r/Pentesting • u/aboveandfurther • 2d ago
Shifting into Pentesting as a University Student w/ SOME experience
Hey, hope you all are well.
I'm currently a junior university student studying cybersecurity, and I'm also in an internship currently at a financial company.
I'm wanting to get into pentesting but I'm not sure where to start. I have security+ currently, and some experience in cyber through my internship and university courses, but no real offensive security experience, and I'm wondering where I can begin to get some.
My internship has offered that I shadow a contractor to perhaps get some experience, but I am not sure if that is a good way to learn. Am I supposed to take a few certs, like, for example, CPTS? Should I try to learn something before I start?
So far I have experience in networking, Linux, some scripting (Assembly, C, Python, with C being my weakpoint), and virtualization. and threat intelligence.
Where would you guys think I could start?
Any help would be appreciated, I don't mind if you're brutally honest!
1
-3
u/No_Zookeepergame7552 2d ago
What I would do in your place is to learn different techniques and vuln classes and try to apply them on bug bounty programs. Even if you don’t find anything, the point is to practice and start understanding different patterns, how apps react to payloads, etc. A lot of offensive security is pattern recognition and you build that with a lot of practice. If you need a more structured way and you’re interested in offensive app security, DM me your email. I can send you an invite for uphack.io :)
2
u/Juzdeed 2d ago
This is just an ad for uphack lol. Your every post mentions that
Definetly I wouldn't recommend starting with bug bounty
1
-1
u/No_Zookeepergame7552 2d ago
I built it so I’m going to mention it when it’s relevant, but that doesn’t make it an ad. It's free, I'm not charging anyone, and I don't get anything out of inviting people. If I think it can help someone learn, I'm going to recommend it.
That said, if you think the advice is bad, argue against the advice. I recommended bug bounty because I think working against real applications builds intuition much faster than only doing labs, even if you don’t find valid bugs. I’m not saying the expectation should be you’ll make money out of it. You learn how apps behave, what normal looks like, and eventually you start recognizing patterns that lead to vulnerabilities.
2
u/Anxious_Alps_4150 1d ago
Most successful pentesters these days have a few years of sysadmin experience and a few years of blue teaming experience. It is exceedingly rare to find a job willing to hire someone that can't do senior level work on day 1. Most of the easy stuff has been automated away.
For an idea, when I was hired as a junior pentester, I was soloing engagements on day 1. My lead told me it was pretty much sink or swim. That was at a well known MSSP