Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 26 guests online
 
Advertisement

You are here: Home
EH-Net
May 25, 2013, 03:53:39 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1]
1  Ethical Hacking Discussions and Related Certifications / General Certification / Re: Certification plans for 2013? on: November 25, 2012, 08:13:09 AM
Hi all,

Depends on my financial status for 2013 and of course, work!

January 2013 - going for another python programming course. Maybe also do the online cloud security cert ...

June 2013 - do one SANS cert ... GCIH, if I can get into the work-study program.

After June ... maybe between July - Dec 2013 - the OSCP.

Have gotten CEH, ECSA ... and in the midst of SPSE ... juggling between studying for the certs and work and personal stuffs right now ...
2  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: Career in CEH on: November 25, 2012, 07:55:28 AM
Hi,

This is my first posting here but I do feel the need to pitch in a bit on this topic to share my experience on pentesting and those certs.

After I did my CEH & ECSA certifications, I did find that opportunities in IT Sec opened up for me.

Got my first pen testing job bcoz of the certs (the client wanted pentesters with a CEH) ... though it didn't prepare me enough for the real-life pentest situation.

I can't really disclose the details (signed an NDA) but my team and I had to pentest more than 50 servers for an organization, and though the certs did give tools and methodology on pentesting, I had to read and learn and learn and learn on my own ... especially when it came to report writing. After 5 hectic 10-hour days of pentesting plus another 5 days for report-writing, thankfully we managed to complete the pentest...

The experience was excellent though coz it was real-life, not a lab and definitely not answering multiple choice. Had to do the whole drill - war driving, black-box pentesting, social engineering, testing & mapping the network, pwning the servers ... even to the point of DOSing 3 of them, though thankfully they weren't critical services.

So is it enough to have the 2 certs? Not really. after completing the certs, it's best to continue learning and reading up on security, latest vulnerabilities, new exploits, zero-days, etc ...

I consider the certs as a foundation to IT Sec and will continue to learn... whether the learning will lead to another certification or more practical experience ... it doesn't matter. Important thing is, you continue to update your knowledge. 

Pentesting of course is not just pentesting servers, some clients might want you to test their websites, web applications, their mobile apps ... so be prepared ... no two pentests are the same ... which is what makes it thrilling ... Smiley

So my advice to the OP, yeah go get ur certs ... but don't stop learning. You can't be a pentester by answering multiple choice Qs only.
You've got to actually DO the pentest ... if ur given a small pentest job to start with, even if it's testing the security of your friend's new app ... go for it... do it, learn from it ... and you'll get better and be ready for the next pentest job.

So what's next for me?
Maybe get one of those cloud security certs and of course, the coveted OSCP. Smiley

Cheerz.
Pages: [1]
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.068 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.