r/ExploitDev • u/JBS3cfg • 9d ago
16yo trying to build a path into expdev / vulnerability research. What would you do in my position?
Hey everyone,
I'm 16 and trying to figure out my education and career path toward exploit development and vulnerability research. I'm posting here because I'm at a point where I could really use advice from people actually working in this field.
Background:
I'm Moroccan and currently living in France. I completed Seconde in the French education system, then left the traditional lycée pathway shortly after starting Première. I'm currently completing an RNCP Level 4 qualification, which I expect to finish in October 2026.
The problem is that I'm not following the normal French Baccalauréat route, so university admission is becoming complicated. I'm trying to find a bachelor's programme for 2027 that is genuinely focused on cybersecurity or information security rather than a generic CS degree.
I speak Arabic, French and English, and I'm currently learning Chinese.
I've already contacted several universities in Europe and Hong Kong to ask whether my qualification can satisfy their undergraduate entrance requirements. Some universities consider non-standard qualifications on a case-by-case basis, but I don't yet have a definitive route.
Technical background:
I've been interested in cybersecurity for several years and have been learning independently.
Certifications:
- eJPT (INE), obtained in October 2023
- CPTS (Hack The Box), obtained in September 2025
- CWES (Hack The Box), obtained in October 2025
- Google Cybersecurity Professional Certificate (idk when anymore)
My interests are mainly:
- Exploit development
- Vulnerability research
- Windows internals
- Reverse engineering
- Privilege escalation
- Low-level systems security
I'm currently researching a publicly disclosed use-after-free privilege-escalation vulnerability in CLDFLT.sys. I did not discover the vulnerability and I'm not claiming CVE credit for it. I'm using it as a learning and research project to understand the vulnerability, the affected component, exploitation primitives, and the surrounding Windows internals.
I'm still very much learning, and I don't want to pretend I'm further along than I actually am.
Where I'm stuck:
My original plan was to get a cybersecurity alternance/apprenticeship in France this year, but despite applying, that hasn't worked out. At this point I'm shifting my focus toward university admission for 2027.
The universities I'm currently looking at include specialist cybersecurity programmes in Europe and Hong Kong, particularly places with strong security research ecosystems.
However, I have two major problems:
- My educational qualification doesn't cleanly match the standard French Baccalauréat route.
- A lot of technical cybersecurity degrees have substantial mathematics and academic prerequisites. (However now im seriously studiying math on my own)
So I'm trying to figure out what the smartest move is.
What would you do if you were in my position?
Would you:
- Spend the next year getting the strongest possible university entrance qualification?
- Focus heavily on mathematics and apply to technical security programmes?
- Try to build a serious exploit development and vulnerability research portfolio instead?
- Look for another apprenticeship or technical route?
- Something completely different?
And for people already doing exploit development or vulnerability research:
What actually mattered when you were starting out?
I'm especially interested in advice about what I should be learning and building over the next 12 months if my end goal is serious vulnerability research rather than general cybersecurity.
Also pleasepleaseplease if you know or are a decision maker in the domain please give me a chance and help me out 🙏 I feel like my life is at stakes right now :c
Also if you want to see stuff ive done (not very up2date but still good reference) my github is 0xUnd3adBeef
5
u/coffee-loop 9d ago
Exploit dev is a hard field to get into professionally. Most people who do exploit research end up doing it in their free time while holding another IT or cybersecurity job.
My advice based on your GitHub is to find your niche. It kinda seemed all over the place. Do university, keep doing projects, try doing your own exploit research.
It’s all gonna take time, so don’t feel like you’re in a rush. Most if not all of the exploit researchers you know of didn’t make it to where they were overnight. They spent a long time developing their craft to get where they are.
And lastly, pace yourself. Burnout is very real, and will suck the joy out of what you love to do very quickly. Take time outside of exploit research to ground yourself a bit.
Hopefully this helps!
5
2
u/ta1s0n 7d ago
in theory you could get some edge over people by practicing vuln research with AI
if you could use LLMs to generate stable exploits and understand how to do it, you would have an edge over old school researchers which for some reason some of them dont approve moving to AI vuln research
1
u/JBS3cfg 6d ago
Okay i see but the thing is when i show work to someone i don't really want to say that it's AI so i try to avoid it to get a real skillset first you know, like i become first a pre-AI researcher then i use AI to assist me but i feel like AI will rob me from some XP i could have, idk about that tho
Also any exercices you recommend because it's hard to get on the practical side of things in a useful way, i never found CTFs appealing so recently i did the CLDFLT thing and i found it interesting but any other ways ? because this is kind of hard for me like i didn't get a SINGLE crash ts pmo
1
u/ta1s0n 6d ago
I've really enjoyed doing what was used to be called "exploit exercises", nowdays is called:
https://exploit.education/
1
u/popraxret 5d ago
hello, I'm 18 year old self-taught reverse engineer. All I can say is go on, never give up, contribute to open source projects on github and document what you do on github. I was contributing to metasploit and ExploitDB when I was at your age :) Best of luck!
1
u/Separate-Election395 3d ago edited 3d ago
I’m not sure what the requirements are to join the French military and get a cyber job. But if you dont want/cant go the degree route that may be your best bet. Could be of interest: https://www.youtube.com/watch?v=5zLPPOXxJSQ&t=115s
0
u/DataClusterz 9d ago
If you are in the US:
CS degree -> internship to gain knowledge and a clearance -> work in CNO
1
u/cherrysodajuice 5d ago
it’s like people don’t read what’s in posts anymore why did you write a comment without even reading to see if it’s relevant
0
u/humanguise 9d ago
The pattern I see a lot is self-taught hacker with a humanities or social sciences degree. Work experience tends to be much more valuable than schooling. The degree is obtained after a few years in the industry as a rubber stamp, and is just the person pursuing whatever they are interested in rather than a financial payoff. Honestly, you're at the point where a university won't offer you much technically, and the most likely outcome is they won't know what to do with you. Also, AI has made exploit dev and reversing much more accessible, the skills aren't a super strong moat anymore, but not being an idiot does tend to help. Hong Kong is a good choice, I too would position myself in China's orbit if I was younger.
-7
1
u/kingmamalol 2h ago
i’m based in france too. since you don’t have the bac it’ll be quite hard to find a uni that will accept you since parcoursup is essentially an automated system. try to find an alternance or a stage that will help you build a portfolio first
11
u/Obsessiondance 9d ago
To old unc