🔐 Authentication & Session Testing

This category focuses on tools designed to brute-force web login protocols, dissect and forge JSON Web Tokens (JWT), and map out OAuth authorization flaws.

Tool Catalog

🐉

Hydra

A very fast network logon cracker supporting multiple authentication protocols (HTTP, SSH, FTP, Telnet).

🏛️

Medusa

Speedy, parallel login brute forcer engine supporting modular protocols.

🔑

jwt_tool

Toolkit for auditing and exploiting JSON Web Tokens (including signature validation bypasses, None algorithm forgery, and key confusion).

💎

Burp Suite Intruder / Authz

Automated request replay plugins designed to test authentication rate-limiting and authorization boundary violations.


🔗 Back to Toolkit