r/Pentesting 19h ago

Help a beginner plz🧐

0 Upvotes

Hello, I have started learning web pentesting with this plan:

​Learn Linux basics ,​Network basics ,Frontend basics (HTML, JS) ,​Backend basics (PHP, MySQL)

​The next step is to explore one of the OWASP Top 10 vulnerabilities (maybe IDOR), read write-ups, take notes, solve labs, and then start hunting for practice (and maybe earn some money), and I'll do this steps until learn all the OWASP Top 10 vulnerabilities.

​So, does this plan help me learn correctly? Or should I do something else?

​Also, could you give me any tips you wish you knew when you started learning web pentesting? 😀


r/Pentesting 3h ago

What are your salary/benefits?

12 Upvotes

I figure this is good info for everyone to have. I see huge ranges online and am not sure how good anyone's comp is relatively.

Me: 159k/year, US-based, 6 YOE as a pentester, ~12 YOE in cybersecurity, CISSP, expired Sec+, government contractor, shit PTO, no bonuses or stock options.

What about you all?

Edit: I should add that I'm fully remote


r/Pentesting 15h ago

GitHub - iss4cf0ng/Alien: Alien is a modular webshell client developed for cybersecurity research and education. It provides a unified post-exploitation framework for managing different web technologies through reusable modules.

Thumbnail
github.com
2 Upvotes