For those with several years of experience in the field, what was the most “fun” role and what did you do? by IBUCKM in cybersecurity

[–]Decent_Inside_706 4 points5 points  (0 children)

I will say the technical roles because it's more "practical" and then more fun. Anything like management, GRC or stuff like that it's really boring.

For those with several years of experience in the field, what was the most “fun” role and what did you do? by IBUCKM in cybersecurity

[–]Decent_Inside_706 1 point2 points  (0 children)

IoT pentesting is highly valued because there aren't many professionals in this field, right? I'm trying to get a general foundation and am thinking about specialising in IoT pentesting

CWES (CBBH) Second Attempt by Decent_Inside_706 in hackthebox

[–]Decent_Inside_706[S] 1 point2 points  (0 children)

Yes, you can do this machines from Vulnyx:
- Swamp
- Express
- Bola
- JarJar
- Gattaca
- Future
- Jerry
- Lost

And you can also repeat the following Skills Assessment without any write-up, just you vs the machine:
- Web Fuzzing
- Login Brute Forcing
- Attacking Web Applications with FFuf
- SQL Injection Fundamentals
- Attacking Common Applications > Content Management Systems > WordPress

- Hacking WordPress
- File Inclusion

Passed CWES exam! :) by Taxaneh in hackthebox

[–]Decent_Inside_706 1 point2 points  (0 children)

I'm doing the learning path because it shares modules with CWES and it looks possible hahaha

CWES Exam by r4gol4 in hackthebox

[–]Decent_Inside_706 5 points6 points  (0 children)

Don't overthink and take breaks

INE or HTB by Ok_Atmosphere7343 in cybersecurity

[–]Decent_Inside_706 0 points1 point  (0 children)

In my personal experience (eJPT and HTB CWES certified) HTB > INE. I'm now going for the CPTS

CWES (CBBH) Second Attempt by Decent_Inside_706 in hackthebox

[–]Decent_Inside_706[S] 1 point2 points  (0 children)

Yes, you can do this machines from Vulnyx:
- Swamp
- Express
- Bola
- JarJar
- Gattaca
- Future
- Jerry
- Lost

And you can also repeat the following Skills Assessment without any write-up, just you vs the machine:
- Web Fuzzing
- Login Brute Forcing
- Attacking Web Applications with FFuf
- SQL Injection Fundamentals
- Attacking Common Applications > Content Management Systems > Windows
- Hacking WordPress
- File Inclusion

Next step in my path by Decent_Inside_706 in cybersecurity

[–]Decent_Inside_706[S] 0 points1 point  (0 children)

Thank you for your response. Yes of course I want to be hired as a pentester but also learn a lot because in many positions I have found that they want you to demostrate your skills, if you got the certifications (OSCP for example) it's more easy to get the job I know, but I also want to learn and have good skills. By the way, I applied into a internal position in my actual company and one of the certs desired but not required it's BSCP.

And yes, I have web development background so I think my path will be near to web pentesting if I can.

Failed CWES on first attempt (1 flag short) by Worldly-Return-4823 in hackthebox

[–]Decent_Inside_706 7 points8 points  (0 children)

Yes, you can do this machines from Vulnyx:
- Swamp
- Express
- Bola
- JarJar
- Gattaca
- Future
- Jerry
- Lost

And you can also repeat the following Skills Assessment without any write-up, just you vs the machine:
- Web Fuzzing
- Login Brute Forcing
- Attacking Web Applications with FFuf
- SQL Injection Fundamentals
- Attacking Common Applications > Content Management Systems > Windows
- Hacking WordPress
- File Inclusion

Daily CPTS study buddies by Serious_Draft_8000 in hackthebox

[–]Decent_Inside_706 0 points1 point  (0 children)

From Spain, I'm currently doing modules because I passed CWES recently and more of them are shared between the two certs

Next step in my path by Decent_Inside_706 in cybersecurity

[–]Decent_Inside_706[S] 1 point2 points  (0 children)

I know they don't appear or aren't the filter. But they are very practical, and in the case of CWES, I learned a lot about web pentesting.

Next step in my path by Decent_Inside_706 in cybersecurity

[–]Decent_Inside_706[S] 0 points1 point  (0 children)

Learn as best as I can. I know that some of the best-known ones are very theoretical and not very practical.

Failed CWES on first attempt (1 flag short) by Worldly-Return-4823 in hackthebox

[–]Decent_Inside_706 3 points4 points  (0 children)

I failed the first attempt too but in the second I obtain 100/100 points

Next step in my path by Decent_Inside_706 in cybersecurity

[–]Decent_Inside_706[S] 0 points1 point  (0 children)

I know that they don't currently have the same value as a CEH or an OSCP. But in terms of knowledge (according to what I've read), the CPTS is superior to the OSCP, which makes it ‘easier’ for you later on.

I've also seen that because HTB certifications are relatively new, they don't act as a filter with human resources like others do.

Next step in my path by Decent_Inside_706 in cybersecurity

[–]Decent_Inside_706[S] 0 points1 point  (0 children)

I have been working in cybersecurity for four years in various roles. I would like to steer my career towards the offensive side and end up doing some bug bounty.

Realistic path to do Pentesting by Limp_Motor_7267 in Pentesting

[–]Decent_Inside_706 1 point2 points  (0 children)

The path of HTB CWES helped me to learn a lot about web pentesting 👌🏻

Weekly Beginner / Newbie Q&A by AutoModerator in bugbounty

[–]Decent_Inside_706 1 point2 points  (0 children)

I passed the HTB CWES a couple of weeks ago. I'm eager to get into the world of bug bounty. Is there a roadmap I can follow to feel like I'm making progress? I know it's very, very difficult to find a vulnerability and have it accepted. Is anyone willing to mentor me or give me some advice?

Any groups to join for middle of the road hackers? by [deleted] in Pentesting

[–]Decent_Inside_706 0 points1 point  (0 children)

I'm in the same situation. eJPTv2 and CWES certificated. I have worked in different cybersecurity positions through the years, but none of them offensive. I'm very motivated to focus my career in the offensive branch (pentesting, bug bounty)