18 ms·
Dylan, I'm a software engineer. Let's say I wanted to transition into security with the eventual goal of consulting for web / mobile application security. 1.
by 147 10y ago
Dylan,
I'm a software engineer. Let's say I wanted to transition into security with the eventual goal of consulting for web / mobile application security.
1. Would going through the books you've recommended here and practicing a good path to get me to there?
2. Could you elaborate more on your second to last paragraph? Say I found a Rails vulnerability. How would I monetize that? I interpreted your statement as saying do lots of bug bounties or fewer not bug bounties.
- dsacco 10y agoHey Christopher, 1. Yes, working through those books would get you to a position at any of the best consulting firms for security. As Thomas will tell you, they used to ship some of the books I mentioned to candidates to prepare them for interviews at Matasano :). Those books will teach you everything you can learn from books alone; the rest is just up to practice. 2. If you find a Rails vulnerability, the most straightforward path to monetizing it is reporting it directly to the Rails core dev team and registering for a CVE number recognizing you as the researcher. Once the vulnerability is patched, report the fact that you found it and it was patched to Hackerone's Internet Bug Bounty (IBB) program. The IBB program rewards researchers for reporting serious flaws in major software used around the internet. Your interpretation is correct. I use "bug bounties" colloquially to mean web application vulnerabilities, but technically Hackerone's IBB is a bug bounty. The point is that web application vulnerabilities are worth less as a general rule than vulnerabilities that impact a plurality of websites, due to things like vulnerability half life. Hope that helps!
- goldenkey 10y agoYou'll probably never get there. Either you're born a phreaker, cracker, pentester, or you're a kid who does other things during HS and college. The kind of people that do sec have been doing it since they were 10. You'll have a hard time competing. (And yes, I am the former.)