Christophe
Forum Replies Created
-
Hey Anthony, first things first, I want to welcome you to the community! You’ve come to the right place and we’re glad to have you here 😀
Second, I want you to know that you’re definitely not the only person who’s feeling that way. I know sometimes it can seem like everybody is crushing it on social media, but you don’t get to see the behind-the-scenes struggles that they’re going through. Most of the people who are getting nice bounties have been doing it for years or have an extensive background. Just like you though, they had to start from zero at some point in their lives :-). So try not to let that get you down too much! Let it motivate you though!!
It’s definitely not too late – all the bugs are not gone. If they were, we’d all be out of a job. The other thing to keep in mind is that bug bounty hunting isn’t the only thing you can go after in this field. There are many other options, and sometimes you can start off with a different entry point. So even if bug hunting isn’t working out right now, don’t quit cybersec! Not saying you’re necessarily there yet, just saying that so you know there are different avenues.
Now to more actionable tips:
1- Most beginner hunters that I talk to who are struggling don’t spend enough time on, or don’t have a solid process for, information gathering. Instead, they jump right into the application and start throwing random payloads at the target to see what sticks and what doesn’t. Or they’ll fire up an automated tool right away and point it at all the input fields they can find. Then, when nothing happens, they say that there are no security bugs and they move on to a different target.
I’m not saying that’s necessarily what you’re doing, but I have to ask: what does your reconnaissance process look like right now? How much do you know about your target before you try and attack it?
2- Next, I’m glad to see that you’re focusing on 3 classes of vulnerabilities only because sometimes people try to cover everything under the sun. It might be beneficial to narrow your focus down even further to 1 vulnerability class (maybe 2). That way you’re really focusing all of your energy on finding one type of vulnerability and you’re learning that class super well.
3- Try to find a mentor in the space. Someone who’s doing bug bounties right now or who has in the recent past, and who’s ahead of your skillset. You’re asking for help so that’s a great first start.
I’m actually putting together an invite-only group for bug bounties right now. We’re still in the early stages, but the idea is to start beginners off by going after realistic test environments (ie: a copy of Cybr’s platform) to practice without worrying about making a mistake, and also solving certain challenges that I’ve put together in order to gauge where you are at. Then, moving on to real bounty programs (HackerOne, Bugcrowd, etc) and having the group collaborate & share discoveries, ideas, feedback, etc along the way. Let me know if this is something you’d be interested in and we can chat to make sure you’d be a good fit for the program!
Hope this helps, and I look forward to your thoughts,
Christophe
-
Christophe
AdministratorDecember 29, 2020 at 4:27 am in reply to: Question Regarding App Sec CourseHey @sn3106 ! This was definitely not intentional, so I appreciate you letting us know. I’ve gone ahead and fixed it so that the correct video will play for that lesson now.
Thanks and happy learning!
-
Do you play rugby or mostly follow it?
That’s awesome about your brother getting you interested and helping you get going! Even with Google and other sources, makes a huge difference when you’ve got people you can turn to for advice/help 😄
Oh and welcome to the community! Keep it up with all of your learning and what you’re doing – you’re making great progress!!
-
Christophe
AdministratorDecember 21, 2020 at 4:40 pm in reply to: What operating system does everyone use for pen-testing?Same, I default to Kali just because it’s been around for a while and I started using it back when it was BackTrack instead of Kali.
I know a few people who prefer ParrotOS though
-
Christophe
AdministratorApril 20, 2021 at 8:40 pm in reply to: Easily access your earned Certificates of CompletionWhat I always say is: what matters most is the journey to getting certified. Not necessarily the paper certification itself.
What I mean by that is regardless of what the certification exam is like, the people who designed that certification exam approached it with the expectation that the test taker would have the skills, experience, and knowledge required to pass the exam.
What some people do is try to ‘game’ the exam itself. They’ll do things like memorizing concepts (instead of seeking to understand the concepts), look for exam dumps, and overall just get certified in order to be able to put it on their resume.
So when they get to the job interview, most skilled interviewers can quickly pick apart the fact that you don’t actually know what you’re talking about, you simply memorized concepts for the exam. This has happened to me multiple times. We bring someone in for an interview, we start to ask more detailed and specific technical questions, and the person falls flat on their face…but they have 3+ certifications…
Don’t get me wrong – sometimes you have to memorize things, or look up ways to increase your odds of passing. Let’s say for example that the certification expects you to know some basic and common port numbers. You’ll need to memorize those, sure, but memorizing port numbers won’t do anything for you in the real world if you don’t really understand what ports are, or what they’ve even used for.
The other main issue I see with some certifications is that they’re just not well-thought-out. They don’t test the right things, or they don’t test them in the right way. Most people get certifications to enhance their careers, so when a certification doesn’t do a good job of mapping back directly to real-world skills, it definitely seems like a waste. So some certs have earned that negative reputation, and as a result, a lot of hiring managers don’t look favorably upon them.
With all of this said, I’ve talked to a lot of hiring managers over the years, and the vast majority of the time I’ll hear them say either:
- I do like to see certifications on resumes
- I don’t care about certifications on resumes
Only a few times have I heard a hiring manager tell me that they dislike certifications so much that they won’t consider a candidate because they have them. I strongly advise against this when I hear it, for many reasons. The main reason being that it’s OK to dislike certifications, but don’t potentially eliminate great talent when you don’t even know the circumstances of why they got a certification.
So overall I personally recommend certifications because I do believe they can be very beneficial when you focus on the journey to getting certified, not just the paper certification itself. Rarely will having a certification (or more) work against you.
-
Christophe
AdministratorMarch 2, 2021 at 5:27 pm in reply to: Introduce Yourself & Tell Us How We Can Help You Succeed in Cybersecurity!I found the HUD break functionality to be a bit janky at times, so I usually just use ZAP without the HUD. To do that, make sure ZAP is open, navigate to the page where you’ll want to set up a break point, then click on the green circle in ZAP, which will make it turn red. Then, complete your action (like trying to submit a form, for example), and ZAP will pause the action until you step through each request & response. The way to step through is to click on the play-looking button next to the green circle until you get to the request/response you’re interested in. At that point, you can modify the request directly from ZAP.
Let me know if this doesn’t make sense and I can send over a quick video showing it!
-
Christophe
AdministratorMarch 1, 2021 at 5:57 pm in reply to: Introduce Yourself & Tell Us How We Can Help You Succeed in Cybersecurity!Hi @Godejord , and welcome to the Cybr community! Can’t wait to hear & see more of your thoughts on how we can increase security awareness!
-
Haha, the very next time you open up a terminal, try it out! For example, try:
curl cheat.sh/cat
It will show you some correct ways of using cat, including some misuses and helpful commands!
Let me know if I can help 🙂
-
This is very true! Of course, there can be specific advice depending on the field, but oftentimes the biggest mistakes are universal like you said!
-
Christophe
AdministratorDecember 5, 2020 at 10:22 pm in reply to: Introduce Yourself & Tell Us How We Can Help You Succeed in Cybersecurity!Hi Gerso, and welcome to the community! Glad to have you here. What kinds of training are you primarily interested in? Any ideas on what roles you’re looking to head towards, or still figuring that out?
-
Christophe
AdministratorDecember 3, 2020 at 2:18 am in reply to: Introduce Yourself & Tell Us How We Can Help You Succeed in Cybersecurity!Hey Nigel, we met through Discord but wanted to welcome you again through here and say hello! Glad to have you!
-
Christophe
AdministratorNovember 25, 2020 at 2:03 am in reply to: Introduce Yourself & Tell Us How We Can Help You Succeed in Cybersecurity!Thank you! We’ll definitely keep at it 🙂
-
Christophe
AdministratorNovember 25, 2020 at 2:03 am in reply to: Introduce Yourself & Tell Us How We Can Help You Succeed in Cybersecurity!Welcome Steven! Shannon is awesome – glad you found her video useful! Definitely looking forward to having you go through the XSS course, and I can’t wait to hear your feedback 🙂
-
Those exams and the official training are NOT cheap, so I definitely understand wanting to be as prepared as possible. I’d love to hear more about your studying progress, so please keep us posted.
You’ve probably already seen this, but I’ve heard this can be a helpful cheat sheet reference for the exam: https://backdoorshell.gitbooks.io/oscp-useful-links/content/
-
I hear ya, so even though there already are labs available, it’s not ideal because they’re not necessarily organized in a roadmap and instead it feels like they’re all over the place? I can definitely relate with that!
Are you actively studying for the OSCP then or just kind of playing around with different labs and thinking about it?