Being a security consultant involves rather less hacking then you might think it does. I'd strongly suggest talking to Thomas or whatnot and ask what goes into selling and delivering an engagement. Just like you shouldn't buy a restaurant just because you like cooking, don't get into security
consulting just because you like the idea of doing security
research.Also, SQL scanner on a site you have no relationship with is both a) really freaking obnoxious, b) potentially dangerous, and c) potentially civilly and criminally actionable.
If you want practice on doing security research, the Stripe and Matasano CTFs are really good. Other options include "Pick the 2nd or 3rd most popular OSS application in your favorite ecosystem and start reviewing the code for the top 10 OWASP vulnerabilities." Spend two weeks on that and you will find Horrible Things.