Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

1.8 KiB

API Reference: Testing API Authentication Weaknesses

JWT Security Checks

Check Severity Description
alg:none Critical Signature verification bypassed
Weak HMAC secret Critical Brute-forceable signing key
No exp claim High Token never expires
Long TTL (>24h) Medium Extended token validity
Sensitive data in payload High PII in JWT claims
Missing iss/aud claims Medium Token scope ambiguity

OWASP API2:2023 Test Points

Test Category
Unauthenticated endpoint access Missing auth middleware
JWT alg:none bypass Broken token validation
JWT secret brute-force Weak cryptographic key
Token reuse after logout Missing revocation
Refresh token rotation Session management
Account enumeration Information disclosure
Password policy bypass Weak credential controls

Common JWT HMAC Secrets

Secret Type
secret Default
your-256-bit-secret JWT.io example
jwt_secret Convention
changeme Placeholder

JWT Attack Tools

Tool Purpose
jwt_tool JWT testing with 12+ attack modes
hashcat -m 16500 GPU JWT secret brute-force
Burp JWT Editor Interactive JWT manipulation
Nuclei Auth bypass templates

Python Libraries

Library Version Purpose
requests >=2.28 HTTP API calls
base64 stdlib JWT decoding
hmac stdlib HMAC signature testing
hashlib stdlib Hash functions

References