I've hit a wall with websec 06-07-2016, 01:30 AM
#1
I'd say I've spent a good 4 or 5 years absorbing all of the knowledge I can about web security, and I feel like there's nothing else for me to do. I've felt this way for a few months and I've gone around trying to see if there's anything new to learn but I just can't seem to find anything, web security is getting repetitive and boring. I've tried challenging myself with wargames but all of them are either too easy or they regex your input when there really should be more than 1 solution. I have a very strong base in PHP, I'd say the only thing left for me to do is learn JS, but idk how much that would accomplish since it's not really useful except for XSS and editing pages of dumb admins who use client-side filters, and even then, you really don't need to be a master of JS to be able to do either of those things. I also thought about learning languages such as Ruby on Rails, Django, etc but realized that would be pointless since the attacks are more or less the same regardless of the language. The only thing I feel like I'm lacking in is black-box testing experience since I don't go around targeting random websites and no one took me up on my service.
What to do? Is it time for me to dive into OS-level stuff?
What to do? Is it time for me to dive into OS-level stuff?