hahwul/jwt-hack

Unloaded wordlist file on snapcraft version

hahwul opened this issue · 4 comments

similar issue
hahwul/dalfox#134

before

$ jwt-hack version
v1.0.2

$ jwt-hack crack eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.5mhBHqs5_DTLdINd9p5m7ZJ6XD0Xc55kIaCRY5r6HRA -w ./samples/wordlist.txt
[*] Start dict cracking mode
INFO[0000] Loaded words (remove duplicated)              size=0
[+] Finish crack mode

upgrade patch version

$ sudo snap refresh jwt-hack

after

$ jwt-hack version
v1.0.3

$ jwt-hack crack eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.5mhBHqs5_DTLdINd9p5m7ZJ6XD0Xc55kIaCRY5r6HRA -w ./samples/wordlist.txt
[*] Start dict cracking mode
INFO[0000] Loaded words (remove duplicated)              size=16
INFO[0000] Invalid signature                             word=ds
INFO[0000] Invalid signature                             word=fas
INFO[0000] Invalid signature                             word=dfas
INFO[0000] Found! Token signature secret is test         Signature=Verified Word=test
INFO[0000] Invalid signature                             word=sadf
INFO[0000] Invalid signature                             word=df
INFO[0000] Invalid signature                             word=asdf
INFO[0000] Invalid signature                             word=efq
INFO[0000] Invalid signature                             word=1234
INFO[0000] Invalid signature                             word=qsf
INFO[0000] Invalid signature                             word=sad
INFO[0000] Invalid signature                             word=f
INFO[0000] Invalid signature                             word=asd
INFO[0000] Invalid signature                             word=zx
[+] Found! JWT signature secret: test
[+] Finish crack mode