35. Careers, Certifications and Bug Bounty
35.3 Practice Platforms
Skill comes from practice on legal targets built for learning:
| Platform | Type | Best for |
|---|---|---|
| TryHackMe | Guided rooms in the browser, free and paid tiers | Absolute beginners, SOC and pentest paths |
| Hack The Box (Academy and Labs) | Machines and structured modules | Intermediate pentest practice |
| PortSwigger Web Security Academy | Free web labs by the makers of Burp Suite | OWASP and web testing (Chapter 29) |
| OWASP Juice Shop, DVWA | Vulnerable apps you run yourself | Local web labs (Chapter 21) |
| VulnHub, Metasploitable | Downloadable vulnerable VMs | Offline lab practice (Chapter 18) |
| OverTheWire (Bandit) | Linux wargames over SSH | Linux command-line skill |
| picoCTF, CTFtime | Capture The Flag competitions | Problem solving, teamwork |
| Blue Team Labs Online, LetsDefend | Defensive investigation labs | SOC analyst practice |
A good weekly routine: 3 practice sessions on one platform, 1 write-up of what you solved (without giving away answers of active challenges), and 1 revision of a weak area.
Ravindra Bagale's Tip
Walkthrough baghun room "complete" karne mhanje shikne nahi. Aadhi 30-45 minute swatah prayatna kara, adakla tar fakt ek hint ghya. Ani ho – ya platforms var shiklela technique kadhich tyachya baher kharya site var try karu naka.
Practice task
Create free accounts on TryHackMe and PortSwigger Web Security Academy. Complete one beginner Linux room and two SQL injection labs, and write a half-page note on what you learned from each.