EH-Net

Resources => Career Central => Topic started by: variable on April 25, 2012, 02:50:13 PM



Title: Pen Test Interview Soon
Post by: variable on April 25, 2012, 02:50:13 PM
I have an interview lined up for a pen testing job next week.  I do have a computer security background but I am relatively new to pen testing.   I was told there will be a virtual box setup that i am suppose to compromise and then writeup a report when im done scanning/testing/hacking.   My question is what sort of tools/preparation would you take into an interview like this?   What sort of criteria would YOU want to see on a report.  Any advice is helpful. 


Title: Re: Pen Test Interview Soon
Post by: ajohnson on April 25, 2012, 02:57:54 PM
Can you bring BackTrack in? That should provide more than you need to do the tasks at hand.

This is a great resource for a report template: http://www.offensive-security.com/offsec/sample-penetration-test-report/

Do you have any specific questions on the process? There's unfortunately no secret that will magically make you a pen tester in a matter of days.


Title: Re: Pen Test Interview Soon
Post by: BillV on April 25, 2012, 03:01:43 PM
Were you told to bring your own system to attack from or will that be provided for you?

Certainly, in addition to the technical skills, they will want to see how well you can report on it. I would recommend reading this blog post:
http://pen-testing.sans.org/blog/2012/02/09/maximizing-value-in-pen-testing

I would want to see that you can summarize the findings in a non-technical summary and that you can present the risk appropriately. I would want to see what your thought process is on how you rate risks - in other words, for this purpose, I wouldn't care what you rated findings so long as you provided thoughtful support. I would also be looking at how you tell me to fix the problem.


Title: Re: Pen Test Interview Soon
Post by: variable on April 25, 2012, 03:21:08 PM
As far as I know I cant bring in a system.  It will be a lab enviroment with a VM windows machine at a logon prompt and anything goes from there.  Its just a basic test to see if you can bypass authentication, gain root, find what services are running and wheter or not you can compromise them.  The more prepared the better off I am.  What interview questions would you ask someone for a entry level pen-test job?


Title: Re: Pen Test Interview Soon
Post by: ajohnson on April 25, 2012, 03:40:34 PM
Start with this: http://resources.infosecinstitute.com/ideal-skill-set-for-the-penetration-testing/

And review an alternate perspective: http://www.thehackeracademy.com/the-key-skill-set-of-great-penetration-testers/

And as Bill alluded to, the most important thing is your thought process and cognitive capabilities. It's relatively easy to remedy technical gaps of knowledge, but it's much more difficult to improve someone's problem solving skills.

That test sounds odd. You're just sat in front of a single Windows system, and there's no attack system? Maybe they're testing you to see how prepared you are. Bring in a bootable Backtrack USB thumb drive and know how to add/change Windows accounts once booted to that (obviously make sure that's allowed).


Title: Re: Pen Test Interview Soon
Post by: Agoonie on May 11, 2012, 09:03:16 AM
I have an interview lined up for a pen testing job next week.  I do have a computer security background but I am relatively new to pen testing.   I was told there will be a virtual box setup that i am suppose to compromise and then writeup a report when im done scanning/testing/hacking.   My question is what sort of tools/preparation would you take into an interview like this?   What sort of criteria would YOU want to see on a report.  Any advice is helpful. 

How did the interview go?  Was it everything you thought would happen or did they through surprises during the interview?


Title: Re: Pen Test Interview Soon
Post by: impelse on May 12, 2012, 06:34:00 PM
When I was reading this post, I was expecting to see the result of the interview.lol



Title: Re: Pen Test Interview Soon
Post by: 3xban on May 14, 2012, 09:57:17 AM
I know, left us hanging and all.