1001Ferramentas

🔐Security

Security tools help you protect data and understand how cryptography works: hash generators and checkers, password strength, two-factor (TOTP) codes, classic ciphers and header checks. Everything is processed locally — your passwords and files never leave the browser.

98 tools

🔐

Password Generator

Generate strong, random passwords with custom length, uppercase letters, numbers and symbols. Generated in the browser — no data leaves your device.

🔐

Encrypt Text

Apply classic ciphers (Caesar, ROT13, Atbash) or Base64. Useful for puzzles, CTFs and testing — do not use for real security.

🛡️

Password Strength Checker

Analyze the strength of any password: length, character classes, entropy in bits and resistance estimate. Processed in the browser — the password never leaves your device.

🔒

SQL Escape

Escape SQL strings by adding backslashes to single quotes and other special characters to prevent SQL injection.

🔑

Passphrase Generator

Generate strong, memorable passphrases made of random words. Easy to remember and hard to guess.

🔐

HMAC Generator

Generate HMACs (Hash-based Message Authentication Codes) with MD5, SHA-1, SHA-256, SHA-384, SHA-512 and SHA-3 algorithms.

🔐

Bcrypt Hash Generator

Generate secure bcrypt hashes from passwords and verify whether a password matches an existing bcrypt hash.

🔑

TOTP Code Generator (2FA)

Generate TOTP (Time-based One-Time Password) codes from a base32 secret, just like Google Authenticator. Useful for testing 2FA integrations without a phone.

#️⃣

File Hash (Checksum)

Calculate MD5, SHA-1, SHA-256, SHA-384 and SHA-512 of a file or text all at once. Perfect for verifying download integrity. Processed in your browser — no upload.

🗝️

RSA Key Pair Generator

Generate RSA key pairs (public and private) of 2048 or 4096 bits directly in your browser. Useful for SSH, JWT, asymmetric encryption and certificates. No data sent to servers.

🔁

ROT13 Cipher

Apply the ROT13 cipher (rotate by 13 letters) to text. Applying twice returns the original. Used in forums to hide spoilers. Only A–Z and a–z are affected. Everything in your browser.

🔂

ROT47 Cipher

Apply the ROT47 cipher (rotation across 47 printable ASCII chars 33–126). Wider than ROT13: covers numbers and symbols. Applying twice returns the original. Everything in your browser.

🪞

Atbash Cipher

Apply the Atbash cipher (A↔Z, B↔Y, C↔X...): each letter is mirrored in the alphabet. Ancient Hebrew cipher used in the Bible. Applying twice returns the original. Everything in your browser.

🗝️

Vigenère Cipher

Encrypt and decrypt text with the polyalphabetic Vigenère cipher using a keyword. More robust than Caesar by using multiple shifts. Everything in your browser.

🪙

BIP39 Mnemonic Generator

Generate BIP39 mnemonics of 12, 15, 18, 21 or 24 words (Bitcoin/Ethereum wallet standard). Words come from the official 2048-word list. Useful to test wallets. Everything in your browser.

🔏

JWT Builder (HS256)

Build a JWT by filling in header, payload and secret. HS256 signature computed in the browser via SubtleCrypto.

🔒

Content-Security-Policy Builder

Build a Content-Security-Policy header by adding directives (default-src, script-src, img-src, frame-ancestors) with predefined sources.

🔐

HIBP K-Anonymity Format

Explains the Have I Been Pwned k-anonymity flow: SHA-1 password, first 5 chars on GET, suffix returned.

🔑

Secure Token Generator

Generate cryptographically secure random tokens (alphanumeric, hex or base64) in your browser. Ideal for API keys, secrets, passwords and unique IDs.

🌐

CORS Config Validator

Validate a CORS configuration (allowed origins or *), checking the format and duplicates. Useful for safely configuring APIs and web servers.

⚠️

Mixed Content Detector

Scans http:// references inside HTML served over HTTPS, flagging insecure assets and links.

🛡️

Basic CSP Evaluator

Evaluates a Content-Security-Policy directive reporting unsafe-inline, unsafe-eval or wildcard issues.

🔒

HSTS Header Builder

Builds the Strict-Transport-Security header with max-age, includeSubDomains and preload as selected.

🔗

Referrer-Policy Builder

Builds the Referrer-Policy header from a standard value (strict-origin, no-referrer, etc.).

🛂

Permissions-Policy Builder

Builds the Permissions-Policy header from a list of feature=allowlist entries (e.g. geolocation=()).

🧱

COOP / COEP Headers Builder

Generate the COOP and COEP HTTP headers (Cross-Origin Opener/Embedder Policy) to isolate your origin. Required to safely use features like SharedArrayBuffer.

🔐

JWT Secret Strength

Measures the strength of an HMAC JWT secret: byte length, approximate entropy and rating.

🚆

Rail Fence Cipher

Encrypts messages with the Rail Fence (zigzag) cipher, spreading letters across N rails and reading rail by rail. A classic transposition cipher for learning cryptography.

🔢

Polybius Square Cipher

Encrypt and decrypt messages with the Polybius square, which turns each letter into a pair of digits on a 5×5 grid (with I and J combined).

🔐

Beaufort Cipher

Enciphers letters with the Beaufort cipher, a reciprocal Vigenere variant where each output letter is key minus plaintext mod 26, so the key also decodes.

🔺

Trifid Cipher

Encodes each letter of a message as its three coordinates in the 3x3x3 Delastelle grid, the fractionation step that the Trifid cipher is built on.

🔡

ADFGVX Cipher: Substitution Step

Encodes text on a fixed unkeyed 6x6 Polybius square of A-Z and 0-9, turning each character into its ADFGVX pair. No columnar transposition.

⚙️

Nihilist Cipher Encoder

Encodes text with the Nihilist cipher: every letter becomes its Polybius square coordinate, with I and J sharing a cell, added to a repeating numeric key.

🟦

Four-Square Cipher

Encrypts text two letters at a time using two keyword grids, with I and J sharing one cell and a trailing X padding an odd length. Encoding only.

🔑

Vernam Cipher (One-Time Pad)

XORs your text byte by byte against a key and prints the ciphertext in hex. A short key repeats, so it is a true one-time pad only if it matches the length.

🔠

Bifid Cipher with Custom Key

Encrypts text with the Bifid cipher using a 5x5 Polybius square built from your keyword, merging I and J and interleaving row and column coordinates.

Affine Cipher with Explicit Keys (a, b)

Encrypts text with E(x) = (a·x + b) mod 26, refuses any key a that shares a factor with 26, and prints the modular inverse needed to decrypt.

🔒

HSTS Header Builder

Assembles a Strict-Transport-Security header line from a max-age in seconds plus optional includeSubDomains and preload directives, ready to paste into a config.

⚠️

Public-Key-Pins (HPKP) Header Reader

Parses a Public-Key-Pins header: lists the pins, checks the base64 SHA-256 format, reads max-age and explains why HPKP was dropped and what replaced it.

🔐

Vigenère Autokey Cipher Encoder and Decoder

Enciphers or deciphers text with the classic autokey variant, where the plaintext extends the keyword instead of repeating it. Letters A to Z only.

🗝️

Columnar Transposition Cipher

Encrypts or decrypts text by writing it in rows under a keyword and reading the columns in alphabetical key order, padding the last row with X.

🏛️

Caesar Cipher Brute-Force (All 25 Shifts)

Crack a Caesar cipher by showing all 25 possible shifts at once. Great for breaking coded messages, puzzle games and studying cryptography.

🔡

Atbash Cipher Decoder

Decode and create messages in the Atbash cipher, which swaps each letter for its opposite in the alphabet (A↔Z, B↔Y). Shows the full map and the result.

🥓

Baconian Cipher, 5-Bit A/B Groups

Encodes each letter as a group of five A and B symbols in Bacon's 24-letter alphabet, where I shares a code with J and U shares one with V.

🔡

Bacon Cipher

Encodes text with the Bacon cipher, replacing each letter with a group of five As and Bs. Uses the modern 26-letter alphabet, keeping I and J apart.

🔢

Polybius Cipher

Encode text with the Polybius cipher (5x5 square, I/J merged). Each letter becomes a row/column digit pair. Useful for puzzles and classical cryptography.

🔠

A1Z26 Cipher

Converts text into numbers by each letter position in the alphabet (A=1, Z=26), separated by hyphens. A simple cipher popular in geocaching, escape rooms and logic puzzles.

🧮

Affine Cipher

Encode text with the Affine cipher using E(x) = (a·x + b) mod 26. Here uses a=5, b=8 (coprime with 26). Combines multiplicative and additive substitution.

🗝️

Keyword Cipher

Build the cipher alphabet from the keyword you choose, followed by the remaining letters. Enciphers and deciphers, and shows the generated alphabet next to the plain one.

📜

Trithemius Cipher

Polyalphabetic cipher where letter n is shifted by n positions (similar to Vigenère with key ABCDEF…). Invented by Johannes Trithemius in the 16th century.

🌐

Summarize CIDR Blocks to Supernet

Aggregate multiple IPv4 CIDR blocks into the smallest supernet that contains them all — free online tool for network admins.

🔍

Overlapping CIDR Detector

Detect overlapping or duplicate CIDR blocks in a list — useful for firewall reviews, AWS Security Groups and ACLs.

✂️

Split CIDR into N Equal Subnets

Split a CIDR block into N equal-sized subnets — a one-page visual VLSM calculator.

📏

Convert IP Range to CIDR List

Convert an IP range (start and end) into the smallest list of equivalent CIDR blocks. An essential tool for configuring firewalls, ACLs and network rules.

🛡️

IPv6 CIDR Visual Explainer

Explain an IPv6 prefix visually: hex breakdown, address count, expanded/compressed range — quick reference for SREs.

🔢

ASN Format Validator

Validate 2-byte and 4-byte ASN format (AS plain and dot notation), including reserved/private ranges — for BGP networks.

🚪

Port Knocking Sequence Generator

Generate a random TCP/UDP port sequence for port knocking — a client-side utility to configure knockd or similar.

📧

SPF Record Builder

Builds an SPF record step by step (ip4, ip6, include, mx, a, ~all, -all) and counts the terms that consume a DNS lookup, so you can compare against the limit of 10.

📨

DMARC Record Builder

Create a DMARC record with policy (none/quarantine/reject), percentage, ruf/rua mailto and SPF/DKIM alignment.

🔐

DKIM Selector Validator

Validate DKIM selector format and build the TXT record name (selector._domainkey.domain.com) for DNS.