Match inside encoded content
Match inside encoded content
Find tokens by what they encode: a JWT by its decoded header and claims, a base64 blob by the text or the entropy of what it decodes to. Nothing is verified; a JWT’s signature is not checked. Every form is on decoded content.
A JWT that turns signing off
\{jwt}{alg:none} is a JWT whose decoded header names no algorithm:
$ trex scan '\{jwt}{alg:none}' --text 'auth eyJhbGciOiJub25lIn0.eyJzdWIiOiIxMjMiLCJleHAiOjE3ODk0MzA0MDB9.sig ok'
[5..69] "eyJhbGciOiJub25lIn0.eyJzdWIiOiIxMjMiLCJleHAiOjE3ODk0MzA0MDB9.sig"
A claim is named the same way, \{jwt}{role:admin}, and an expiry compares with the clock,
\{jwt}{exp<now}.
A key hidden in base64
\{base64}{text:*BEGIN*} is a blob whose decoded text holds BEGIN, and \{base64}{bits>4.5} one
whose decoded bytes carry more than 4.5 bits of entropy a byte:
$ trex scan '\{base64}{text:*BEGIN*}' --text 'key LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQ== blob AAECAwQFBgcICQoLDA0ODxAREhMUFRYXGBkaGxwd end'
[4..48] "LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQ=="
$ trex scan '\{base64}{bits>4.5}' --text 'key LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQ== blob AAECAwQFBgcICQoLDA0ODxAREhMUFRYXGBkaGxwd end'
[54..94] "AAECAwQFBgcICQoLDA0ODxAREhMUFRYXGBkaGxwd"
\{base64}{match:name} runs a sub-pattern you declared over the decoded bytes.