Finishing the Hack The Box Certified Bug Bounty Hunter Course: A Module Marathon

Finishing the Hack The Box Certified Bug Bounty Hunter Course: A Module Marathon

Originally, my plan was to document my progress through the Hack The Box Certified Bug Bounty Hunter (HTB CBBH) course as I completed each module. However, I ended up diving deep into a full-on module marathon and completed the entire course in one go.

Rewriting My Notes for Deeper Understanding

Throughout this journey, I focused on restructuring and refining my notes for better comprehension and future reference. This approach helped reinforce key concepts, making them easier to recall and apply. While I gained a solid grasp of most topics, a few areas still require additional study and hands-on practice.

Areas for Further Exploration

Even after completing the course, I identified a few knowledge gaps that I need to address:

  • SQL Injection – While I understand the core mechanics, some advanced SQLi exploitation techniques remain unclear to me.
  • Cross-Site Request Forgery (CSRF) – I need to deepen my understanding of how to reliably trigger CSRF attacks in real-world scenarios.
  • Web Services and API Attacks – This module was particularly interesting, but I still have questions regarding Web Services Description Language (WSDL) and its role in SOAPAction spoofing.

To strengthen my skills in these areas, I plan to leverage PortSwigger Academy (https://portswigger.net/web-security) as a reference and training resource. The hands-on labs there should help me refine my understanding and execution of these attack techniques.

Next Steps: More API and Web Attacks

While reviewing my weaker areas, I will also be moving forward with additional learning. My next focus will be tackling the new API Attacks, Attacking GraphQL, and Web Fuzzing modules on HTB Academy. These topics are increasingly relevant in modern web security assessments, and I’m excited to see how they build upon what I’ve already learned.

Final Thoughts

Completing the HTB CBBH course in a single stretch was a challenge, but it was well worth the effort. Now, my priority is reinforcing and expanding my knowledge through targeted practice, additional research, and real-world application. I’ll be documenting my progress as I tackle these gaps and explore the new HTB Academy modules.

If you’re also going through the HTB CBBH course or working on similar topics, feel free to connect.