprüfungen für gängige JWT-Schwachstellen |
| Server | API-Server | API-Server-Modus ausführen (http://localhost:3000) |
| MCP | Model Context Protocol Server | KI-Modell-Integration über standardisiertes Protokoll |
Sie können sowohl reguläre als auch DEFLATE-komprimierte JWTs dekodieren. Das Tool erkennt und dekomprimiert komprimierte Tokens automatisch.
jwt-hack decode eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjM0In0.CHANGED
jwt-hack decode COMPRESSED_JWT_TOKEN
Dekodieren Sie JWE-Tokens (JSON Web Encryption), um ihre Struktur zu analysieren. Das Tool erkennt das JWE-Format (5 Teile) automatisch und zeigt die Verschlüsselungsdetails an.
# Decode JWE token structure
jwt-hack decode eyJhbGciOiJkaXIiLCJlbmMiOiJBMjU2R0NNIn0..ZHVtbXlfaXZfMTIzNDU2.eyJ0ZXN0IjoiandlIn0.ZHVtbXlfdGFn
# Shows JWE header, encrypted key, IV, ciphertext, and authentication tag
jwt-hack encode '{"sub":"1234"}' --secret=your-secret
Sie können die Option --compress verwenden, um DEFLATE-Komprimierung auf die JWT-Payload anzuwenden.
jwt-hack encode '{"sub":"1234"}' --secret=your-secret --compress
# With Private Key
ssh-keygen -t rsa -b 4096 -E SHA256 -m PEM -P "" -f RS256.key
jwt-hack encode '{"a":"z"}' --private-key RS256.key --algorithm=RS256
Erstellen Sie JWE-Tokens (JSON Web Encryption) zum Testen verschlüsselter JWT-Szenarien.
# Basic JWE encoding
jwt-hack encode '{"sub":"1234", "data":"encrypted"}' --jwe --secret=your-secret
# JWE tokens are encrypted and can only be decrypted with the proper key
jwt-hack encode '{"sensitive":"data"}' --jwe
Prüft, ob die Signatur eines JWT mit dem angegebenen Secret oder Schlüssel gültig ist.
# With Secret (HMAC algorithms like HS256, HS384, HS512)
jwt-hack verify YOUR_JWT_TOKEN_HERE --secret=your-256-bit-secret
# With Private Key (for asymmetric algorithms like RS256, ES256, EdDSA)
jwt-hack verify YOUR_JWT_TOKEN_HERE --private-key path/to/your/RS256_private.key
Wörterbuch- und Brute-Force-Angriffe unterstützen auch mit DEFLATE komprimierte JWTs.
# Dictionary attack
jwt-hack crack -w wordlist.txt JWT_TOKEN
jwt-hack crack -w wordlist.txt COMPRESSED_JWT_TOKEN
# Bruteforce attack
jwt-hack crack -m brute JWT_TOKEN --max=4
jwt-hack crack -m brute COMPRESSED_JWT_TOKEN --max=4
jwt-hack payload JWT_TOKEN --jwk-attack evil.com --jwk-trust trusted.com
Scannt JWT-Tokens automatisch auf gängige Sicherheitsprobleme und Schwachstellen.
# Full scan including weak secret detection and payload generation
jwt-hack scan JWT_TOKEN
# Skip secret cracking for faster results
jwt-hack scan JWT_TOKEN --skip-crack
# Skip payload generation
jwt-hack scan JWT_TOKEN --skip-payloads
# Use custom wordlist for weak secret detection
jwt-hack scan JWT_TOKEN -w custom_wordlist.txt
# Limit secret testing attempts
jwt-hack scan JWT_TOKEN --max-crack-attempts 50
Der scan-Befehl prüft auf:
Starten Sie eine lokale REST-API für Automatisierung und Integrationen. Um Authentifizierung zu erfordern, verwenden Sie --api-key und fügen Sie X-API-KEY in Anfragen ein.
# Start on localhost:3000 with API key protection
jwt-hack server --api-key your-api-key
# Example request (must include X-API-KEY when --api-key is set)
curl -s http://127.0.0.1:3000/health -H 'X-API-KEY: your-api-key'
jwt-hack kann als MCP-Server ausgeführt werden, sodass KI-Modelle über ein standardisiertes Protokoll mit der JWT-Funktionalität interagieren können.
# Start MCP server (communicates via stdio)
jwt-hack mcp
Der MCP-Server stellt die folgenden Tools bereit: