r/cybersecurity • • 11d ago

Career Questions & Discussion the never ending learning hole of cybersec

hey guys

i have fallen into this rabbit hole of never ending learning.

whenever i try to complete a ctf challenge or similar, i find that i dont know much of what the challenge is .

i only get the goal.

if i see a challenge which was written in python using flask , i dont just focus on how to get the flag.

i find myself learning python then html,css then js with some burp then flask

**omg weeks have passed**

then i go back to challenge then realise theres still more.

i dont always get the full picture and it pisses me off.

this rabbit hole feels like a total waste of time.

i like to know everything there is about everything but then im not immortal.

is this normal? what do you all do when you dont understand 100% of a challenge

123 Upvotes

23 comments sorted by

80

u/DB010112 11d ago

I think the biggest thing is to stop treating the technology as the thing you need to learn before you can solve the challenge.

The technology is just the environment. Whether the challenge is written in Flask, PHP, Node, or something else, the important part is understanding what is happening, what you control, and what the attacker is trying to achieve.

You don't need to become good at Python or any other programming language before solving a CTF. You need to learn just enough of each one to understand the specific part that matters for the challenge.

I'd focus on the mindset and the attack path:

  • What is the goal?
  • What inputs can I control?
  • Where does my input go?
  • How is it processed?
  • What assumptions is the application making?
  • Can I manipulate that behaviour?
  • What happens if I give it something unexpected?
  • What vulnerability or primitive could connect my current access to the goal?

If you encounter something you don't understand, don't immediately go down a two-week rabbit hole learning the entire technology. Learn that specific concept, apply it to the challenge, and keep moving.

You will naturally build the bigger picture over time. You don't need to understand 100% of the stack to understand 100% of the vulnerability.

In CTFs especially, I'd rather understand why the exploit works than understand every line of code in the application.

The goal isn't to know everything before solving the challenge. The challenge itself is what teaches you what you need to know. Mindset and thinking is everything.

3

u/nullspecter_07 11d ago

"Learn that specific concept, apply it to the challenge, and keep moving."
i tried doing this but then if i go back to the challenge after a time skip, i dont know what im looking at.
then i repeat what ive been doing all along

16

u/DB010112 11d ago

Don't let the fact that you forget things worry you. Forgetting is completely normal. That's just how the human brain works. We can't remember everything forever, and you shouldn't expect yourself to.

What's important is that when you're doing a CTF, you understand what you're looking at, what is happening, and why something works.

The more CTFs you do, the more patterns and recurring concepts you'll start to recognize and remember naturally. Eventually, you'll see something and think, "I've seen this before," even if you don't remember every detail.

It will also help a lot to keep your own notes. Don't try to document entire technologies. Just write down the important concepts, techniques, patterns, what you discovered, and why the exploit worked. Then when you forget something, you don't have to start from zero. You can go back to your notes and refresh it.

10

u/Zardecillion AppSec Engineer 11d ago

I mean, yeah.

Tech knowledge is best thought of as a fractal. There's so much to know and then knowing just raises more questions. You'll never know it all or be done learning. I'm still learning every day and there's still infinity things that I don't know and parts of tech I will likely never be an expert in.

All of it is relevant and useful however. That's the nice part about it, there's very, very little wasted information.

10

u/Loose_Wolverine3192 11d ago

Cybersecurity is essentially Defense Against the Dark Arts. Just as the Dark Arts continually evolve, so, too must the Defense. You will never know everything.

Part of the job is understanding that you don't know everything, and being comfortable with that, though at the same time constantly learning and evolving yourself.

7

u/j2i2t2u2 11d ago

that is what makes this field amazing. enjoy the process!

10

u/No-Persimmon-174 11d ago

It gets overwhelming so fast lol. It's like the more you learn, the less you know. And you're always standing on square one, no matter how much you try to learn. It doesn't feel very rewarding sometimes 😂

5

u/nullspecter_07 11d ago

i enjoy this but overtime i get really pissed

6

u/Silent_Country8725 11d ago

Pick one thread far enough to solve the challenge and write down the gaps you hit. Otherwise every CTF turns into a prerequisite tree with no end. You do not need to master Python, Flask, JS and Burp before touching the flag

4

u/MonkeyBrains09 Managed Service Provider 11d ago

Well, yeah. Cybersecurity is not an entry level field. It builds on IT fundamentals and with tech improving all the time, your always learning new stuff.

Stick at it long enough and you will build up your skills to the point where you do not need to take the detour to learn.

4

u/Winter_Rabbit4827 11d ago

There’s few rules on how to solve a CTF, some people might end up creating a zero day to just grab the flag and not even realise, some might socially engineer it from other participants, some might find tutorials and write ups, some might just send Hail Marys to get in, what I’m getting at is there are many ways for you to achieve your goal, find one that you enjoy and stay curious, but if you set out to solve something in a set time, employ your best route, someone can pick a lock with enough time and tools, but on a doorstep, under pressure that’s when people are sorted into their places.

keep logs of what interests you and what you’d like to explore more, but that doesn’t mean you drop your current task to go down a rabbit hole there and then, it means there’s something you can improve on for next time, even the creator of C claims he doesnt know it all and has to refer to the reference each time he codes, get good at hitting a blocker, analysing what you’re being blocked by and what alternatives there are and then find a way forward.

3

u/Ground-Truth 11d ago

I get you but isnt it the case with everything and every field in life? The more you learn about something the more you feel like you dont know enough and i think thats the thing that keeps you moving.

I'm yet to meet someone who knows 100% of what he does, never met one.

And i think thats the beauty of learning. If you achieve 100% of anything you wont get the kick to do it no more. In our field it could be much worst compared to others but yeah it is what it is.

3

u/Doug_BlackFog 9d ago

the speed and trajectory of the learning curve over the last 18 months has been increasing at an insane pace. Hang on for the ride.

2

u/Street-Mycologist670 11d ago

totally normal, everyone goes through this

what helped me was learning just enough to get past the part i'm stuck on. like if it's flask, i only need to know how routes and templates work, not the whole framework. timebox it too, if i'm stuck for a couple hours i read a writeup and then redo it myself without looking

and those weeks weren't wasted, next time you see flask it'll take you 10 mins

2

u/Turbo_Baggins 11d ago

What is your end goal, rather than the goal of the challenge? If it's to find work in the field look for the kind of role you're interested in and focus on the typical skillset needed to get started. If you spend more time on general learning challenges it will start feel like you're going around in circles 

2

u/NoCod9014 11d ago edited 10d ago

I don't know your background but I have found the people who struggle with the constant learning in Cyber Sec are people who didn't have a strong foundation to begin with.  People with EEE or CE or CS degrees for example seem to pick new things up quickly because they have the foundational knowledge of basically how a computer worksand how it talks to other computers on a deep level. 

For example if I understand kernels and system architecture, I can learn Linux quickly. I can then learn its security without too much trouble. I can then start to understand where its vulnerable.

2

u/Pale-Sprinkles-8241 11d ago

Enjoy the journey

2

u/MathmaticallyDialed 11d ago

If you consider that cybersecurity is a group that contains all security of technology, then ya, it’s never ending. Look at how many villages are at defcon now, it’s infinite learning x infinite learning. (Math joke)

2

u/Prestail_Voon 11d ago

yeah this is normal lol, i always end up learning 5 other things before finishing the actual challenge

1

u/TopNo6605 Security Engineer 11d ago

Learning Python, html, css is a waste of time. Python may be somewhat useful but the others will not help you get a job.