Identification and reporting of bugs and vulnerability in a responsible way.
All depends on your interest and hardwork, not on degree, age, branch, college, etc.

What to study?
1. Web, HTTP, TCP/IP
2. Systems administration
3. Order line
4. Linux
5. Web innovations, javascript, php, java
6. Atleast 1 prog language (Python/C/JAVA/Ruby..)
Choose your path (Important)
1. Web pentesting
2. Versatile pentesting
3. Work area applications
Resources
» Books
For web
1. Web application programmers handbook
2. Web hacking 101
3. Programmer's playbook 1,2,3
4. Hacking specialty of misuse
5. Dominating current web pen testing
6. OWASP Testing guide
For Mobile
1. Mobile application programmer's handbook
» Youtube channels
Hacking
1. Live Overflow
2. Hackersploit
3. Bugcrowd
4. Hak5
5. Hackerone
Programming
1. thenewboston
2. codeacademy
» Writeups, Articles and blogs
1. Medium (infosec writeups)
2. Hackerone public reports
3. owasp.org
4. Portswigger
5. Reddit (Netsec)
6. DEFCON gathering recordings
7. Discussions
Practice (important)
Tools
1. Burpsuite
2. nmap
3. dirbuster
4. sublist3r
5. Netcat
Testing labs
1. DVWA
2. bWAPP
3. Vulnhub
4. Metasploitable
5. CTF365
6. Hack the container
Start!
Select a platform
1. Hackerone
2. Bugcrowd
3. Open bug abundance
4. Zerocopter
5. Antihack
6. Synack (private)
• Pick astutely (first not for abundance)
• Select a bug for chase
• Thorough inquiry
• Not direct consistently
REPORT:
• Make an elucidating report
• Follow mindful exposure
• Make POC and steps to replicate
0 Comments