@selfpentest/notpasswdstrength
v1.1.2
Published
An example package for training oneself that pretends to be a password strength meter, but then also _pretends_ to send the password off to a hacker
Readme
notpasswordstrength

⚠️ Not intended for actual use.
You can use this package to pentest your own applications to see if they are vulnerable to supply chain attacks.
An example package for training that pretends to be a password strength meter, but then also pretends to send the password off to a hacker.
- version 1.0.0 is innocent
- version 1.1.0 is pretending to steal the password by sending a request to example.com but it doesn't actually even capture the password passed to it.
pretended usage
const { checkPasswordStrengthIncorrectly } = require('@selfpentest/notpasswordstrength');
const result = checkPasswordStrengthIncorrectly('password123');
console.log(result); When used, it will demonstrate exfiltrating the password to a server listening on http://localhost:1337/
Use npx @selfpentest/demo-cc to run the local HTTP server that will receive and display the demonstration payload.
Intent
This package is not a hacking tool. It lets the developer check if their setup is vulnerable and can be used for security demonstrations.
