Web application security
The base everything else builds on. Over 100 PortSwigger Web Security Academy labs plus CTF work, and bug bounty reporting on HackerOne and Bugcrowd.
- Complete:OWASP Top 10Read6h
- Complete:PortSwigger Web Security Academy — 100+ labsPractice80h
- Complete:Access control and business logic testingPractice20h
- Complete:REST and GraphQL API testingPractice15h
- Complete:RootMe CTF challengesPractice20h
- Complete:Accepted bug bounty reports on HackerOne and BugcrowdMilestone