Skip to content
Match inside encoded content

Match inside encoded content

Match inside encoded content

Find tokens by what they encode: a JWT by its decoded header and claims, a base64 blob by the text or the entropy of what it decodes to. Nothing is verified; a JWT’s signature is not checked. Every form is on decoded content.

A JWT that turns signing off

\{jwt}{alg:none} is a JWT whose decoded header names no algorithm:

$ trex scan '\{jwt}{alg:none}' --text 'auth eyJhbGciOiJub25lIn0.eyJzdWIiOiIxMjMiLCJleHAiOjE3ODk0MzA0MDB9.sig ok'
[5..69] "eyJhbGciOiJub25lIn0.eyJzdWIiOiIxMjMiLCJleHAiOjE3ODk0MzA0MDB9.sig"

A claim is named the same way, \{jwt}{role:admin}, and an expiry compares with the clock, \{jwt}{exp<now}.

A key hidden in base64

\{base64}{text:*BEGIN*} is a blob whose decoded text holds BEGIN, and \{base64}{bits>4.5} one whose decoded bytes carry more than 4.5 bits of entropy a byte:

$ trex scan '\{base64}{text:*BEGIN*}' --text 'key LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQ== blob AAECAwQFBgcICQoLDA0ODxAREhMUFRYXGBkaGxwd end'
[4..48] "LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQ=="

$ trex scan '\{base64}{bits>4.5}' --text 'key LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQ== blob AAECAwQFBgcICQoLDA0ODxAREhMUFRYXGBkaGxwd end'
[54..94] "AAECAwQFBgcICQoLDA0ODxAREhMUFRYXGBkaGxwd"

\{base64}{match:name} runs a sub-pattern you declared over the decoded bytes.