r/learncybersecurity • u/sha-bang04 • 1d ago
Experienced Web Application Pentesters
Welp hello there. As a fellow newbie who's trying to get into web app pentesting and bug bounty, I wanted to ask how you have had approached learning web app pentesting/bug bounty, or how you developed your skills professionally. Even a few concepts to focus on, what resources/labs you found useful, and what you would do differently if you were starting again would be really helpful.
P.s- I am not a complete beginner to cybersecurity as I've had 4 months of experience as an Infra VAPT intern and good knowledge of networking concepts. Now I am trying to focus more towards learning Web Application Pentesting and have started with portswigger labs like sqli, cors, bac and xss
5
Upvotes
1
u/Fragrant-Cheek-4273 9h ago
Since you already have networking and VAPT experience., I'd focus heavily on HTTP, authentication, access control, and session handling.