person who identifies an error or vulnerability in a computer program or system Identification and reporting of bugs and vulnerability in a responsible way.
START BUG BOUNTY Internet, HTTP, TCP/IP Networking Command-line Linux Web technologies At least 1 programming language (Python/C/JAVA/Ruby.. ) Owasp top 10
graphical tool for performing security testing of web applications, it supports the entire testing process, from initial mapping and analysis of an application's attack surface, through to finding and exploiting security vulnerabilities.
Security Project is an online community that produces freely-available articles, methodologies, documentation, tools, and technologies in the field of web application security. The Open Web Application Security Project provides free and open resources.