Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Introducing SignSaboteur: forge signed web tokens with ease

Summary

SignSaboteur is an open-source Burp extension for editing, signing, verifying and attacking signed tokens — JWT, Django, Flask, Express — with default-secret wordlists and automated brute-forcing.
Published
Collected

original ↗

Related coverage

back