Day 1/90 days
Today marks the start of my 90-day AppSec execution journey, and I intentionally kicked off from the fundamentals. No shortcuts, no assumptions — just a clean, structured baseline to make sure every advanced skill I build next stands on solid ground.
I spent Day 1 revisiting the core pillars of how modern web applications actually behave under the hood:
Understanding HTTP mechanics (headers, cookies, sessions, caching)
Reviewing the OWASP WSTG Web Architecture standards
Reconfiguring my tooling:
Burp Suite browser integration
Re-establishing a clear mental model of how data flows from client → server → backend services
Relearning the basics isn’t a step backward it’s a strategic reset. Strong fundamentals accelerate everything that comes afterward: exploitation, API security, mobile testing, automation, and real-world offensive workflows.
linkedin.com/posts/gabrielod…
And here is my writeup on medium.
Understanding the Modern Web Attack Surface (AppSec)
medium.com/@gabbytech01/unde…