Introducing SignSaboteur: forge signed web tokens with ease
portswigger.net | research | #burp-suite | #authentication | #jwt | #tooling | #brute-force | #signed-tokens
Summary
SignSaboteur is an open-source Burp extension for editing, signing, verifying and attacking signed tokens — JWT, Django, Flask, Express — with default-secret wordlists and automated brute-forcing.
- Published
- Collected
Skip to content