β What's New
π Authentication Bypass Tester Module
Professional authentication security testing with 5 attack categories:
Core Capabilities:
1. Default Credentials Testing
- 20 common username/password combinations
- Includes: admin:admin, root:root, administrator, guest, etc.
- Automatic success detection
- CRITICAL severity classification
2. Session Fixation
- Tests pre-set session ID acceptance
- Session regeneration validation
- HIGH severity vulnerabilities
3. Cookie Manipulation
- 8 bypass techniques:
- admin=true, isAdmin=1
- role=admin, user_type=admin
- authenticated=true, logged_in=1
- auth=1, is_authenticated=true
- HIGH severity classification
4. JWT Token Manipulation
- None Algorithm Attack (signature removal)
- Role manipulation (elevate to admin)
- User ID tampering
- CRITICAL severity vulnerabilities
5. Password Reset Testing
- Token reusability
- Predictable token detection
- Empty token bypass
- CRITICAL severity
Key Features:
- π― 30+ attack techniques across 5 categories
- π Selective test execution
- π Severity-based classification
- β‘ Real-time progress tracking
- π Detailed vulnerability reports
- πΎ JSON and CSV export
π§ Configuration
{
"authBypass": {
"targetUrl": "https://example.com/login",
"passwordResetUrl": "https://example.com/reset-password",
"jwtToken": "",
"tests": ["all"],
"delay": 500,
"useProxy": false
}
}Test Options:
"all"- Run all tests"default_credentials"- Default creds only"session_fixation"- Session testing only"cookie_manipulation"- Cookie bypass only"jwt_manipulation"- JWT testing only"password_reset"- Reset vulnerabilities only
π Example Output
π Authentication Bypass Tester Started
================================================================
Target: https://example.com/login
Tests: all
π Testing Default Credentials...
β VULNERABLE: admin:admin - Status: 200
β VULNERABLE: root:root - Status: 200
π Testing Session Fixation...
β VULNERABLE: Session ID not regenerated
π Testing Cookie Manipulation...
β VULNERABLE: admin=true
π Testing JWT Token Manipulation...
β VULNERABLE: None Algorithm
π Authentication Bypass Summary
================================================================
β οΈ Total Vulnerabilities: 5
defaultCredentials:
β’ DEFAULT_CREDENTIALS (CRITICAL)
sessionFixation:
β’ SESSION_FIXATION (HIGH)
cookieManipulation:
β’ COOKIE_MANIPULATION (HIGH)
jwtManipulation:
β’ JWT_MANIPULATION (CRITICAL)
Time elapsed: 12.34s
π‘ Use Cases
- Penetration Testing: Identify auth weaknesses
- Security Audits: Validate authentication mechanisms
- Bug Bounty: Find authentication bypasses
- Compliance: Meet security testing requirements
- DevOps: Integrate into CI/CD pipelines
π¦ Complete Feature Set (14 Modules)
- Smart Brute Force
- Password Generator
- Rate Limit Checker
- Wordlist Optimizer
- API Fuzzer
- SQL Injection Tester
- DDoS Tester
- JWT Analyzer
- Header Injection Tester
- WebSocket Security Tester
- Subdomain Enumerator
- Multi-Target Campaign Manager
- SSL/TLS Analyzer
- Authentication Bypass Tester β NEW!
π Installation & Upgrade
New Installation:
git clone https://github.com/PicoBaz/NexusBrute.git
cd NexusBrute
npm install axios chalk ws
node index.jsUpgrade from v2.5.0:
git pull origin mainAdd to config.json:
{
"authBypass": {
"targetUrl": "https://example.com/login",
"tests": ["all"]
}
}π What It Detects
CRITICAL:
- Default credentials acceptance
- JWT None Algorithm bypass
- Password reset token issues
HIGH:
- Session fixation vulnerabilities
- Cookie-based authentication bypass
Attack Techniques:
- 20 default credential combinations
- 8 cookie manipulation methods
- 3 JWT manipulation attacks
- Session regeneration testing
- Password reset exploitation
π Benefits
- β‘ Fast Testing: 30+ techniques in seconds
- π― Comprehensive: Covers all major auth vulnerabilities
- π Detailed Reports: JSON/CSV with severity levels
- π Best Practices: Aligned with OWASP standards
- πΎ Automation Ready: Perfect for CI/CD
β οΈ Legal Notice
FOR AUTHORIZED TESTING ONLY. Obtain explicit permission before testing.
π Contact
- GitHub: @PicoBaz
- Email: picobaz3@gmail.com
- Telegram: @picobaz
Full Changelog: v2.5.0...v2.6.0
Use Responsibly. Test Ethically. Secure Everything. π
Made with β€οΈ by @PicoBaz