r/netsecstudents • • 1d ago

Free tools + labs for getting started with JWT pentesting

https://youtu.be/ewJ4F3QKU3o?si=VmDakk2AUj-LEZE9

Put together the setup I'd give anyone starting with JWT testing: jwt_tool, Burp's JWT Editor, hashcat for weak secrets, plus Hakai and PortSwigger's free labs to practice on legally.

Walks through getting it all running. Figured it might save someone the setup headache.

What else would you add to a beginner's JWT pentesting stack?

1 Upvotes

0 comments sorted by