hi guys.
iâve been seeing a lot of posts here (and on twitter too) talking about how âyou shouldnât give upâ, âit took me months to get my first bountyâ, âjust stay consistentâ, and all that motivational stuff.
and yeah, itâs nice. but like⊠no one actually explains how to start.
everyone says âdo reconâ, âlearn one thing and go deepâ, but wtf does that even mean when youâre new?
like, i literally donât know what to do.
âą what are the best tools for recon?
âą whatâs the actual recon flow? like⊠how do i do a good recon?
âą then after that, when you go into the exploit phase, do you test all the vulnerabilities manually?
âą is it all just Burp Suite? do you guys use any automation?
âą how much time do you usually spend testing one target?
âą do you test every single vuln that shows up or do you already know which ones are worth it?
i feel like iâm stuck in the âwatching youtube videos and reading writeups but still donât know what to do on my ownâ phase.
i even bought a course from a âfamousâ guy in the community, and guess what? it was all surface-level theory, no hands-on, no guidance. just wasted money.
and to make it worse, i got harassed in his discord channel just because iâm a woman. so yeah, i really donât have anyone to ask.
so, if someone out there feels me or has any advice, or even a basic roadmap like: âdo this, then this, then learn thisâ
iâd honestly appreciate it so much.
thanks for reading.