Hacker News new | ask | show | jobs
by Techbrunch 1824 days ago
I would not recommend OSWE to learn appsec since it is teaching "Advanced Web Attacks" and assume that you know the basics.

Something that is really interesting I think is the whitebox approach that some people in infosec might be missing if they don't come from a developer background and never botherered looking at the code introducing the vulnerabilities.

If you want to learn appsec I recommend Web Security Academy: https://portswigger.net/web-security

1 comments

PortSwigger is great. Certifications, on the other hand, are not a good way to learn appsec.