
MyJWT
A cli for cracking, testing vulnerabilities on Json Web Token(JWT)

A cli for cracking, testing vulnerabilities on Json Web Token(JWT)

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

Penetration Testing and Hacking CTF's Swiss Army Knife with: Reverse Shell Handling - Encoding/Decoding - Encryption/Decryption - Cracking Hashes /…

Words list generator to crack security tokens

Automated exploit chain for CVE-2026-63030 / CVE-2026-60137 — unauthenticated blind SQLi via WordPress REST batch route-confusion. Dumps user hashes,…

DifuseHQ Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient…

A native backdoor module for Microsoft IIS (Internet Information Services)

Wavestone's web interface for password cracking with hashcat

针对JWT渗透开发的漏洞验证/密钥爆破工具,针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ,也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)


Moodle 4.5.0-4.5.2 Unauthenticated REST API User Data Exposure via Stack Trace Args Leak | CVSS 7.5

JWT brute force cracker written in C

Brute_Force_Attack Gmail Hotmail Twitter Facebook Netflix


Making Favicon.ico based Recon Great again !

Simple HS256, HS384 & HS512 JWT token brute force cracker.

Web-based GUI for Hashcat that simplifies password cracking with session management, mask generation, wordlist support, and multi-user access.
