Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 25 guests and 2 members online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Certificationarrow The Charter Study Group - Pen Testarrow Intro Post
Ethical Hacker Community Forums
December 02, 2008, 12:31:39 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Intro Post  (Read 7473 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Online Online

Posts: 2380


Editor-In-Chief


View Profile WWW
« on: October 25, 2005, 11:24:24 PM »

Welcome to The Charter Member Study Group for ethical hacking and penetration testing. First we need to make some decisions.

Members:
don, dengar13, shavedlegs, mno, bilals91 and tmartin
Anyone else?

What is our focus?
CEH, CPTS or both
I say both. Since CEH is good to start but is slightly outdated and the CPTS is still in beta, we should start with CEH and have our goal to update our skills with CPTS. What say you?

Where to start?
Obvious first steps are to review the outlines, so we know what is headed our way. Then move quickly into some books for more detailed info.

I will take suggestions as to what should be next, but I think everyone should check in regularly with their progress whether or not they follow this outline.

Looking forward to hearing from the members,
Don

PS - If you haven't bought the materials, it would be cool if you used our Amazon link. The cost is the same to you, and we get to pay our hosting bills. Thanks in advance.
« Last Edit: October 25, 2005, 11:48:40 PM by don » Logged

CISSP, MCSE, CEH, Security+ SME
SanyaX
Newbie
*
Offline Offline

Posts: 0


View Profile
« Reply #1 on: October 26, 2005, 01:28:54 PM »

Hi Don

I am interested in CPTS or any other certification which does not need the Training pre-requisite. I want to go for self study mode. The CEH is not very difficult. As you have done CISSP, it should be a easy exam. A good exposure to basic security concepts is very helpfull. I am not sure for CPTS on how difficult it is. I think we should explore on exams/certifications, which does not have training pre-requisite as the training is many times a costly affair.

so for CTPS, I am in the group.

Thanks

Logged
Dengar13
Moderator
Full Member
*****
Offline Offline

Posts: 224



View Profile
« Reply #2 on: October 30, 2005, 10:06:20 AM »

Our focus should be both.  Pentesting is now apart of the latest version of the CEH exam and they should go hand-in-hand. 

Where to Start?  Let me personally add Hacking Exposed, 5th Edition.  It helped me immensly!
Logged

A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
Oyle
Sr. Member
****
Offline Offline

Posts: 264


"Man. Nature. Technology".


View Profile WWW
« Reply #3 on: April 04, 2006, 04:04:28 PM »

Hey, I'm in, too.

To user CEH -- NEVER EVER say an exam is easy; you know what will happen. Having too much confidence walking in to an exam may spell disaster. A lot of work went into creating these exams, I like to give them the respect they deserve. Consider them a challenge, yes, you maybe one of the people out there that do good at taking exams, but you need hands-on exp. for practically ALL exams on the market these days. Just some advice from little old test taker, me.

Don -- Yeah, sure, I can post questions for the threads, I just want to make it clear that I'm using the "older' version 3, before EC_Council came out with their "version 4" in May 05. Don't know if there's major difference between the two, but I want to make sure everyone knows it..

 
Logged

MCP, MCP+I, MCSA, MCSE(NT4/W2K), CCNA, CCA, NWCCC, VH-PIRTS, CEH
--------------------
"hackers are like jedi, crackers are like the sith: do not fall prey to the dark side".

From 1337 h4x0r h4ndb00k: "the ten laws of geek", law x
                  -Tapeworm
Dengar13
Moderator
Full Member
*****
Offline Offline

Posts: 224



View Profile
« Reply #4 on: April 04, 2006, 04:24:32 PM »

Hey, I'm in, too.

To user CEH -- NEVER EVER say an exam is easy; you know what will happen. Having too much confidence walking in to an exam may spell disaster. A lot of work went into creating these exams, I like to give them the respect they deserve. Consider them a challenge, yes, you maybe one of the people out there that do good at taking exams, but you need hands-on exp. for practically ALL exams on the market these days. Just some advice from little old test taker, me.

Don -- Yeah, sure, I can post questions for the threads, I just want to make it clear that I'm using the "older' version 3, before EC_Council came out with their "version 4" in May 05. Don't know if there's major difference between the two, but I want to make sure everyone knows it..

 

I believe the difference between the two was that they added PenTesting methods to 4.  As far as anything else besides that I don't think so.  People going for this now have many more resources than Oyle or myself did. 
Logged

A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
Negrita
Sr. Member
****
Offline Offline

Posts: 289



View Profile
« Reply #5 on: April 04, 2006, 04:30:59 PM »

I'm in for the study group, but I'm not sure when I'll take the exam. That would depend on approval from EC-Council.

BTW Oyle, you can check the Version 4 Course Outline, to see the differnces between what you have and what should be studied.
Logged

CEH, CCSA NG/AI, NNCSS, MCP, MCSA 2003

There are 10 kinds of people, those that understand binary, and those that don't.
don
Editor-In-Chief
Administrator
Hero Member
*****
Online Online

Posts: 2380


Editor-In-Chief


View Profile WWW
« Reply #6 on: April 04, 2006, 05:04:55 PM »

Dengar - You are now a moderator of the Charter Group Forum. As for your eligibility for prizes... I think it only bolsters your image in my eyes. You are not an employee of The Digital Construction Company and you are not being paid to do this. I think this is what I mean by being a valued contributor. Does anyone disagree?

Oyle - I think Dengar is correct. Version 4 only added domains to Version 3. Maybe if you could go through the Version 4 stuff also and add the discussion topics just to make sure we are studying the right stuff. If you don't know enough to make the full intro on the additional domains, I'm sure we can fill in the blanks.

Rules for this forum - I think general rules of netiquette apply. It is free speech, but let's not be ugly or lewd.

I still think we should strive to do both CEH and CPTS, but maybe we can take them one at a time. We keep the title of the study group as "Pen Test" as opposed to CEH or CPTS alone. We start with CEH as a foundation and proceed into CPTS.

With this in mind, what do you think of starting with my original first steps:


Don
Logged

CISSP, MCSE, CEH, Security+ SME
Oyle
Sr. Member
****
Offline Offline

Posts: 264


"Man. Nature. Technology".


View Profile WWW
« Reply #7 on: April 05, 2006, 01:08:17 PM »

OK, I checked the ver 4 details off the ECCouncil page; the "Module" headings ("Module" = "Chapter", as far as I'm concenred).

 Major differences are as follows:

*Module 17 in my books are "Novell Hacking"; in the current version, Module 17 is "Physical Security".
*Module 1 in my book is "Introduction to Ethical Hacking"; in the current version, Module 1 is "Ethics and Legality"
*In my books, Module 19 is "IDS, Firewalls and Honeypots"; in the current version, Module 19 is "Evading IDS, Firewalls and Honeypots"
* In my books, all there is is 21 Modules, the last being Cryptography. In the new version, there is a Module 22, "Penetration Testing". 

So I'd say have a handle on 90% of the current courseware.

It looks to me as if they have some more subject matter under each heading, but I think my courseware is still pretty compatible to what what is now "current".

I worry though, that including the CEH in with the CPTS might confuse some people. My courseware has 21 modules ("chapters"), the last one being on cryptography, which I happen to think is reeeeaaally cool stuff. It's my favorite Module.

« Last Edit: April 05, 2006, 01:26:49 PM by Oyle » Logged

MCP, MCP+I, MCSA, MCSE(NT4/W2K), CCNA, CCA, NWCCC, VH-PIRTS, CEH
--------------------
"hackers are like jedi, crackers are like the sith: do not fall prey to the dark side".

From 1337 h4x0r h4ndb00k: "the ten laws of geek", law x
                  -Tapeworm
don
Editor-In-Chief
Administrator
Hero Member
*****
Online Online

Posts: 2380


Editor-In-Chief


View Profile WWW
« Reply #8 on: April 05, 2006, 02:45:10 PM »

Although I think we should commit as a group to do both CEH and CPTS, I also agree with Oyle on focusing on CEH to prevent confusion. So how about we do CEH first, then move on as a group to CPTS? Then we can move on to their Module layout and just cover what was missed.

Thoughts?

Don
Logged

CISSP, MCSE, CEH, Security+ SME
Oyle
Sr. Member
****
Offline Offline

Posts: 264


"Man. Nature. Technology".


View Profile WWW
« Reply #9 on: April 05, 2006, 03:08:50 PM »

That sounds good, but what do you mean, "move on" to the CPTS? I suppose there are some people out there that would rather do CPTS instead  of / before / in place of the CEH. Why not just have the CEH and CPTS run concurrently alongside each other?? But is there anyone that wants to volunteer/moderate for the CPTS?? I don't know of anybody on the board here already a CPTS willing to volunteer/moderate. Not to say there isn't any, but the name of the domain is ethicalhacker.net not ethicalhackerandpentester.net Just trying to avoid some confusion here. Heck, I'm starting to get confused on this.  Grin

This sounds like a bad habit I have of making everything harder than it needs to be.
Logged

MCP, MCP+I, MCSA, MCSE(NT4/W2K), CCNA, CCA, NWCCC, VH-PIRTS, CEH
--------------------
"hackers are like jedi, crackers are like the sith: do not fall prey to the dark side".

From 1337 h4x0r h4ndb00k: "the ten laws of geek", law x
                  -Tapeworm
don
Editor-In-Chief
Administrator
Hero Member
*****
Online Online

Posts: 2380


Editor-In-Chief


View Profile WWW
« Reply #10 on: April 05, 2006, 03:31:48 PM »

OK. You started it...  Wink

The name of the site is www.ethicalhacker.net. It is not certifiedethicalhacker.net, so this site is not dedicated solely to the credential named CEH. It is a place for all things related to hacking in a legal manner. That's why we have 3 eth hacking / pen testing certs listed in our Certification Category as well as forensic and incident response certs. Also, certs are a small part of the entire site.

'Ethical Hacking' has become a common term in the industry to describe multiple security processes including pen testing.

Please keep in mind that this entire sector of the cert industry is in its infancy. CEH has grabbed the early spotlight, but who knows if CPTS will overtake it. As of now, all I know is that they are 2 different credentials in the same space. Will they both find their niche? Maybe.

So... let's take a poll. I'll add it as a new post.

Don
Logged

CISSP, MCSE, CEH, Security+ SME
don
Editor-In-Chief
Administrator
Hero Member
*****
Online Online

Posts: 2380


Editor-In-Chief


View Profile WWW
« Reply #11 on: April 05, 2006, 03:45:11 PM »

Something else to consider is that as the owner of the entire site, I am looking at a bigger picture. I hope that we will not be the only study group to form here at EH-Net. Therefore, each group must have their own name. Since we're the first, I named us the Charter Group. Looking even further into the future, each study group may want to concentrate on different topics at different times in their careers. So we could have:

Charter Study Group - Pen Testing
Charter Study Group - Forensics

I think most of us in the Charter Group want to study pen testing as a subject and possibly get more than one cert in that subject. If we only want to study for a single cert, we can rename the group:

Charter Study Group - CEH
Charter Study Group - CPTS
Charter Study Group - CCE

... and so on.

Hope this is clearer.

Don
Logged

CISSP, MCSE, CEH, Security+ SME
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.061 seconds with 25 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.