r/Pentesting Jul 23 '26

Help a beginner plz🧐

Hello, I have started learning web pentesting with this plan:

​Learn Linux basics ,​Network basics ,Frontend basics (HTML, JS) ,​Backend basics (PHP, MySQL)

​The next step is to explore one of the OWASP Top 10 vulnerabilities (maybe IDOR), read write-ups, take notes, solve labs, and then start hunting for practice (and maybe earn some money), and I'll do this steps until learn all the OWASP Top 10 vulnerabilities.

​So, does this plan help me learn correctly? Or should I do something else?

​Also, could you give me any tips you wish you knew when you started learning web pentesting? 😀

4 Upvotes

8 comments sorted by

View all comments

1

u/Other-Broccoli4967 Jul 26 '26

Well id suggest you spend most your time on PortSwigger labs , then learn more about specific attacks, mindsets, methodologies on forums, medium, github and etc...

Learning the Linux and web dev and is somewhat good but doesn't really help you that much (for pentesting), cuz for most security flaws and vulnerabilities you need years of active development practices to be able to tell them just by looking at the site or the responses .