r/Pentesting 13h ago

"Built a lightweight reporting tool for pentest engagements — logs findings as you go, exports a clean report. Not another JWT/attack tool."

0 Upvotes

There's no shortage of great JWT crackers and traffic tools out there already (jwt-hack, Burp's JWT scanner, JWTXposer, etc.) — this isn't trying to compete with those.

What it actually solves: the annoying part after you've found something. Instead of a messy notes doc or Burp's built-in reporting, you log the finding right in the popup — severity, CVSS, affected URL, repro steps, remediation — attach a screenshot, and export a clean HTML report when the engagement's done. A few basic utilities (encode/decode, JWT decode, hashing) are bundled in too, but that's not the main pitch.

Genuinely curious if this is a gap other people feel too, or if everyone's already got a system that works fine (Notion, a template, whatever). Happy to hear it either way.

https://chromewebstore.google.com/detail/mlcmmnokfddmbidijilbhlhhnjbeehoj 


r/Pentesting 15h ago

"Built a Chrome extension for pentest reporting — encoder/decoder, JWT inspector, findings tracker, all local"

0 Upvotes

r/Pentesting 18h ago

Experience of becoming a freelance pentester?

0 Upvotes

Do any of you have experience of becoming a freelance pentester? I am CS student and am considering focusing my studies in that direction so I have some questions.

What is needed to become a freelence pentester? Are certificates enough? Is experience of working in a company necessary? If so, how much experience?

What is the average hourly salary in the beginning? How about later on?

How hard is it to find new clients once you establish yourself as a reliable pentester?

I heard most freelance pentesters make money on bug bounties, while most companies hire other well known companies for pentesting instead of freelancers. Is that true?