Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 28 guests and 2 members online
 
Advertisement

You are here: Home
EH-Net
May 19, 2013, 01:59:45 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 2 3 [4] 5
46  Ethical Hacking Discussions and Related Certifications / OSCP - Offensive Security Certified Professional / Re: Need Guidance from gurus on: November 24, 2011, 07:27:22 AM
Hey Manikanta..

I hail from the same city, Bangalore. Good to see that people are getting into security field Smiley

You are at the right place (EHnet) for guidance
I think other members gave u a good insight into what u need for OSCP.
From the syllabus of OSCP it's clear that the course is more about network security than about Web App's security. So your CCNP level skills will come handy and other things u might need will be: Some basic skill in scripting language(Python/Perl/PHP), Able to read(understand) Assembly language code, Linux skills and before you enroll, boot ur BackTrack and try to get comfortable with some important security tools so that when you get on the labs, You can straight away start practicing than wasting valuable time trying to figure out how things work
And most importantly, get yourself ready to do lots and lots of research on own, manage your time... and always TRY HARDER  Grin
I am planning to do OSCP some time around early 2012, so keep posting your progress and I might hassle you about OSCP when I am ready to take up the certification  Tongue
47  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Hardware you should have during an onsite pentest? on: November 23, 2011, 10:44:00 AM
I once had a faculty who was a professional Incident response handler, I had a chance to peep into his 'Jump bag' and they carry so much, things like screw drivers, spare screws and variety of hardware interfaces to connect to devices on site Smiley . And he used to say never steal from your own jump bag Cheesy
48  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: SecurityTube Metasploit Framework Expert (SMFE) Certification on: November 23, 2011, 06:32:23 AM
This course seems affordable, not too pricy. For me I dont need dead lines and stuff to work/learn so I am not enrolling, I mean I can manage with the free material available (Vivek's Mega primer and Metasploit book).. But I highly recommend this course for some one who wanna learn the in and out of Metasploit Smiley

@Jamie. R - I am looking forward to take some Web App's certification too, you got any ideas on mind. I am a novice when it come to Web App's stuff, just learning basics now.
49  Resources / Tutorials / Re: Free hacking ebooks on: November 23, 2011, 01:50:32 AM
Well, I am sure there are a lot of places where you can download this kind of free stuff but this is not a right place to post/share this stuff.. this site is clearly an Ethical Hacker Network Embarrassed
50  Ethical Hacking Discussions and Related Certifications / Other / Re: Internet Question on Browsing on: November 22, 2011, 10:26:22 PM
HTTPS Everywhere is a Firefox extension produced as a collaboration between The Tor Project and the Electronic Frontier Foundation. It encrypts your communications with a number of major websites

https://www.eff.org/https-everywhere
51  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Hardware you should have during an onsite pentest? on: November 22, 2011, 10:01:44 PM
I have never been on any professional pen test  Tongue
but let me add to the list..

Network hub or switch
Live CD's
Blank CD/DVD's
Power strip
52  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / SecurityTube Metasploit Framework Expert (SMFE) Certification on: November 22, 2011, 09:23:33 PM
Securitytube folks did it again..

SecurityTube Metasploit Framework Expert (SMFE) Certification an online certification on the Metasploit Framework.
http://www.securitytube.net/smfe

So any body interested in enrolling??
53  Resources / Tools / Re: SecTools.Org Relaunched - 2011 on: November 07, 2011, 01:12:06 PM
Never heard of it  , thats nice  Cool

Nothing to do with this thread, but any one tried this site:
http://www.hackertyper.com/  Grin
54  Ethical Hacking Discussions and Related Certifications / Wireless / Re: Wireless Network Security - Thesis on: November 04, 2011, 11:28:10 PM
Hey piersf, Welcome to the forums  Smiley

These links will be helpful for you to learn about Wireless Networks Security and also for your thesis:

http://www.willhackforsushi.com/
http://packetstormsecurity.org/papers/wireless/
Hacking Exposed Wireless, 2nd Edition

if you want to learn more about tools:
BackTrack 5 Wireless Penetration Testing Beginner’s Guide book
http://www.aircrack-ng.org/
55  Features / Book Reviews / Re: Has anyone read BackTrack 5 wireless pentesting? on: October 30, 2011, 10:46:01 AM
This book is really more of doing and less of theory.

By the time time you finish third chapter you would have already started to learn stuff like Bypassing security measures ( Hidden SSID's and Mac filters. )

I am planning to take OSWP this December, as OSWP needs to setup your own lab and basic linux skills, I bet this book comes really handy.

Before taking OSWP I want to finish the following

CWNA official guide : for WLAN basics
Hacking Exposed Wireless 2nd Edition - Solid book
BackTrack 5 Wireless Penetration Testing Beginner’s Guide book
and Wireless Hacking Megaprimer by Vivek

I think this list would be really enough to get through OSWP course smoothly.
56  Ethical Hacking Discussions and Related Certifications / Programming / Re: Python tools on: October 30, 2011, 10:35:59 AM
I have both Python 2.7 & 3.1 installed on my Ubuntu box  Smiley

The major difference that between these two versions is Python 3 has limited library support and the fact that most current Linux distributions has Python 2.6 - 2.7 as default.
If you are just in learning phase of the language I think any of these versions should go smooth.
57  Ethical Hacking Discussions and Related Certifications / Malware / Re: Looking for a windows trojan on: October 30, 2011, 03:47:22 AM
Trojans  Roll Eyes

Well.. I prefer using Dark Comet 4, it has been recently released and has fully undetectable features n stuff like that, there is a Mac version coming soon.
http://www.darkcomet-rat.com/
58  Resources / Career Central / Re: Where to start on: October 24, 2011, 02:49:41 AM
idr0p mentioned the best books on web application security.

Regarding other resources, OWASP has some rich content regarding Web Apps Security. https://www.owasp.org/

And they are some deliberately vulnerable applications available, that lets you practice your skills on. Take a look at Webgoat, Metasploitable.
http://www.metasploit.com/about/how-do-i-use-it/test-lab.jsp
59  Resources / Career Central / Re: My new career path..tell me what you think? on: October 22, 2011, 10:20:48 PM
I am more interested in Network part of Security. For now most of my learning part is going on self pace, thanks to my college library for having awesome books.
One major reason that I aint going for any certs now is not having $$  Tongue
I can be pretty stingy on things  Grin but I really don't mind spending money on two things:
- Hardware
- Good Documentation

My path is some thing like:
- Linux Skills (Self pace) - there is a huge amount of material online.
- Protocols (TCP/IP...) - some good books like TCP/IP Illustrated
- nmap - lucky to have Fyodor's book at library
- Wireshark Skills - Wireshark has really nice user guide and wiki.(and lots n lots of practice)
- Higher concepts like Firewall's and IDS
- Python Skills - there are plenty of good books(some are free), this is something I have been focusing mostly on because at some point you feel like you can't turn your ideas into code. So my focus is more on coding.
 
This list and some others  will keep me busy for quite some time.

My certification path would be something like:
CWNA - To get started with wireless things.
OSWP - getting deeper into wireless security
OSCP  - Once I am comfortable with the above skill (and some other skills) I am going for OSCP. I am not in for eCPPT, as it covers almost the same stuff like OSCP except it focuses more on Web App's security.

Coming to your point,
"Linux +" skills will be pretty much fine for going further into security. if you have time & bucks, you can consider RH certs.

In the wireless portion, I would rather suggest to focus on CWNP certs because they are vendor neutral certifications.
After CWNP certs, as your focus is wireless you can go for OSWP, that course is pretty nicely laid out. SANS certs are good but they come with a big $$, I feel like Offensive Security certs come with a good learning curve and are not too pricey for what they offer. GPEN would be a nice place to start with.

eCPPT is good with the Web Apps security modules and you can also take a look at "So You Want To Be A Web App Pentester" by Joe McCray.
60  Ethical Hacking Discussions and Related Certifications / Programming / Re: Python tools on: October 21, 2011, 12:44:32 PM
+1 for Eclipse with Pydev
And I use gedit on Ubuntu most of the time
Pages: 1 2 3 [4] 5
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.067 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.