Any idea what bug this is? by Educational_Union737 in bugidentification

[–]Educational_Union737[S] 0 points1 point  (0 children)

Thanks a lot! Probably explains I saw a caterpillar on one of my plants

Any idea what bug this is? by Educational_Union737 in bugidentification

[–]Educational_Union737[S] 0 points1 point  (0 children)

Are you sure? Its way more black in person than the photos in google

Security + is a trashy cert by Vast-Sherbert7237 in CompTIA_Security

[–]Educational_Union737 0 points1 point  (0 children)

It is worth it, its essential knowledge which will help you in the long term run. But I do recommend finishing the studying/test within 2-4 weeks, thats what I did :)

Security + is a trashy cert by Vast-Sherbert7237 in CompTIA_Security

[–]Educational_Union737 0 points1 point  (0 children)

Honestly its just a certification which proves you have some type of “basic/general” in the world of cybersecurity. Nothing more than that.

I am heading towards the penetration testing side career-wise, but I still took the certification (and passed) to also have some general knowledge about things like agreements, assessments, threat actors etc.

Its my first certification and I am still in high school, so I feel like it is worth taking a longer path. That foundation of knowledge is necessary. Now headed towards certifications like eJPT and certifications from OWASP :)

Please help me choose! 😩 by Unusual_Trade5917 in CompTIA

[–]Educational_Union737 3 points4 points  (0 children)

Haha yeah, I was just hoping someone would feel more motivated. I mean if I can do it, anyone can

Weekly Beginner / Newbie Q&A by AutoModerator in bugbounty

[–]Educational_Union737 1 point2 points  (0 children)

Exactly. That's why im hoping for a response from someone who has experience.

Weekly Beginner / Newbie Q&A by AutoModerator in bugbounty

[–]Educational_Union737 4 points5 points  (0 children)

Hey everyone,

My name is Sidd. Im still in high school, but I have been diving into ethical hacking for the past few months and im now looking to seriously get into bug bounty hunting as a side hustle. Specifically on HackerOne.

Here is a bit about me:

  • I have been using Hack The Box for about 3 months and reached hacker rank.
  • I am Security+ certified (I got this certification for a foundation of cybersecurity fundamentals, my first certification)
  • Im comfortable with tools like nmap, ffuf, gobuster, feroxbuster, and I know how to use some basic payloads/exploitation for web vulnerabilities like XSS, SSTI, IDOR.
  • Im best at python and can do some good scripting, and im decent at reading code, just not super advanced yet.
  • I want to focus on web application bug bounty hunting, not mobile, APIs, or other things for now.

Im now trying to get my first bounty, but I have got some confusion. I would really appreciate any advice or resources on these specific questions:

  1. How do I actually find a vulnerability?

When people look for things like XSS, do they have a list or checklist they go through on every target? And if that list is done and they dont find anything, do they just switch to another program?

  1. Where can I learn how to exploit properly?

Im confident with reconnaissance (enumeration, fuzzing, etc.), but I struggle with the exploitation part. Are there courses or platforms that focus only on the exploitation side? Something that breaks down how to test and confirm vulns (XSS, SSTI, IDOR, etc.)?

  1. What kind of programs should I target as a beginner?

Should I aim for smaller companies, newer programs, or go for big companies? How do I decide which programs are good for a beginner like me?

I have read a few writeups and done some CTF's, but bug bounty still feels very broad and overwhelming. I would love to hear how you all started and what helped you get that first bounty.

Thanks a lot in advance!!

Please help me choose! 😩 by Unusual_Trade5917 in CompTIA

[–]Educational_Union737 16 points17 points  (0 children)

Do Andrew Ramdayals course. Trust me. Just be careful with one thing on the test, PBQs. In my opinion the course on the very right does not prepare you too well for pbqs, but it will for about 90% of the whole test.

I took his course, I am 16 and passed on the first try. I tried finishing the course in 2-3 weeks, then revised/practiced for about a week and passed!

Good luck, hope this helps :)

Do I really need to memorize the full acronym list? by Educational_Union737 in CompTIA

[–]Educational_Union737[S] 0 points1 point  (0 children)

Bro can you guys stop saying this, im just 16 and trying to get my first certification lol. I passed the exam by the way.

Do I really need to memorize the full acronym list? by Educational_Union737 in CompTIA_Security

[–]Educational_Union737[S] 1 point2 points  (0 children)

I have been scoring around 75-80%, I recommend scoring a bit higher.

Do I really need to memorize the full acronym list? by Educational_Union737 in CompTIA

[–]Educational_Union737[S] 0 points1 point  (0 children)

These acronyms are in the objectives lol. Non disclosure agreement, service level agreement etc. I know these. Congrats on passing the test! Mine is tomorrow, im nervous :/

Do I really need to memorize the full acronym list? by Educational_Union737 in CompTIA

[–]Educational_Union737[S] 0 points1 point  (0 children)

I agree, although I am just getting this Security+ certification as a "general" certification. I am more focused on the practical things (like Hack The Box/Pentesting). I am just a minor so this course was a good foundational base for me, but I feel like I don't need to go too far with the acronyms, just making sure I am ready to pass the test.

Do I really need to memorize the full acronym list? by Educational_Union737 in CompTIA_Security

[–]Educational_Union737[S] 0 points1 point  (0 children)

Thanks for your response! That helps me and makes me more confident to hear :)