


This site has a massive list of practice apps and systems for several hacking scenarios. It’s actually more of a practical walk-through. This is a great site to learn a bit more about various web hacking techniques and how they’re done. These will give you an idea of what you’ll run up against in the real world. Practicing on vulnerable applications and systems is a great way to test your skills in simulated environments.

While you’re learning it’s important to make sure that you’re also understanding and retaining what you learn. The Tangled Web: A Guide to Securing Web Applications The Hacker Playbook 2: Practical Guide to Penetration Testing Highly suggested by Bugcrowd’s Jason Haddix This book starts from square one, walking you through getting Kali Linux installed all the way through using tools and finding exploits. This is an absolute must-read and considered the web-app hacker’s ‘bible’. Hacking is a lifelong journey of learning.
THE WILD AT HEART BOUNTIES HOW TO
The greatest hackers on Bugcrowd have specialities and areas of interest, but they don’t know how to hack everything. Focus on that one area and pick up new things as you go, but don’t try to be the “ultimate hacker” and learn everything. It’s very important to focus on an area of hacking that is interesting & exciting to you. Since bug bounties often include website targets, we’ll focus on getting you started with Web Hacking and later we’ll branch out. There are some go-to books that you can buy to help you learn the basics and essentials of penetration testing and bug hunting. We’ve collected several resources below that will help you get started. Congratulations! It’s very exciting that you’ve decided to become a security researcher and pick up some new skills.
