Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 38 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
An Ethical Hacker must have these skills...
EH-Net
May 24, 2013, 12:44:15 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
An Ethical Hacker must have these skills...
Pages:
1
...
3
4
[
5
]
Go Down
« previous
next »
Print
Author
Topic: An Ethical Hacker must have these skills... (Read 97803 times)
0 Members and 1 Guest are viewing this topic.
donchizy
Newbie
Offline
Posts: 1
Re: An Ethical Hacker must have these skills...
«
Reply #60 on:
November 13, 2010, 10:55:42 PM »
thank you all for the post it has been educating and at the same time confusing, i really need a mentor and someone to guide me, i am a student studing computer science, this is just me 2nd year but have a dream of becoming a CEH the big question is where do i start from which knowledge do i need before enbarking for the course. I will appretiate ur advice and thanks in advance.
Logged
chrisj
Hero Member
Offline
Posts: 1163
Re: An Ethical Hacker must have these skills...
«
Reply #61 on:
November 13, 2010, 11:13:25 PM »
It would help if we knew what you already had good grounding in. Also what besides or why do you want a CEH? Do you want it just to have it? Do you want it as a stepping stone to something else?
How are you at Networking, System Administration and programming? What hacking have you looked at or tried? Do you know Virtualization yet?
Couple of things to look into:
The rest of this site. Including the Features tabs where things get reviewed.
Hacking For Dummies (it's a good start).
Hacking Dojo
Infosec Mentors (not a bad program. I have or had a mentor, but we didn't really click).
Offensive Security's WiFu course.
The Security + cert (Appears to give a broad overview of all aspects of security).
Logged
OSWP, Sec+
peta909
Newbie
Offline
Posts: 3
Re: An Ethical Hacker must have these skills...
«
Reply #62 on:
June 01, 2011, 09:17:52 PM »
Hi, I frame my learning process into 3 main parts:
1. Host
Learn to be comfortable using and configuring both Windows based and Linux based OSes.
I have a laptop that I dual boot to have both windows and Backtrack. By forcing myself to use Backtrack(linux) I was able to learn many linux commands fast.
2. Applications
Learn to built your own website with any language E.g. PHP
Learn to configure web application servers E.g. Apache or IIS
Learn to configure databases E.g. MySQL
3. Networks
Read up on TCP/IP and understand how packets flow and formed in the networks.
A very good book to start reading is TCP/IP Illustrated. However, do note that it is very dry.
Make use of wireshark to collect network traffic while you start surfing the web. By looking at the packets collected and cross reference to TCP/IP Illustrated book you can learn alot about networks.
Last but not least google is your friend. God Bless.
Logged
El33tsamurai
Full Member
Offline
Posts: 192
Re: An Ethical Hacker must have these skills...
«
Reply #63 on:
June 21, 2011, 01:38:59 PM »
I would say able to read and spend many hours reading about this stuff. I find myself going online and watching tutorials , reading forums and websites like ethicalhacker.net, going to the local book store reading hacking books and hacking mags like hakin9. The more I read the more I learn and can add to my ethical hacking skills.
Logged
CCENT, A+, Network+, Security+
YuckTheFankees
Sr. Member
Offline
Posts: 324
Re: An Ethical Hacker must have these skills...
«
Reply #64 on:
October 15, 2011, 12:57:51 PM »
peta909,
Very good post! I pretty much have 1 and 3 taken care of but I'm a little weak in the application area. I'll be able to improve my web application server knowledge through my linux +/ red hat training..PHP I can learn online..and I havent figured out MySQL yet. Great Thread!
Logged
OSCP in progress
millwalll
Guest
Re: An Ethical Hacker must have these skills...
«
Reply #65 on:
October 17, 2011, 03:47:24 AM »
I think it all depends on what area you want to work in. Most of what I have learned has been from doing tutorials and watching video and mostly network stuff. I landed a job a fews months ago that required me to test web apps so now in process trying learn as much as I can about web apps.
It might also be useful to stick with what you know to start off with if you good network then try learn as much as you can about them.
Logged
charliemong
Newbie
Offline
Posts: 22
Re: An Ethical Hacker must have these skills...
«
Reply #66 on:
November 03, 2011, 02:36:59 PM »
Quote from: rance on March 11, 2008, 11:36:11 AM
Quote from: pseud0 on March 05, 2008, 12:36:02 PM
Necessary ethical hacker skills, the starter edition:
TCP/IP
OS basics for M$ and the *IX distro of your choice
Internal network basics (switches, hubs, firewalls)
A sense of humor (preferably dirty but manic is also acceptable)
External network basics (routing, IP, interaction with internal networks, etc)
Relationship between services, ports, and how exploits work
Washboard abs
Some familiarity with coding (not expert, but can muddle through)
Understanding of general web application construction (front/back end, etc)
A WOW account (maybe EverQuest if you roll like that)
Some level of business sense (need to explain business impact of your findings)
A comfort level with your skin tone being 3 shades more pasty than your racial peers
Washboard abs?! Well, that disqualifies almost everyone I know in IT.
The skin complexion though? Got that one nailed...
Am with you on the skin tone but Abs??? try AB! lol
Logged
If you know the enemy and know yourself, you need not fear the result of a hundred battles. If you know yourself but not the enemy, for every victory gained you will also suffer a defeat. If you know neither the enemy nor yourself, you will succumb in every battle.
- Sun Tzu
Abmart
Newbie
Offline
Posts: 6
Re: An Ethical Hacker must have these skills...
«
Reply #67 on:
December 13, 2011, 09:02:06 AM »
Hi everyone in the house, I am newbie here, I don't even know where to start from now so please if anyone know or have ebook on ethical hacking should please help me with it.
Logged
tamato
Newbie
Offline
Posts: 5
Linux: Because rebooting is for adding hardware
Re: An Ethical Hacker must have these skills...
«
Reply #68 on:
July 20, 2012, 05:11:55 AM »
Hi Guys
verry soon i will be writing my CEH and am shit scared in going because i do understand the concepts and the phaxes and all of that
The only part is when it comes to actually doing and implementing it
Ive brokeinto a few of my wifi AP to try out aircrack and played with DVWA but the thing is i keep hitting a brick wall
I scan a victim then see the open ports and google up the vulns but there after
clueless
Ive also tried the metasploit and understand but only thing that worked was the MS068 smb vulns thereafter zip ...and i dont think its verry practical in running the automation tools (as the ceh instructor said)
I just need someone to help me in setting an enviroment and breaking into there to uinderstand what happens etc
If some one would be willing to help please
I pretty much feel useless
My biggest dream is to get really good so to build a name for myself and i keep getting this wall
Logged
3xban
Hero Member
Offline
Posts: 608
Re: An Ethical Hacker must have these skills...
«
Reply #69 on:
July 21, 2012, 06:19:48 AM »
CEH is a generalization, an intro into ethical hacking. It will not make you a pro overnight. If you hit a wall, make a list of what you know about the network, if you have open ports, note them. They may not have any known vulnerability surrounding the service in particular, but they can be used later to get data in or out depending on something internal. For instance, you hit a firewall that has say port 25/80/21/22/443 open. Hopefully the engineer did not filter what internal clients can go out through those (proxy only or other filtering systems). So you scan the firewall, check to see if you can enumerate the services and see if any are vulnerable to exploits that may allow you through the firewall. Well the web servers may have some clues. The FTP and SSH ports may be susceptible to brute-forcing, but you will need accounts to use. 443 may be worth a look, they may have a "secure" web site that has some nice information they believe is protected. You will need to do some recon from data you have access to. If all attempts to gain access from the outside fail, well now you need to look at gaining it from the inside. You will need to exercise some social engineering skills. For lab purposes you are looking at exploiting a flaw in a 3rd party app such as flash, adobe reader or Internet Explorer. You can use metasploit to create the payload and the listener (remember those open ports on the firewall).
Good luck oh and if you decide to pursue OSCP, don't forget to try harder
Logged
Certs: GCWN
(@)Dewser
Andrew Waite
Hero Member
Offline
Posts: 928
Re: An Ethical Hacker must have these skills...
«
Reply #70 on:
July 22, 2012, 10:24:50 AM »
Quote from: tamato on July 20, 2012, 05:11:55 AM
I just need someone to help me in setting an enviroment and breaking into there to uinderstand what happens etc
Easiest way to start a test environment is to get a virtualisation playground (either dedicated box, or just from your main machine) and attack some vulnerable virtual systems.
Depending on your needs
Samurai WTF
contains some vulnerable web applications (including DVWA which you mention), and all the tools needed to attack them, all in one handy package.
For more information, take a look at
section 2 of Metasploit Unleased
(and Metasploit Unleashed in it's entirety) and/or Rapid7's article on
how to setup a test lab
. Both of which also link to some good additional resources for acquiring and setting up intentionally vulnerable targets.
HTH, happy hacking
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
tamato
Newbie
Offline
Posts: 5
Linux: Because rebooting is for adding hardware
Re: An Ethical Hacker must have these skills...
«
Reply #71 on:
July 23, 2012, 01:56:40 AM »
Thanks again guys
I will go and have a bash once again
and see how far the rabbit hole i can go
Will keep you posted
Logged
Pages:
1
...
3
4
[
5
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(28) by
don
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(6) by
azmatt
Greetings
: Hi from the UK
(4) by
MrTuxracer
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(0) by
prats84
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.