Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 83 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum
EH-Net
May 16, 2012, 04:43:52 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 [2] 3 4 ... 15
16  Resources / Career Central / Re: Good news! on: December 06, 2011, 07:32:41 PM
Maybe it's just me, but I would edit the post......
17  Resources / Career Central / Re: Good news! on: December 01, 2011, 08:00:19 AM
Well played Sir, well played !!!!!! Epic congratz.......
18  EH-Net / News Items and General Discussion About EH-Net / Re: Happy Thanksgiving from The Ethical Hacker Network on: November 24, 2011, 11:01:51 AM
Thanks for making this great resource available. This site was instrumental in helping me decide my certification/career path. I have learned so much from ALL of you over the years.

Thanks much guys.
 
19  Resources / Tutorials / Re: Free hacking ebooks on: November 23, 2011, 07:23:42 PM
Consider this....
http://blather.michaelwlucas.com/archives/1038?utm_source=twitterfeed&utm_medium=twitter
20  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: Need Guidance from gurus on: November 23, 2011, 05:10:21 PM
@manikanth - Try Harder Smiley
21  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Mile2 says CPTE is a much better cert than CEH. True? on: November 04, 2011, 07:01:06 PM
I'm about to submit my training request at work.  So if you're in my position with the certs I have, what would you do?  

CEHv7 (in person) for $2500 (including exam voucher)
   OR
CPTE  (live virtual training) for $3000 + exam fee

I'm also going to ask about CCNA bootcamp.
Neither. I would shoot for the OSCP. And if your ok with spending 3K+ I would consider SANS GPEN. It all depends on your goals.
22  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: Hi all I need an advice about the oscp on: November 01, 2011, 09:22:40 PM
thank u.
i am starting the course in 06-11-11  Smiley
wish me luck i will need it i guess
There will come a point when you will feel like calling it quits. And the constant refrain of " Try Harder" won't help either. At that point, take a break, clear your mind and start again. Rinse and repeat.

Have fun. It's GREAT course.
23  Resources / Career Central / Wanted: Software Security Specialists, Engineers, Testers ...but are there any? on: November 01, 2011, 08:25:40 PM
An interesting read.....

http://h30499.www3.hp.com/t5/Following-the-White-Rabbit-A/Wanted-Software-Security-Specialists-Engineers-Testers-but-are/ba-p/5360357

Not enough skilled infosec pros to go around......

What has been your experience?
24  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Infosec Institute plagiarized course material from Corelan.be on: November 01, 2011, 07:28:54 PM
Well done. Hopefully the follow through on the promises is carried out fully.  Delayed or not, it is refreshing to see an organization address an issue like this head on.
Goes to show the power of the collective.
25  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Infosec Institute plagiarized course material from Corelan.be on: November 01, 2011, 06:46:00 PM
Infosec is making it right
http://resources.infosecinstitute.com/corelan-public-apology/
26  Ethical Hacking Discussions and Related Certifications / General Certification / Infosec Institute plagiarized course material from Corelan.be on: October 30, 2011, 01:07:21 PM
http://attrition.org/errata/plagiarism/infosec_institute/
27  Resources / Links to cool sites. / Re: Down the Security Rabbithole - Podcast by Rafal Los on: October 25, 2011, 06:33:16 PM
@chrisj The audio is a bit low in the beginning but it gets better as you go along.
28  Resources / Links to cool sites. / Re: Down the Security Rabbithole - Podcast by Rafal Los on: October 24, 2011, 10:03:33 PM
I gave it more than listen actually. I am a guest on Episode 4 - Effective Small Business Security.

I along with Raf and J. Goerlich discuss this very interesting topic.I really had a great time. And it was a fun discussion.

Raf and J. Goerlich have a huge wealth of knowledge between them.
29  Resources / Career Central / Re: Looking for advice for career path as a Ethical Hacker on: October 19, 2011, 08:29:02 PM
I think you need to pick your own poison and go from there. Think of security in terms of a baseball team. Here you are saying: "I want to play which position should I aim for?" What are your strengths and weaknesses. Focus on your weaknesses to bring them up to par with your strengths while in parallel upping your strengths.

In security, there are a lot of avenues to choose from. Forensics, pentesting, application security, cryptography, networking, etc. Each have their unique methodologies, technologies, protocols, pros and cons.

Examples:

++++++++++

Forensics. Where would you want to fit in? Working as an incident responder researching malware, researching e-Discovery, researching the cause of a compromise? What field? Pros: Banking, insurance, defense industries, huge Fortune 100s are always in demand for these types of individuals.

Cons: Job can be linear, stressful, repetitive.

Certifications: (real world relevant) GCFE, GCFA, EnCe, GCIH, ACE, CCE, GREM, WCNA (Wireshark), GCIA

++++++++++

Pentesting: Where would you want to fit in? Define pentesting. Too many companies have turned this field into a tool (Core Impact, Metasploit, Nessus, etc) however there is more to pentesting than running tools. In order to fit into a well rounded position, the document I linked you too will give you excellent foundations needed. You then need to progress into a more linear stage (focus on applications (which web application, business applications (SAP, etc)).

Pros: Can be fun, creative, non-linear (no two pentests are ever the same)

Cons: Industry has created too many retards that rely far too much on tools. Many industries are now mandated to have penetration testing (PCI requirement). With that stated, many companies are relying on point and click drop boxes (QualysGuard) and calling it a "pentesting day."

Certifications: (the ones that count) GPEN, CEPT, OSCP, OSCE, CPT, RWSP

++++++++++

Network security: Where would you want to fit in? Managing firewalls, IPS, IDS, DLP, acronym hell? Performing network analysis' with tools and hardware such as nGenius, Netwitness, Wireshark, etc., this can criss-cross the forensics realm.

Pros: ALL COMPANIES need network security period.

Cons: Can be as linear as in point A to point B

Certifications: (ones that count) WCNA, CC{N,D,S}P, GCIH, GSEC

++++++++++

Take note, all the certifications I listed are TECHNICAL, for those wondering why CISM, CISA, CGEIT, CISSP, etc isn't listed. And NO, the SSCP to me is not a technical cert. When I state "ones that count / relevant" I mean the ones you *truly* want to aim for as you WILL LEARN while getting them. Not to take anything away from say the C|EH, CHFI but it is what it is. I felt the certifications I listed would help you LEARN something as opposed to dumping a billion tools on your lap and telling you "hey this is a security tool, learn this tool's syntax and we will give you a shiny certificate!"

Your best bet regardless of any advice you see from me or anyone else is to determine something that you can enjoy while making money. I would hate to focus on Forensics only to have a job I hated doing e-Discovery 24x7x365. I know people that dread getting into the field. They work to dissect/analyze info, go to court, are stressed out as all hell. The money they make doesn't cover sanity, happiness.

Go over to Dice.com and check the markets for certs also. Search for the certification itself to see its demand and WHO is asking for that particular cert. That is a good baseline as is e.g:

http://www.payscale.com/research/US/Certification=Certified_Ethical_Hacker_%28CEH%29/Salary
http://www.payscale.com/research/US/Certification=SANS%2fGIAC_Security_Essentials_Certification_%28GSEC%29/Salary
http://www.payscale.com/research/US/Certification=SANS%2fGIAC_Certified_Intrusion_Analyst_%28GCIA%29/Salary
http://www.payscale.com/research/US/Certification=SANS%2fGIAC_Certified_Forensic_Analyst_%28GCFA%29/Salary
http://www.indeed.com/salary/q-Forensic-Consultant-Ence-l-New-York,-NY.html
http://www.indeed.com/salary?q1=GREM&l1=New+York%2C+NY

Hope that helps

How did I miss this??? Great post Sil....I also agree that this post should be a sticky.
30  Ethical Hacking Discussions and Related Certifications / General Certification / Re: SANS 25% off till 10-26-2011 on: October 18, 2011, 09:42:08 PM
Ok so SANS is expensive....but I believe that if you really want something you will find a way to get it. It's like exercising. A lot of folks will tell you that they have no time to go the gym. They have work, family, school and the list goes on. Yet when they are told by an MD that they risk dying if they do not start exercising. They suddenly find the time and resources.

The same hold true to these expensive certifications. It all depends on just how much you want it and the sacrifices you ar willing to make. What is the ROI?

 A lot of the certs you see in my sig were personally funded. Do I have a high paying job? No. But you do what you have to.

My .02
Pages: 1 [2] 3 4 ... 15
Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.076 seconds with 21 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.