← Back to list

The Reality Check I Needed as a Cybersecurity Student: I Thought I Needed More Knowledge, but I…

I went to Bangalore last month and I would say, it definitely has an effect on people…

Hardik Gaikwad · 2026-07-14 04:12 · 0 claps · 3.7 min read
#cybersecurity #students #bangalore #hackthebox #offensive-security
Open on Medium ↗
Wiki topics: CRY · Crypto & Web3 EDU · Education & Learning 🔒 · Cybersecurity

The Reality Check I Needed as a Cybersecurity Student: I Thought I Needed More Knowledge, but I Actually Needed More Practice | B1–1407T26

I went to Bangalore last month and I would say, it definitely has an effect on people. I’ve been to tier 1 cities before, stayed for longer, but Bangalore just felt different. Maybe it was the people, or maybe the lifestyle or maybe just how every other person you look at might just be a founder.

I went to Bangalore to volunteer for a cybersecurity conference focused on offensive security, VULNCON. Having attended only a few conferences before this, I felt being a part of the organising team, or at least volunteering, would be a better opportunity as I would spend more time with people who are in security, whether experienced or not (I was expecting that but to my surprise, I was the only student there). The event was successful, the team knows what they’re doing, I just hoped I don’t screw up anywhere.

Being from a tier 3 college in a tier 3 city, It’s really hard here to find people in security, I had a few seniors who switched domains just before the placement season and I had a couple of other batchmates, who are as oblivious as I am, or at least, I was (a little less now). Point being, I’ve been wanting to meet people, get reality-checked, find answers and make connections that would help me with whatever problems I’ve been facing. And this team has definitely helped me. For the first time in my life, I’ve seen a group of people talk about bugs, vulnerabilities, clients and anything in security in general. This is what I was looking for.

What made an impact

The event, the people there, the community were definitely inspiring and motivating, but what really made an impact on me was the conversations I had. One of these guys I shared my room with, had cleared CPTS 2 years back and we had a discussion on that (I’m currently preparing for CPTS). He gave me advice, warnings and told me how good the certification exam is. The first person I met there was a full time bug bounty hunter and he told me about how he started, and what the current scene is.

Another person helped me realise where I stand and what needs to be done, I’ve been avoiding getting into bug bounty, actually trying machines and facing anything real because I thought I wasn’t at that skill level yet and I’ll get into it when I get even better. I still don’t think I am at that level yet but this is a loop I now realise I have to get out of. He told me I have to get my hands dirty to actually understand how everything works and get better while at it. I cannot know how systems work until I actually try to test them. During those conversations, I realised how I haven’t even tested vulnerable machines yet, let alone live targets except the eJPT labs and exams and rooms on TryHackMe. Rooms on TryHackMe are a way to learn but I never tried to implement those learnings on actual machines and DIY labs. This has been an issue I didn’t realise I was obliviously creating for myself all this time.

Even if nothing comes out of it, I have to get my hands dirty, I have to start testing live targets and understand what goes on when an application is working. It will help me understand more clearly how requests are sent, how responses are received, and even the smallest of details in systems, which will eventually help me.

What I will do about it

Considering how important it is to actually get into the battlefield, use tools, try different methods and figure it out on my own, I have decided that I’ll be starting with labs and bug bounty soon. I’ll enrol in BB programs even if I don’t find anything, I’ll try to dig through domains and directories or simply just watch over the network tab. This is a short term goal I’ve decided on.

Currently I am preparing for CPTS and I’m hoping to clear the learning path on HackTheBox Academy in a couple months. This is my first time using HTB. It’s been a month and it’s growing on me, I love the material and how labs are structured. Starting out feels easy and the beginner machines do actually build confidence. Speaking of confidence, yes, one major benefit of testing live and doing labs will be confidence. It’ll help me grow and trust myself in testing which has been a problem since the start of my journey. While I’m at it, I’ll do labs and retired machines on the main platform and get into it as much as I can. I’ll learn about a few web attacks and test them on machines, create my own home lab and finally test them on targets on BB programs or Vulnerability Disclosure Programs I find.

One other thing I have realised is that I have never done anything public to showcase my skills. No write-ups, no published research papers and obviously no claimed bounties or CVEs in my name. So, all this has motivated me to start writing about my security journey and what I find (hopefully bugs in platforms soon). This write-up is my first one and I’ll be making a habit out of it.

Thanks for reading!


메타데이터
post_id
baf196f056b8
slug
the-reality-check-i-needed-as-a-cybersecurity-student-i-thought-i-needed-more-knowledge-but-i-baf196f056b8
url
https://medium.com/@hardik4g24/the-reality-check-i-needed-as-a-cybersecurity-student-i-thought-i-needed-more-knowledge-but-i-baf196f056b8
canonical_url
https://medium.com/@hardik4g24/the-reality-check-i-needed-as-a-cybersecurity-student-i-thought-i-needed-more-knowledge-but-i-baf196f056b8
author_url
https://medium.com/@hardik4g24
status
ok
fetched_at
2026-07-17 01:05:21