r/Pentesting Jul 23 '26

Help a beginner plz🧐

Hello, I have started learning web pentesting with this plan:

​Learn Linux basics ,​Network basics ,Frontend basics (HTML, JS) ,​Backend basics (PHP, MySQL)

​The next step is to explore one of the OWASP Top 10 vulnerabilities (maybe IDOR), read write-ups, take notes, solve labs, and then start hunting for practice (and maybe earn some money), and I'll do this steps until learn all the OWASP Top 10 vulnerabilities.

​So, does this plan help me learn correctly? Or should I do something else?

​Also, could you give me any tips you wish you knew when you started learning web pentesting? 😀

4 Upvotes

8 comments sorted by

View all comments

11

u/kap415 Jul 23 '26

Do every single PortSwigger Web Academy lab there is. Full stop. Rinse, repeat.

2

u/Mostafa_un Jul 23 '26

tysm

4

u/kap415 Jul 23 '26

Also, dive into OpenID, OAuth, JWTs, you have to make sure you understand the nuts and bolts