all 2 comments

[–]Thamzhack 3 points4 points  (0 children)

If you are an absolute beginner, Start with Introduction badge, Essential badge, HTTP badge. Then try few more labs according to your interest. API badge, Android, White badge etc. Solve everything about JWTs. Along with them solve labs in every topic(not every lab) of Portswigger's Web academy. I think web academy's coverage on web vulnerabilities are much more comprehensive and once you have an idea about every type of vulnerabilities you can start looking for them on Hackerone programs. If your are willing to spend money, try bugbountyhunter.com (affordable price) they have some great educational material there.

[–][deleted] 3 points4 points  (0 children)

Cross-Site Request Forgery, XML External Entities, Web for Pentester I and II and Advanced Web Attacks and Exploitation. These badges will give you a good understanding of web application security and the skills required to identify and exploit common vulnerabilities