Answering a noob's questions

Answering a noob's questions

Table of Contents

Yoo Welcome to Issue #20 of Navigating Security.

šŸƒQuote of the week:

I’m too lazy to lookup quotes.

Ā  Tadi

What To Expect 🫔

  • Answering questions from the previous issue by Byron, the ā€œnoobā€ šŸ’€
  • A new series coming out soon as well? šŸ¤”

This Week’s YouTube Video:

What I learned from 300+ days of being a hacker (so far)

āš ļø The newsletter is currently not sponsored

Answering questions from the last post šŸ“

As you may have seen, I have a friend helping me out with the newsletter now because I can’t do anything consistently. If you haven’t read the previous newsletter issue, I suggest you do so, but you can probably get away with just following along.

[How a Noob follows the ultimate hacker roadmap.

Take small steps towards your goals.

www.navigatingsecurity.net/p/how-a-noob-follows-the-ultimate-hacker-roadmap](https://www.navigatingsecurity.net/p/how-a-noob-follows-the-ultimate-hacker-roadmap?utm_source=navigatingsecurity.beehiiv.com&utm_medium=newsletter&utm_campaign=answering-a-noob-s-questions&_bhlid=ed134f334aa44544332a99a5e2c6a9bf96c794f7)

ā“How do you build muscle memory when it comes to OWASP-related vulnerabilities, even when you’re expecting SQL injection it’s almost like each time you’re doing something completely different.

Ā  Byron

šŸ…°ļø Muscle memory is built with practice, just like everything else. The more you do it, the more you’ll know how to approach different situations because in reality no situation is the same. The principal concept is what matters.

ā“How do you maintain patience and precision when using time-based blind SQL injections?

Ā  Byron

šŸ…°ļø You’re literally shooting in the dark. Patience is a virtue.

ā“Can you explain why the classic payload ' OR '1'='1 works, and in what scenarios it might fail?

Ā  Byron

šŸ…°ļø What I can tell you is it doesn’t work anymore in modern applications, especially considering that most developers know how to write ā€œsafeā€ code against those types of attacks. SQLi still exists, it’s just a little more complicated than before. The following articles might be helpful:

ā“Does experience with app development help with web app hacking?

Ā  Byron

šŸ…°ļø Yes. As a beginner, probably not, but when you reach a point where you’ve progressed past being a scriptkiddie it’ll be harder to hack without some knowledge of how applications are built.

ā“What’s the best approach to mastering OWASP-related vulnerabilities, since they seem to be a common requirement on job postings?

Ā  Byron

šŸ…°ļø Practice, practice, practice. Do CTFs, do labs, read disclosure reports. Pick a few things you are most interested in and go as deep as possible.

New Year, New Series šŸ¤“

https://imgflip.com/tag/new+year+new+me

I might just be back from my many frequent hiatuses.

When I started creating content, I never intended to come across as a teacher in any way. I didn’t know much, so I wanted it to feel more like, “Here’s what I’m learning—come learn with me.”

I’d like to return to that approach and show you how I’m now growing into a more mid-level professional—not necessarily a noob anymore.

The series will be called How I’m Learning to Be a Better Pentester. I’ll primarily be highlighting what I’m learning, how I’m being intentional about my growth, and how you can be too. The first post should be on LinkedIn soon, if it’s not already—so catch me there as well!

As always, if you have any questions or suggestions, feel free to hit me up on LinkedIn or Discord. Cheers!

ā±ļøIncase you missed the previous issue, here you go:

[How a Noob follows the ultimate hacker roadmap.

Take small steps towards your goals.

www.navigatingsecurity.net/p/how-a-noob-follows-the-ultimate-hacker-roadmap](https://www.navigatingsecurity.net/p/how-a-noob-follows-the-ultimate-hacker-roadmap?utm_source=navigatingsecurity.beehiiv.com&utm_medium=newsletter&utm_campaign=answering-a-noob-s-questions&_bhlid=1e53f9c51aae6ee8678bb8e33323113b276ba60e)

Suggestions

Hit me up on Discord or LinkedIn if you have anything you feel would be cool to include. Thanks, Cheers.

Share :

Related Posts

There is more to Burp Suite than meets the eye...

There is more to Burp Suite than meets the eye...

šŸƒQuote of the week: Java sucks! ~ Tim Tomes What To Expect 🫔 🤯There’s a lot more to Burp Suite than meets the eye - Tim Tome’s PBAT course šŸ’»Build vulnerable labs, you’ll get better at hacking šŸ“ˆHow to get better at hacking - get out of your comfort zone Burp Suite is amazing🤯 I recently took the PBAT training by Tim Tomes (author of Recon-ng, Py-scripter, and HoneyBadger v2) as part of the training provided at the NorthSec conference and as soon as we started I realized how much I did not know about Burp Suite.

Read More
Pentest War Stories-ish

Pentest War Stories-ish

šŸƒQuote of the week: Always look for ways to chain bugs to increase the impact - one crit is cooler than two mediums.

Read More
Complete Hacker Roadmap

Complete Hacker Roadmap

Yoo Welcome to Issue #17 of Navigating Security. šŸƒQuote of the week:

Read More