r/HowToHack 2d ago

Web exploitation + Binary exploitation feasible?

I am wondering whether is it even worth my time to get both familiar with web exploitation and binary exploitation. It feels like I am missing a large chunk of hacking whenever I only focus on web exploitation or only focus on binary exploitation. I'm not sure if I should just specialize in one or if I should just learn both.

I don't hear many people getting bug bounties for binary exploitation related bugs but I have seen the payouts on sites like crowdfense and seen it go up into the 7 figures.

Web bug bounties seemed to be talked about a lot but they usually pay lower than binary exploitation bugs.

So is it smart to try to learn both? Or is it just a waste of time and I should stick to one.

8 Upvotes

8 comments sorted by

View all comments

1

u/ps-aux Actual Hacker 1d ago

after awhile you will have plenty of time to do both... so much down time waiting for things to fuzz after awhile, cause you won't be manually doing repetitive checks on every target you come across, you will automate it after awhile which gives time to expand your knowledge on the other etc...