Until We Meet Again
Another checkpoint in my journey through pentesting, development, and everything in between.
Until We Meet Again
Soo… here we are again. xD
This week has been pretty tough, not gonna lie. I’ve been spending most of my time figuring out how applications are deployed manually, understanding how everything works behind the scenes, and testing all kinds of things. At times it honestly felt overwhelming, but I enjoyed every bit of it. The deeper I go, the more I realize there’s always something new waiting to be learned.
I’ve also been making a lot of pentesting notes lately. Looking back at how I used to take notes, I can definitely see an improvement. But I also think I need to do a lot more research. These days I don’t just want to know what something does—I want to know why it works the way it does. Sometimes I get stuck on a concept and start questioning whether I’m even going in the right direction. Then I take a step back, do more research, read documentation, try different approaches, and eventually everything starts making sense again.
I guess that’s just part of the journey.
And honestly… God’s been with me through all of it. Things are going well. I just need to lock in a little more and keep moving forward.
One of the best things that happened this week was getting the chance to ask Bruno Rocha Moura about getting into Application Security. We talked about the path, what I should focus on, and what skills actually matter. Hearing it directly from someone who’s already working in the field gave me a lot of clarity. I walked away from that conversation feeling genuinely excited.
His blogs have helped me a lot over the past few months, not just with learning AppSec but even with the way I write notes and document everything I study. They’ve completely changed how I approach learning.
For those who don’t know me yet, I’m currently in my third semester of my Computer Science degree. College is… well, college. Sometimes it feels like we’re learning things that don’t really prepare us for what I actually want to do. So most of my real learning happens outside the classroom.
Funny enough, I even tried testing my college’s website one day.
And yes…
I actually found a few issues. xD
Did I get a bug bounty?
No.
Did I get a reward?
Also no.
At least my ma’am appreciated the effort, so I’ll take that as a win.
Lately I’ve also been trying to improve my reporting skills. Every time I finish a box, I try writing a proper report using SysReptor instead of just collecting screenshots. I’m trying to follow a structure similar to what CPTS expects because I don’t just want to solve machines—I want to communicate my findings professionally as well. I know I’m still learning, but every report feels a little better than the previous one.
On the development side…
Things have been going surprisingly well.
I’ve been spending more time understanding how applications are built instead of only thinking about how to break them. The more I learn about development, the more I understand why application security is such an interesting field. Building and breaking software feel like two sides of the same coin, and I want to get better at both.
There are still a lot of things I want to build, a lot of write-ups I need to publish, and plenty of notes sitting in my vault waiting to be cleaned up and shared. Programming articles are coming too. I want this website to slowly become a place where I document everything I’m learning—from cybersecurity and development to random lessons I pick up along the way.
Before I wrap this up, I want to give a huge shoutout to two people whose work has genuinely helped me.
Bruno Rocha Moura has been a massive inspiration throughout my AppSec journey, and his articles have taught me a lot about thinking like an application security engineer.
Yash has also helped me tremendously. His notes, ideas, and the way he documents everything have inspired me to improve my own note-taking system.
If you’re interested in cybersecurity or AppSec, I highly recommend checking out their work.
That’s pretty much it for this week.
Over the next few days I’ll start publishing the write-ups I’ve been sitting on for a while, along with more programming posts and my personal notes. There’s still a long way to go, but I’m enjoying every step of the journey.
Until we meet again.