Part 1. 30 days(3 hrs average)
Learn it in a sequece:-
Watch this video first:- How to shot web by jason haddix
Study these vulns first:-
- IDOR
- XSS
- SQLi
- Directory traversals
- Broken web authentications
Tools to learn:-
- Sublist3r
- Burp(In-depth)
- NMap
Videos & Youtube:-
- Hackersploit
- Nahamsec(Even if you feel it boring you need to stick with it)
YOU CAN DO YOUR RESEARCH AS WELL BUT DON'T LOOK MUCH DEEPER
Part 2- 30 days(3 hours average)
Study these vulns now, only when you have cleared the previous part.
- XXE
- RCE
- CSRF
- SSRF
- Race conditions
- Subdomain takeover
Tools to learn:-
- Burp advance(pro)
- Knockpy or subbrute
- Google dorks
Videos:-
-
Bugcrowd university(all videos)
-
HAcker101 videos
-
Insider PHP(youtube)
-
Stok
-
DC cybersec
-
Bug hunting methodology 2 & 3
-
Nahamsec :- Its just the little things.
PRACTICALS
-
Portswigger labs
-
Bwapp
-
HACKER101 CTFs
-
Hackthebox in last
Writeups
*Pentester.land *BUgcrowd writeups *Netsec on reddit(stay active there) *Hackerone POC reports
Guides
OWASP TOP 10 2017 SANS TOP 25 SSRF BIBLE Cheatsheet XSS cheatsheet portswigger XXE cheatsheet
Books:-
- Web application hacker's handbook
- Hackers palybook 2
- Tangled web
- Mastering moderb web pentesting
- Web hacking 101