The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Where to start?

Ashish | Last updated: Oct 12, 2020 04:01PM UTC

I am a begineer in pentesting and bug bounties. I came across https://portswigger.net/web-security/all-materials this url while searching for resources to learn Web Application Security. So My Question is as a complete begineer where should I start learning, I mean which vulnerability. There are so many at https://portswigger.net/web-security/all-materials. Thanks!

Uthman, PortSwigger Agent | Last updated: Oct 12, 2020 04:18PM UTC

Hi Ashish, You can begin anywhere you like. That is the greatest feature of the academy! The learning materials are comprehensive and most of the topics are discrete (although all related to web security vulnerabilities). I would start with bugs that are easier to understand conceptually - e.g. XSS, SQL injection, etc... You can then practice these in bug bounty programs.

Ishaq | Last updated: Oct 13, 2020 01:12PM UTC