Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
badsecrets — A library for detecting known secrets across many web frameworks | Kitploit
Tools/GitHubGitHub/blacklanternsecurity/badsecrets
Vulnerability AnalysisWeb SecurityCryptographyPenetration TestingSecret Detection
GitHubblacklanternsecurity/badsecrets

badsecrets

A library for detecting known secrets across many web frameworks

View Repository
81784243 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

badsecrets

Ruff License Tests codecov Pypi Downloads

A pure python library for identifying the use of known or very weak cryptographic secrets across a variety of platforms. The project is designed to be both a repository of various "known secrets" (for example, ASP.NET machine keys found in examples in tutorials), and to provide a language-agnostic abstraction layer for identifying their use.

Knowing when a 'bad secret' was used is usually a matter of examining some cryptographic product in which the secret was used: for example, a cookie which is signed with a keyed hashing algorithm. Things can get complicated when you dive into the individual implementation oddities each platform provides, which this library aims to alleviate.

Check out our full blog post on the Black Lantern Security blog!

Inspired by Blacklist3r, with a desire to expand on the supported platforms and remove language and operating system dependencies.

Current Modules

Passive Modules

Passive modules analyze cryptographic products (cookies, tokens, signed URLs, etc.) that you already have. They work offline by attempting to decrypt or verify the product against a database of known secrets.

NameDescription
ASPNET_ViewstateChecks the viewstate/generator against a list of known machine keys.
ASPNET_ResourceChecks WebResource.axd and ScriptResource.axd encrypted URLs against a list of known machine keys. Useful when __VIEWSTATE is not present on a page.
Telerik_HashKeyChecks patched (2017+) versions of Telerik UI for a known Telerik.Upload.ConfigurationHashKey
Telerik_EncryptionKeyChecks patched (2017+) versions of Telerik UI for a known Telerik.Web.UI.DialogParametersEncryptionKey
Flask_SignedCookiesChecks for weak Flask cookie signing password. Wrapper for flask-unsign
Peoplesoft_PSTokenCan check a peoplesoft PS_TOKEN for a bad/weak signing password
Django_SignedCookiesChecks django's session cookies (when in signed_cookie mode) for known django secret_key
Rails_SecretKeyBaseChecks Ruby on Rails signed or encrypted session cookies (from multiple major releases) for known secret_key_base
Generic_JWTChecks JWTs for known HMAC secrets or RSA private keys
Jsf_viewstateChecks Both Mojarra and Myfaces implimentations of Java Server Faces (JSF) for use of known or weak secret keys
Symfony_SignedURLChecks symfony "_fragment" urls for known HMAC key. Operates on Full URL, including hash
Express_SignedCookies_ESChecks express.js express-session middleware for signed cookies and session cookies for known 'session secret'
Express_SignedCookies_CSChecks express.js cookie-session middleware for signed cookies and session cookies for known secret
Laravel_SignedCookiesChecks 'laravel_session' cookies for known laravel 'APP_KEY'
ASPNET_CompressedviewstateChecks for a once popular custom compressed Viewstate code snippet vulnerable to RCE
Rack2_SignedCookiesChecks Rack 2.x signed cookies for known secret keys
Yii2_SignedCookiesChecks Yii2 framework signed cookies for known cookie validation keys
Shiro_RememberMeChecks Apache Shiro rememberMe cookies for known AES encryption keys
LTPA_TokenChecks IBM WebSphere LtpaToken and LtpaToken2 cookies for known LTPA encryption keys

Active Modules

Active modules go a step beyond passive detection. They use YARA-based prefiltering to fingerprint a live target (based on HTTP response headers, cookies, and body content), then forge cryptographic products with known keys and send them to the target to confirm whether the key is accepted. This makes them useful for cases where you don't already have a token to analyze but suspect the target may be using default or well-known secrets.

Active modules are enabled by default in URL mode (--url). Use --passive-only to disable them.

NameDescription
Shiro_RememberMe_KeyForges Apache Shiro rememberMe cookies with known AES keys and tests if the target accepts them (deserialization RCE)
GlobalProtect_DefaultMasterKeyTests PAN-OS GlobalProtect portals for use of the default master encryption key
LTPA_Token_KeyForges IBM WebSphere LtpaToken2 cookies with known LTPA keys and tests if the target grants authentication (auth bypass)

Installation

We have a pypi package, so you can just do pip install badsecrets to make use of the library.

Simple Usage

The best way to use Badsecrets is by simply running badsecrets after doing a pip install:

pip install badsecrets
badsecrets eyJhbGciOiJIUzI1NiJ9.eyJJc3N1ZXIiOiJJc3N1ZXIiLCJVc2VybmFtZSI6IkJhZFNlY3JldHMiLCJleHAiOjE1OTMxMzM0ODMsImlhdCI6MTQ2NjkwMzA4M30.ovqRikAo_0kKJ0GVrAwQlezymxrLGjcEiW_s3UJMMCo

Under the hood, it's using the cli.py example. The CLI can also be accessed manually without a pip installation:

Without pip installation:

git clone https://github.com/blacklanternsecurity/badsecrets.git
cd badsecrets
python ./badsecrets/examples/cli.py eyJhbGciOiJIUzI1NiJ9.eyJJc3N1ZXIiOiJJc3N1ZXIiLCJVc2VybmFtZSI6IkJhZFNlY3JldHMiLCJleHAiOjE1OTMxMzM0ODMsImlhdCI6MTQ2NjkwMzA4M30.ovqRikAo_0kKJ0GVrAwQlezymxrLGjcEiW_s3UJMMCo

Examples

To use the examples, after doing the pip install just git clone the repo and cd into the badsecrets directory:

git clone https://github.com/blacklanternsecurity/badsecrets.git
cd badsecrets

The commands in the example section below assume you are in this directory.

If you are using the Badsecrets BBOT module, you don't need to do anything else - BBOT will install the package for you.

cli.py

Bad secrets includes an example CLI for convenience when manually checking secrets. As mentioned above, it is also accessible by just executing badsecrets, after a successful pip install.

Usage

usage: badsecrets [-h] [-nc] [-j] [-u URL] [-nh] [-c FILE_OR_MODULE:KEYS]
                  [-p PROXY] [-a USER_AGENT] [-H HEADER] [-d] [-t TIMEOUT]
                  [-P] [-l]
                  [product ...]

Check cryptographic products against badsecrets library

positional arguments:
  product               Cryptographic product to check for known secrets
Download Tool