|
EH-Net
|
|
May 23, 2013, 01:13:08 PM
|
Show Posts
|
|
Pages: 1 ... 3 4 [5] 6
|
|
61
|
Columns / Editor-In-Chief / Re: [Article]-CASP – The Evolution of Technical Security Certifications?
|
on: December 02, 2011, 10:53:45 AM
|
|
I always ask about OSI model in the interview. It just seems like a good way to find a starting place. I don't even necessarily expect people to dig deep, just tell me 7 layers and name them. Once you start discussing TCP/IP and packet structure in depth that is more what I'm interested in than the theory.
tturner - I agree with you on the applicant fail, but it should be both ways. How did this person get the cert? Exactly how you described, paper mill studying got the rubber stamp and now his resume has every CompTIA cert on it.
3xban - I am still LOL about the 3 days per SOHO, you could take one apart, put it back together, and configure it in 2 hours!
|
|
|
|
|
63
|
Ethical Hacking Discussions and Related Certifications / General Certification / Re: Experience vs Certifications
|
on: December 02, 2011, 12:03:59 AM
|
Hang in there. I spent six years working my ass off trying to get into security; it didn't just happen. I started off by taking over the IT responsibilities of a company of five people (it wasn't my primary responsibility), moved to a company of about 30 people, and then went to a managed services provider before I finally got a full-time security position. You need to start wherever you can get your foot in the door and work your way into what you want from there.
This is the best path to get into a full time security position. Take over, and the job will come ...
|
|
|
|
|
64
|
Columns / Editor-In-Chief / Re: [Article]-CASP – The Evolution of Technical Security Certifications?
|
on: December 01, 2011, 11:45:58 PM
|
I've been a CompTIA cert holder since 1999 and have never been very impressed with their programs.
I hate to sound negative because it does look like they're exploring expansion of their current space, but I recently interviewed for a position on my team and two of the candidates who were brought in had A+, Sec+, and Network+, yet were extremely unqualified. Perhaps it's just a caveat emptor for certifications altogether, but if someone has those and can't explain the OSI model (as I always ask in interviews) then clearly a goal has been missed. Perhaps prereqs should be higher?
|
|
|
|
|
65
|
Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: Problematic Pen Testing situation
|
on: December 01, 2011, 10:33:30 PM
|
|
This issue was finally resolved for anyone interested or not interested.
We ended up working w/ the client and mapped out a plan w/ similar objectives from our preferred pen test contractor and the client accepted this. The test completed today and surprisingly, no high or urgent vulnerabilities were found. I guess my paranoia probably got to me on this one, but at the end of the day, we found no issues, and this particular problem was what caused me to seek out advice from the crew at ethicalhacker.net and become a registered user. Thanks to everyone for commentary and input, it's a wonderful site.
|
|
|
|
|
66
|
Ethical Hacking Discussions and Related Certifications / Programming / Re: How to learn PERL!
|
on: December 01, 2011, 10:22:44 PM
|
PowerShell is pretty sweet, the Stop-Process cmdlet is the first thing I've seen from MSFT that actually operates the way kill would in *nix. I guess I'd suggest just focusing on a few items that need to be scripted, plotting out the logic, then writing them in a different language until you find one you really feel comes naturally to you. Taking that first step into programming/scripting is scary if from a non-dev background but after a few months of doing it you'll look back and be like wtf took me so long 
|
|
|
|
|
73
|
Resources / Tutorials / Re: how to exploit iis 6
|
on: November 30, 2011, 10:14:32 PM
|
|
I think before you just start going through tools, you should map out your plan for the demonstration. As you're using Metasploit ...
Intelligence Gathering Steps X,Y,Z Threat model X,Y,Z Known/Discovered Vulnerabilites X,Y,Z Exploitation (your Proof of concept) QED
Showing your boss a detailed plan and how you obtained the results would be more beneficial than what has been listed so far. Also, I'd be very careful if this is on a production box. Work in non-prod regions of SDLC if possible.
|
|
|
|
|
Loading...
|