Simple python script to check against hypothetical JWT vulnerability. This script injects a custom key ID into a JWT token, allowing you to test if a server is vulnerable to the hypothetical JWT vulnerability. This script is not intended to be used in production, but rather as a proof-of-concept to demonstrate the vulnerability.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A PowerShell obfuscation detection framework designed to highlight the limitations of signature-based detection and provide a scalable means of detecting known and unknown obfuscation techniques.
A tool to help exploit XXE vulnerabilities by sending a crafted XML file to the server and parsing it to extract the data.
Checksec is a bash script to check the properties of executables like PIE, RELRO, Canaries, ASLR, Fortify Source.
A toolkit for detecting and tracking Blind XSS, XXE, and SSRF vulnerabilities
An open source machine code decompiler that converts binary executables into readable C source code across multiple architectures and file formats.
Identifies 137 malicious npm packages and gathers system information to a remote server.
Standalone graphical utility for viewing Java source codes from ".class" files.
Tools for working with Android .dex and Java .class files, including dex-reader/writer, d2j-dex2jar, and smali/baksmali.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.