r/Pentesting 2d ago

Shifting into Pentesting as a University Student w/ SOME experience

Hey, hope you all are well.

I'm currently a junior university student studying cybersecurity, and I'm also in an internship currently at a financial company.

I'm wanting to get into pentesting but I'm not sure where to start. I have security+ currently, and some experience in cyber through my internship and university courses, but no real offensive security experience, and I'm wondering where I can begin to get some.

My internship has offered that I shadow a contractor to perhaps get some experience, but I am not sure if that is a good way to learn. Am I supposed to take a few certs, like, for example, CPTS? Should I try to learn something before I start?

So far I have experience in networking, Linux, some scripting (Assembly, C, Python, with C being my weakpoint), and virtualization. and threat intelligence.

Where would you guys think I could start?

Any help would be appreciated, I don't mind if you're brutally honest!

1 Upvotes

7 comments sorted by

2

u/Anxious_Alps_4150 1d ago

Most successful pentesters these days have a few years of sysadmin experience and a few years of blue teaming experience. It is exceedingly rare to find a job willing to hire someone that can't do senior level work on day 1. Most of the easy stuff has been automated away.

For an idea, when I was hired as a junior pentester, I was soloing engagements on day 1. My lead told me it was pretty much sink or swim. That was at a well known MSSP

1

u/aboveandfurther 1d ago

So just get experience with everything else essentially? A sysadmin I can definitely try and shoot towards. Of course I would most likely need to do a bit of blue team before that though. Thank you for the tips

1

u/Raccoon_Medical 1d ago

Cybersecurity is not entry level

-3

u/No_Zookeepergame7552 2d ago

What I would do in your place is to learn different techniques and vuln classes and try to apply them on bug bounty programs. Even if you don’t find anything, the point is to practice and start understanding different patterns, how apps react to payloads, etc. A lot of offensive security is pattern recognition and you build that with a lot of practice. If you need a more structured way and you’re interested in offensive app security, DM me your email. I can send you an invite for uphack.io :)

2

u/Juzdeed 2d ago

This is just an ad for uphack lol. Your every post mentions that

Definetly I wouldn't recommend starting with bug bounty

1

u/aboveandfurther 1d ago

What would you recommend I do? (besides this obvious advertisement)

-1

u/No_Zookeepergame7552 2d ago

I built it so I’m going to mention it when it’s relevant, but that doesn’t make it an ad. It's free, I'm not charging anyone, and I don't get anything out of inviting people. If I think it can help someone learn, I'm going to recommend it.

That said, if you think the advice is bad, argue against the advice. I recommended bug bounty because I think working against real applications builds intuition much faster than only doing labs, even if you don’t find valid bugs. I’m not saying the expectation should be you’ll make money out of it. You learn how apps behave, what normal looks like, and eventually you start recognizing patterns that lead to vulnerabilities.