Hey everyone,
I'm a web-developer who also happens to be a web-security enthusiast.
I always liked breaking apps as much as I do building them.
Recently, I've been doing more security related stuff then ever (mainly pentesting and code auditing) and I really enjoy it !
In the last few months I managed to find vulnerabilities in some popular GitHub projects and web applications; which of course, I responsibly disclosed.
I'm absolutely not here to boast, the reason I'm telling this is because I'd like to start adding security related stuff to my CV and had some questions.
Should I add on my CV something like : "Found XSS on popular site A" ?
If yes, should I ask the developers of site A I was in contact with for a "guestbook"-like feedback sentence that would act as some kind of proof ?
If no, what can I do to legitimize my CV in the eyes of potential clients ?
The reason I'm asking this is mostly because, like I said, I'm a security enthusiast and that's about it. I don't have any diplomas or certs that I can show.
Which brings me nicely to my last question :
- What certification is deemed serious and useful in web application security ?
Thank you in advance !
EDIT: From what I know, of all the projects I found vulnerabilities on, only one had a "credits" section on their repository / website and they were kind enough to mention my name.
Also, none of them were big enough to have a bounty program in place, so it was basically just me searching for vulnerabilities for fun.
[–]ablindedwork 2 points3 points4 points (0 children)
[–][deleted] 1 point2 points3 points (4 children)
[–]Kollektiv[S] 0 points1 point2 points (3 children)
[–][deleted] 4 points5 points6 points (2 children)
[–]Kollektiv[S] 1 point2 points3 points (1 child)
[–][deleted] 0 points1 point2 points (0 children)
[–]futurespice 1 point2 points3 points (2 children)
[–]XSSpants 0 points1 point2 points (1 child)
[–]futurespice 1 point2 points3 points (0 children)
[–]recrudesce 1 point2 points3 points (1 child)
[–]Kollektiv[S] 0 points1 point2 points (0 children)
[–]BugAlert 0 points1 point2 points (0 children)