EH-Net

Ethical Hacking Discussions and Related Certifications => Security => Topic started by: nxxw on September 15, 2012, 01:15:07 PM



Title: C|HFI or ECSA/LPT?
Post by: nxxw on September 15, 2012, 01:15:07 PM
Hello Guys,

out of C|HFI and ECSA/LPT what would be the best training to attend after C|EH? Your valuable ideas are most welcome.

Thanks in advance.


Title: Re: C|HFI or ECSA/LPT?
Post by: sh4d0wmanPP on September 16, 2012, 01:25:36 AM
Well they both cover a different field so it depends on what work you do or want to do. Besides that I would suggest to choose for a different organization as eccouncil is not highly regarded.

Instead of CHFI you could do an Encase cert.
Good alternatives for LPT would be: eCPPT or OSCP


Title: Re: C|HFI or ECSA/LPT?
Post by: nxxw on September 16, 2012, 01:29:19 AM
Well they both cover a different field so it depends on what work you do or want to do. Besides that I would suggest to choose for a different organization as eccouncil is not highly regarded.

Instead of CHFI you could do an Encase cert.
Good alternatives for LPT would be: eCPPT or OSCP

Thanks for your advice and I do agree with you  ;)

What if I'm getting a free pass to do one of them? Then what would you recommend?
There's no point in wasting the opportunity know.


Title: Re: C|HFI or ECSA/LPT?
Post by: SephStorm on September 16, 2012, 01:56:02 AM
I would do the ECSA/LPT over the CHFI, CHFI isnt really desired in the field, and there are relatively few forensic jobs out there from what I was hearing somewhere.


Title: Re: C|HFI or ECSA/LPT?
Post by: sh4d0wmanPP on September 16, 2012, 09:20:41 AM
If it's free and you have to choose then I'd stick with ECSA/LPT. Seems a bit more advanced than CHFI, that looks pretty basic... It might cover some of the pentesting that you can skip in the other mentioned certs and gives you some background.

Furthermore I agree with above poster, a lack of jobs. For example the country where I live right now does not have any computercrime laws. Forensics would be useless here but pentesting is something that could take off in the near future.

If you work for a CERT/CIRT I would recommend the CHFI though as it would give you at least basic knowledge of obtaining and handing evidence.

Well, whatever you choose please write a review on this site. I'd like to read it.


Title: Re: C|HFI or ECSA/LPT?
Post by: nxxw on September 16, 2012, 10:01:00 AM
If it's free and you have to choose then I'd stick with ECSA/LPT. Seems a bit more advanced than CHFI, that looks pretty basic... It might cover some of the pentesting that you can skip in the other mentioned certs and gives you some background.

Furthermore I agree with above poster, a lack of jobs. For example the country where I live right now does not have any computercrime laws. Forensics would be useless here but pentesting is something that could take off in the near future.

If you work for a CERT/CIRT I would recommend the CHFI though as it would give you at least basic knowledge of obtaining and handing evidence.

Well, whatever you choose please write a review on this site. I'd like to read it.

Thank you for the valuable explanation. :)
I thought it's just for me that CHFI looks pretty basic.  ;)
I'd like to have the forensic knowledge in addition to the pentesting knowledge but in this situation it seems like choosing ECSA/LPT over CHFI is worthy as I'm not involved in forensic stuff in my day to day chores.

Some people say it's better to do both CEH and CHFI before ECSA/LPT. I'm not sure to how much extent is this statement valid. Any ideas?


Title: Re: C|HFI or ECSA/LPT?
Post by: UNIX on September 16, 2012, 10:22:49 AM
Well, CEH and ECSA are required in order to be eligible to obtain LPT. I went this path without doing CHFI and didn't face any obstacles or similar.


Title: Re: C|HFI or ECSA/LPT?
Post by: nxxw on September 16, 2012, 10:35:06 AM
Well, CEH and ECSA are required in order to be eligible to obtain LPT. I went this path without doing CHFI and didn't face any obstacles or similar.

Do you think choosing ECSA was a good decision rather than going for CHFI?

ECSA/LPT is a single exam right? Or do I have to sit for LPT seperately?


Title: Re: C|HFI or ECSA/LPT?
Post by: nxxw on September 16, 2012, 10:44:06 AM
Oops, I just noticed that I'll have to pay an annual fee for EC-Council to maintain my LPT license. Is it worth paying $250 per annum to hold it?


Title: Re: C|HFI or ECSA/LPT?
Post by: UNIX on September 16, 2012, 10:47:39 AM
As already said, it really depends on your preferences and in which field you are working or want to get into. I did those certifications mainly for a couple of customers, as they are sometimes required.

ECSA is a single exam (with its own fees). After you have obtained both CEH and ECSA, you can apply for LPT, where you have to pay another fee (500 USD for the first two years; after that, 250 USD for each year).

E: If it's worth or not depends on your customers I guess. If it was just for myself, I probably wouldn't have bothered with them at all.


Title: Re: C|HFI or ECSA/LPT?
Post by: nxxw on September 16, 2012, 11:00:07 AM
I see. I'm going to do this just for myself, not for any customers or the employer (not yet at least).

Thank you for your valuable answer btw. (Y)


Title: Re: C|HFI or ECSA/LPT?
Post by: H1t M0nk3y on September 17, 2012, 06:25:05 AM
Hi nxxw,

What do you do on your day to day job? What are your long term goals? That would help us answer your question.

Most people agree that you can get better training somewhere else, but if you want to stick with EC-Council, maybe E|NSA would be the best thing for you?



Title: Re: C|HFI or ECSA/LPT?
Post by: nxxw on September 17, 2012, 06:36:17 AM
My daily tasks are network and datacenter administration, mainly systems. Why I'm interested in selecting one is that I can attend one of the above trainings and get the exam voucher for free at Hacker Halted this year. Why waste that chance? :D

I'd be continuing my current chores for another 1-2 years before I move into something else, say security. In the long run I'm kinda thinking of migrating towards the security side. Haven't decided whether it's gonna be be foresics or pentesting. :)

ENSA is not part of the offer and it's too basic.

Following are also part of the offer. :)

       CWSP   
   
       CAST 611 - Advanced Penetration Testing   
   
       CAST 612 - Advanced Mobile Hacking & Forensics   
   
       CAST 613 - Advanced Application Security   
   
       CAST 614 - Advanced Network Defense   
   
       CAST 615 - Hacking "Secure" Encryption and Countermeasures   
   
       CAST 616 - Securing Windows Infrastructure   
   
       CAST 617 - Advanced Metasploit Decoded   


Title: Re: C|HFI or ECSA/LPT?
Post by: H1t M0nk3y on September 17, 2012, 12:50:38 PM
"CAST 611 - Advanced Penetration Testing"

This course is very, very, very good. If I were you, I would jump on this one!!

I took it last year and it is the best course I ever had... Joe is a great teacher!!!


Title: Re: C|HFI or ECSA/LPT?
Post by: nxxw on September 17, 2012, 08:07:00 PM
I see. I've seen some videos of Joe and he's really good.

So I'll forget about the certs and go for the CAST then. :)


Title: Re: C|HFI or ECSA/LPT?
Post by: BillV on October 01, 2012, 07:18:06 PM
nxxw: Will you be taking one of these courses at Hacker Halted?


Title: Re: C|HFI or ECSA/LPT?
Post by: nxxw on October 01, 2012, 10:02:58 PM
Yep. You are also attending? ;)


Title: Re: C|HFI or ECSA/LPT?
Post by: BillV on October 02, 2012, 08:21:43 AM
Yes, I will be there. I am not taking a class but I will be at the conference portion (Oct. 29-30).


Title: Re: C|HFI or ECSA/LPT?
Post by: nxxw on October 02, 2012, 09:26:47 AM
I'm hoping to be there for the whole thing. Hope we'll meet then.

See you there.  8)