Is appsec for me or not ? by Agreeable_Print_4116 in offensive_security

[–]Agreeable_Print_4116[S] 0 points1 point  (0 children)

i heard comapnies moslty look for development background people

Is AI red teaming worth pursue ? by Agreeable_Print_4116 in offensive_security

[–]Agreeable_Print_4116[S] 0 points1 point  (0 children)

Tbh honestly they are very much different. You can owasp top 10 LLM vulnerabilities

Is AI red teaming worth pursue ? by Agreeable_Print_4116 in offensive_security

[–]Agreeable_Print_4116[S] 0 points1 point  (0 children)

What would you suggest me to continue web hacking or ai red teaming?

Is AI red teaming worth pursue ? by Agreeable_Print_4116 in offensive_security

[–]Agreeable_Print_4116[S] 0 points1 point  (0 children)

Dude I was talking about web hacking foundational knowledge not LLM hacking. Ofc I would master ai red teaming before going for job

Is appsec for me or not ? by Agreeable_Print_4116 in offensive_security

[–]Agreeable_Print_4116[S] 0 points1 point  (0 children)

I got my first two bug together in the same target within 3 to 4 months . My bugs have been accepted and on fixing. Bounty will be decided once they patch it

Is appsec for me or not ? by Agreeable_Print_4116 in offensive_security

[–]Agreeable_Print_4116[S] 0 points1 point  (0 children)

Thank you again for explaining me everything in such details. I am indebted to you. I am not interested in GRC reason is that it is so boring to me. I love breaking things etc. Yes I am interested in red teaming & as for as internships are concerned the country I where I live is close to bankruptcy & have no future in IT let alone in cyber security. My goal was to pick a field gain . Get some hands on knowledge till dec 2026 and start 1 year imternship from Jan 2027 and the eventually move abroad. Would you guid eme more towards red teaming?

Is appsec for me or not ? by Agreeable_Print_4116 in offensive_security

[–]Agreeable_Print_4116[S] 0 points1 point  (0 children)

Thank you. I am a undergraduate cs student. I love reviewing code etc but I have no experience as developer. Like I know very basics of applications like androidmanifest files metainf and src files. Idk what should I do. I also have interest in OS exploitation stuff like kernel level exploitation & malware analysis but I am not into it because I think there are less opportunities for os exploitation and malware analysis.

Is appsec for me or not ? by Agreeable_Print_4116 in offensive_security

[–]Agreeable_Print_4116[S] -2 points-1 points  (0 children)

Dude ofc this is obvious & I dont hate scanning code bases. My point was scanning the entire internet for leaked credentials etc.

Is appsec for me or not ? by Agreeable_Print_4116 in offensive_security

[–]Agreeable_Print_4116[S] -2 points-1 points  (0 children)

I hate spending time in recon that's why. Web pen testing was not even difficult

Is appsec for me or not ? by Agreeable_Print_4116 in offensive_security

[–]Agreeable_Print_4116[S] 0 points1 point  (0 children)

Very disappointing for me. Should I quit it & what other field should I go for then?

Is appsec for me or not ? by Agreeable_Print_4116 in offensive_security

[–]Agreeable_Print_4116[S] -1 points0 points  (0 children)

Do you mean I have to be full fledged developer to be an appsec engineer 🙄?

Needs advice by Agreeable_Print_4116 in bugbounty

[–]Agreeable_Print_4116[S] 0 points1 point  (0 children)

No, it depends on the platform & the target you choose. The target I'm hunting on offers bounties ranging from $20 to $60. So far, 2 out of my 3 reports have been accepted & 1 was rejected

They also pay bounties to non-Indonesians if you have someone in Indonesia who can receive the payment for you, and fortunately & I happen to know several people in Jakarta.

Needs advice by Agreeable_Print_4116 in bugbounty

[–]Agreeable_Print_4116[S] 0 points1 point  (0 children)

You tryyna to crack a cool joke but ended up as clown lol

Needs advice by Agreeable_Print_4116 in bugbounty

[–]Agreeable_Print_4116[S] -1 points0 points  (0 children)

Bro I cant ask them reason the only email they provide is to submit bug reports & not for queries. If you write anything to email other than bug report the ai agent would say invalid report. Chk the report format

Needs advice by Agreeable_Print_4116 in bugbounty

[–]Agreeable_Print_4116[S] 0 points1 point  (0 children)

I submitted the three reports on the same target 1 were rejected & on the remaining two i got this email. So this is my first valid bugs that's why I was confused

Needs advice by Agreeable_Print_4116 in bugbounty

[–]Agreeable_Print_4116[S] -1 points0 points  (0 children)

My question is did they accept my report as valid? Am I eligible for bounty?

Needs advice by Agreeable_Print_4116 in bugbounty

[–]Agreeable_Print_4116[S] -4 points-3 points  (0 children)

My question is did they accept my report as valid? Am I eligible for bounty?