this post was submitted on 22 Mar 2025
41 points (97.7% liked)
Asklemmy
46747 readers
1370 users here now
A loosely moderated place to ask open-ended questions
Search asklemmy ๐
If your post meets the following criteria, it's welcome here!
- Open-ended question
- Not offensive: at this point, we do not have the bandwidth to moderate overtly political discussions. Assume best intent and be excellent to each other.
- Not regarding using or support for Lemmy: context, see the list of support communities and tools for finding communities below
- Not ad nauseam inducing: please make sure it is a question that would be new to most members
- An actual topic of discussion
Looking for support?
Looking for a community?
- Lemmyverse: community search
- sub.rehab: maps old subreddits to fediverse options, marks official as such
- !lemmy411@lemmy.ca: a community for finding communities
~Icon~ ~by~ ~@Double_A@discuss.tchncs.de~
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Web application pentesting.
There are heaps of free resources, a company known as PortSwigger who make one of the most used applications, Burp Suite, offer heaps of free learning paths and tutorials to get you familiar with the skills needed to learn how to do this.
There are then heaps of free bug bounty programs which you can sign up to which allow you to start attempting to find vulnerabilities in web applications for companies which are enrolled with these programs.
I'm not gonna lie and say this is an easy skill to learn but it can definitely be rewarding even with some basic knowledge.
If you have relevant links which you have found specifically useful, or otherwise links in reference to the above, I would be interested in taking a look. Thanks.
Burp Suite academy learning, all free with interactive labs, you only need to download and install the community version of the application. https://portswigger.net/web-security/learning-paths
Rhana Khalil also has a lot of guides on these labs if you're someone who learns best by watching others. https://www.youtube.com/channel/UCKaK-XPQAbznwIISC46b1oA
NahamSec is another big figure in the bug bounty community who often puts out helpful content for new comers. https://www.youtube.com/channel/UCCZDt7MuC3Hzs6IH4xODLBw
Beautiful, thank you!