How to start on web applications security
Summary:
hey guys I hope you are fine, now I am going to talk about how to start with Web applications security.
now if you want to learn something from someone but this guy doesn’t speak the same language of you what will you do?…….yes…you will learn his language to learn from him, it’s the same with web applications now if you want to start “security web application” you should learn how it works, learn it’s language.
now if you want to learn something from someone but this guy doesn’t speak the same language of you what will you do?…….yes…you will learn his language to learn from him, it’s the same with web applications now if you want to start “security web application” you should learn how it works, learn it’s language.
Now I will talk about the programming language:
There are a lot of programming languages you can use Java, ASP, Perl, Ruby, Python, and PHP but the best one is PHP because most of the web applications use it but the other languages have a good future now you learned PHP to understand what website say :D, now you should learn a programming language for the Database to use it with PHP now the Database is something that the website can’t work without it. so you can learn MySQL it’s good but there are others you can search about them “Google Is Your Friend” now the time for Technologies you should learn the web technologies like HTML, HTML5, Javascript, AJAX, JSON and XML these technologies will be useful for you.
Understand the vulnerabilities:
when you finish the programming languages you will start a new thing it is learning the vulnerabilities now you will start to understand how the vulnerability works…..you can use the OWASP Top 10 to know the well-known vulnerability now you will read about it a lot don’t be bored when you understand the vulnerabilities types and how it works and how you can to stop it, now it’s time to learn the advanced exploit for this vulnerabilities and you can read a write-ups that the other Hackers found..and understand how they did that if they used a new method you don’t know…..so this is good you will learn more.
Be advanced:
now you learned Programming languages and understand the vulnerabilities this is good but you should know, the vulnerabilities, not just XSS, SQL injection you will know that there are more of that, now you can do something else you can start to play Capture The Flag (CTF) what is this, this is a something like a game between the hackers/researchers not just on web applications but there are a lot of fields this will make you advanced and you will learn from it a lot, you can follow this website CTFTime this website notice you if any CTF will start soon online or offline this will be helpful, Now the other thing is the Bug Bounty what is it? this is a way to hack websites but ethically…….how? the websites which have a Bug Bounty Programs give the Ethical Hackers/Security researchers a permission to hack there website to find a vulnerabilities on it but here when the Researcher find a bug he write a report about the vulnerability to the security team of the website to help them to close this vulnerability and the website pay for that, now there are a platforms you can start form it to be a Bug Hunter like HackerOne, BugCrowd, Synack.
Time to read:
you should read piece of content this helps you to know new issues new exploits for bugs or learn anything you can follow some Researchers to know anything from their posts or write-ups they will help you and follow blogs about cybersecurity and you can read the reports which the researchers send on HackerOne platform you just select the public reports and start read this is helpful and you can follow these blogs it’s helpful Seekurity, Detectify Labs, and you can read this reports too this is a big collection of reports and follow this website The Hacker News.
Thank you for reading this I hope that I helped you with anything.
Hey Thanks for sharing this blog it is very helpful to implement in our work
ReplyDeleteRegards
hire a hacker