Has anyone taken any of the stanford security courses. They look more towards learning how attacks work and defending against them rather than a specific pen test, web app assessment methodology, but look pretty good?
There is no official study material. However I believe that knowledge of Windows, Linux and web apps is required. So if you were to read Hacking exposed Windows and Linux Editions, network security assessment and Web application hackers handbook, these should suffice I believe
Just wondered if anyone has purchased the "Metasploit: The Penetration Tester's Guide?" If so, how much more depth does the book have in comparison to the freely available "Metasploit Unleashed" guide and the "Metaspploit Megaprimer" videos by Vivek?
CREST CCT and CHECK TL status is certainly what you want to aim for in the UK. CREST actually do a CRT course that is classed as "intermediate" level and only costs £395 + VAT. Its an exam that CREST recommend taking before the CCT exam. This could be an option for you as having this is more than likely to get you a junior role as a Pen Tester in the UK and if you do the CISSP you should be well away.
Ok, obviously eveyone perfoms tasks completely different and am curious as to what scanners use guys use and the nmap switches you guys feel are most effective. So if you were assigned a public address range of 20 hosts and didnt know whether there was an IDS/IPS in place how would you go about performing the scan being as stealthy as possible?
I attended your course for around 2 months when it was first released, but due to several commitments I had to pull out for a while and am intending to rejoin in March. Is it possible to kick off at the Nidan level?