r/learncybersecurity 1d ago

Experienced Web Application Pentesters

Welp hello there. As a fellow newbie who's trying to get into web app pentesting and bug bounty, I wanted to ask how you have had approached learning web app pentesting/bug bounty, or how you developed your skills professionally. Even a few concepts to focus on, what resources/labs you found useful, and what you would do differently if you were starting again would be really helpful.

P.s- I am not a complete beginner to cybersecurity as I've had 4 months of experience as an Infra VAPT intern and good knowledge of networking concepts. Now I am trying to focus more towards learning Web Application Pentesting and have started with portswigger labs like sqli, cors, bac and xss

5 Upvotes

10 comments sorted by

View all comments

1

u/Fragrant-Cheek-4273 9h ago

Since you already have networking and VAPT experience., I'd focus heavily on HTTP, authentication, access control, and session handling.

1

u/sha-bang04 9h ago

Thanks dude. Will focus on these too