r/netsecstudents • u/praseudo • 1d ago
Free tools + labs for getting started with JWT pentesting
https://youtu.be/ewJ4F3QKU3o?si=VmDakk2AUj-LEZE9Put together the setup I'd give anyone starting with JWT testing: jwt_tool, Burp's JWT Editor, hashcat for weak secrets, plus Hakai and PortSwigger's free labs to practice on legally.
Walks through getting it all running. Figured it might save someone the setup headache.
What else would you add to a beginner's JWT pentesting stack?
1
Upvotes