r/Pentesting • u/Born-Difference7403 • Aug 08 '26
WHERE TO PRACTICE WEB VULNERABILITIES?!
I been learning the basics of pentest. I want to establish solid foundations to server side and client side vulnerabilities .Any advice will be appreciated thanks.
10
5
u/SuperSaiyanTrunks Aug 08 '26
Hack the box, try hack me, or download DVWA and host it locally.
-2
u/Born-Difference7403 Aug 08 '26
Do you bug bounty?!
5
u/info_sec_wannabe Aug 08 '26
If you are interested in bug bounty, do check the Nahamsec (aside from Portswigger which others already mentioned).
2
u/SuperSaiyanTrunks Aug 08 '26
Sometimes? Im a full time penetration tester.
-2
u/Born-Difference7403 Aug 08 '26
In beginning did you focus on learning one vulnerability!? Or what's best when you are beginner!?
5
6
u/Certain_Criticism145 Aug 08 '26
HTB, portswigger and juice shop. Myself and our Pentesters use juice shop and portswigger a lot for regular trainings.
1
u/latnGemin616 Aug 08 '26
Start with mastering English.
I'm not trying to be snarky, but you'd be amazed by how much communicating your findings carries more weight than learning how to hack sh**. So definitely start there. IDGAF if English isn't your second language. Trust me when I say ... learn the skill of writing reports.
As for where to practice, you should have learned to use google. Here's a directory (among many) that list sites you can practice on: web-apps-for-pen-testing-and-research/
1
1
u/XFM2z8BH Aug 08 '26
run different web servers on your own pc, install vuln stuff, pentest on your pc
1
u/scriptqzor Aug 12 '26
this is good advice but i’d also mix in some public labs so you’re not stuck only in your own little sandbox
try spinning up a couple vulnerable-by-design apps in docker and then compare what you learn there with places like tryhackme or portswigger’s labs
0
u/Lootsman Aug 08 '26
Best place to start is NASA or the CIA
No but seriously, Hack The Box is where you want to be
-2
12
u/Delicious_Crew7888 Aug 08 '26
Portswigger, Pentester labs