
모듈형 커맨드라인 도구로, 해커를 위해 JWT 토큰을 파싱, 생성 및 조작합니다.
보안 테스트 목적으로 JSON 웹 토큰(JWT)을 파싱, 생성 및 조작하기 위한 모듈식 명령줄 도구입니다.
다음과 같이 직접 설치하십시오:
$ gem install jwtear
888888 888 888 88888888888
"88b 888 o 888 888
888 888 d8b 888 888
888 888 d888b 888 888 .d88b. 8888b. 888d888
888 888d88888b888 888 d8P Y8b "88b 888P"
888 88888P Y88888 888 88888888 .d888888 888
88P 8888P Y8888 888 Y8b. 888 888 888
888 888P Y888 888 "Y8888 "Y888888 888
.d88P v1.0.0
.d88P"
888P"
NAME
jwtear - Parse, create and manipulate JWT tokens.
SYNOPSIS
jwtear [global options] command [command options] [arguments...]
GLOBAL OPTIONS
-v, --version - Check current and latest version
-h, --help - Show this help message
COMMANDS
help - Shows a list of commands or help for one command
bruteforce, bfs - plugin to offline bruteforce and crack token's signature.
jws, s - Generate signature-based JWT (JWS) token.
jwe, e - Generate encryption-based JWT (JWE) token.
parse - Parse JWT token (accepts JWS and JWE formats).
wiki, w - A JWT wiki for hackers.
-h COMMAND를 사용하십시오$jwtear -h jws
NAME
jws - Generate signature-based JWT (JWS) token.
SYNOPSIS
jwtear [global options] jws [command options]
DESCRIPTION
Generate JWS and JWE tokens.
COMMAND OPTIONS
-h, --header=JSON - JWT header (JSON format). eg. {"typ":"JWT","alg":"HS256"}. Run 'jwtear gen -l' for supported algorithms. (required, default: none)
-p, --payload=JSON - JWT payload (JSON format). eg. {"login":"admin"} (required, default: none)
-k, --key=PASSWORD|PUB_KEY_FILE - Key as a password string or a file public key. eg. P@ssw0rd | eg. public_key.pem (default: none)
플러그인은 하위 명령으로 정의됩니다. 각 하위 명령은 하나 이상의 인수 및/또는 스위치를 가질 수 있습니다.
$ jwtear parse -t eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.J8SS8VKlI2yV47C4BtfYukWPx_2welF34Mz7l-MNmkE
$ jwtear jws -h '{"alg":"HS256","typ":"JWT"}' -p '{"user":"admin"}' -k p@ss0rd123
$ jwtear jwe -header '{"enc":"A192GCM","typ":"JWT"}' --payload '{"user":"admin"}' --key public.pem
$ jwtear bruteforce -v -t eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJ1c2VyIjpudWxsfQ.Tr0VvdP6rVBGBGuI_luxGCOaz6BbhC6IxRTlKOW8UjM -l ~/tmp/pass.list
새 플러그인을 추가하려면 plugins 디렉토리 아래에 다음과 같은 구조로 새 Ruby 파일을 만드십시오.
module JWTear
module CLI
extend GLI::App
extend JWTear::Helpers::Extensions::Print
extend JWTear::Helpers::Utils
desc "Plugin short description"
long_desc "Plugin long description"
command [:template, :pt] do |c|
c.action do |global, options, arguments|
print_h1 "Plugin template"
print_good "Hi, I'm a template."
template = TemplatePlugin.new
end
end
end
module Plugin
class TemplatePlugin
include JWTear::Helpers::Extensions::Print
include JWTear::Helpers::Utils
def initialize
check_dependencies
# ..code...
end
# ..code...
end
end
end
각 플러그인에 대한 모든 종속성을 jwtear에 포함시키는 대신, 이러한 종속성을 check_dependencies 메서드에 해시로 추가할 수 있습니다. 그러면 라이브러리를 require하고 누락된 gem을 설치하도록 사용자에게 친절한 오류 메시지를 표시합니다.
해시 _key_는 설치할 gem 이름이고, 해시 _value_는 require 문자열입니다.
deps = {'async-io' => 'async/ip'}
check_dependencies(deps)
사용자가 누락된 종속성을 설치하면 check_dependencies는 플러그인 클래스가 초기화될 때 이를 require합니다.
버그 리포트 및 풀 리퀘스트는 GitHub (https://github.com/[USERNAME]/jwtear) 에서 환영합니다.
git checkout -b my-new-feature)git commit -am 'Add some feature')git push origin my-new-feature)이 gem은 MIT 라이선스 조건에 따라 오픈 소스로 제공됩니다.