BApp details: JSON Web Token Attacker
- Recognition and marking
- JWS/JWE editors
- (Semi-)Automated attacks
- Bleichenbacher MMA
- Key Confusion (aka Algorithm Substitution)
- Signature Exclusion
- Base64url en-/decoder
- Easy extensibility of new attacks
|Last updated||22 November 2017|
You can install BApps directly within Burp, via the BApp Store feature in the Burp Extender tool. You can also download them from here, for offline installation into Burp.
Please note that extensions are written by third party users of Burp, and PortSwigger Web Security makes no warranty about their quality or usefulness for any particular purpose.