This extension help test PeopleSoft SSO tokens. The features are:
- Extracts and displays token information based on the decompressed data
- Generates the Hashcat format - to perform brute-force/dictionary attacks in order to obtain the local node password
- Generates a new PSTOKEN value that can be used in order to authenticate as another user (requires knowledge of the local node password)
This is a re-implementation of the TokenChpoken (https://erpscan.com/press-center/blog/peoplesoft-security-part-4-peoplesoft-pentest-using-tokenchpoken-tool/ - link is down) Tool developed by ERPScan.