Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 45 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
5 Questions you would ask to a future web pen tester!
EH-Net
May 22, 2013, 08:24:19 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
5 Questions you would ask to a future web pen tester!
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: 5 Questions you would ask to a future web pen tester! (Read 8488 times)
0 Members and 1 Guest are viewing this topic.
maumercado
Newbie
Offline
Posts: 11
5 Questions you would ask to a future web pen tester!
«
on:
May 19, 2008, 08:43:09 AM »
Hello all,
Im doing a 5 or more questions exam to evaluate incoming personal to the security staff in the company I work for, now I was thinking more like general questions, like what is xss, what can i gain from doing it?, but I think this kind of questions do not ensure that the guy does know how it is done...
Could you help me out, what would you ask?
Logged
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4167
Editor-In-Chief
Re: 5 Questions you would ask to a future web pen tester!
«
Reply #1 on:
May 19, 2008, 01:24:31 PM »
It depends on what you want. You mentioned below the fact that a certain question may not let you know if the person knows what they're doing. That makes me think that you want experienced candidates. If so, how about:
"What is your favorite tool (one open source and one commercial)?"
Say... Wikto and WebInspect (now by HP) respectively. If they can't name at least one of each, you have your answer. This question alone can spark a lengthy conversation between you and the candidate to talk about more than just 2 tools, benefits and shortcomings of each, whether they like open source solutions, etc. If no conversation occurs, then that's just more of an answer.
If you want someone with the right 'tude and are willing to teach them what they need to know, then it should cover more things like their desired workplace environment, preferred culture, projects they've started just for fun, ways that they've taken an initiative to better themselves (not just advance their tech skills), etc.
I'll let others respond with some ideas in your quest for 5.
Hope this helps,
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
vijay2
Full Member
Offline
Posts: 220
Re: 5 Questions you would ask to a future web pen tester!
«
Reply #2 on:
May 19, 2008, 01:41:15 PM »
I would say one of the first few would be
what is the difference between a Pen Tester and a Hacker ?
or
What is one of the first things required before you begin Pen test ?
Hope this helps
VJ
Logged
GPEN GCFA GCIH CISSP CISA GSEC OSCP C|EH Security+
maumercado
Newbie
Offline
Posts: 11
Re: 5 Questions you would ask to a future web pen tester!
«
Reply #3 on:
May 19, 2008, 02:57:52 PM »
Thank you both...
heck im actually running the interview...
Logged
LSOChris
Guest
Re: 5 Questions you would ask to a future web pen tester!
«
Reply #4 on:
May 19, 2008, 08:36:49 PM »
looks too late but i like to ask about:
1. what's their home network, lab, and SSID for their wifi and if they are running security on it
2. how do they keep up to date with whats going on in the security community and if they are regular posters on any forums/newsgroups.
among other things.
Logged
Andrew Waite
Hero Member
Offline
Posts: 928
Re: 5 Questions you would ask to a future web pen tester!
«
Reply #5 on:
May 20, 2008, 02:52:58 AM »
Quote from: ChrisG on May 19, 2008, 08:36:49 PM
1. what's their home network, lab, and SSID for their wifi and if they are running security on it
Hadn't ever thought of that, better get my home network upto scratch before the next interview just in case
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
geekyone
Full Member
Offline
Posts: 180
Re: 5 Questions you would ask to a future web pen tester!
«
Reply #6 on:
May 20, 2008, 04:12:11 PM »
Just lie about your home network and hope they don't wardrive you.
Logged
CISSP, CEH, GPEN, GCIH, GCFA
LSOChris
Guest
Re: 5 Questions you would ask to a future web pen tester!
«
Reply #7 on:
May 21, 2008, 11:36:02 AM »
yup, its just a way to get into their head and ask follow on qeustions.
if they arent practing security at home how confident can i be they really care about it
if they arent keeping up with security or from only one source that is say outdated before it reaches them, i probably dont want them on my team.
Logged
Dengar13
Sr. Member
Offline
Posts: 380
Re: 5 Questions you would ask to a future web pen tester!
«
Reply #8 on:
May 21, 2008, 12:42:03 PM »
Quote from: ChrisG on May 21, 2008, 11:36:02 AM
yup, its just a way to get into their head and ask follow on qeustions.
if they arent practing security at home how confident can i be they really care about it
if they arent keeping up with security or from only one source that is say outdated before it reaches them, i probably dont want them on my team.
That's a damn good point. I would probably be caught off guard if I were asked that on an interview, but it makes complete sense on why it would be asked.
Logged
A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
BillV
Hero Member
Offline
Posts: 1892
Re: 5 Questions you would ask to a future web pen tester!
«
Reply #9 on:
May 21, 2008, 01:23:11 PM »
Quote from: ChrisG on May 19, 2008, 08:36:49 PM
1. what's their home network, lab, and SSID for their wifi and if they are running security on it
Network? I have a Win95 box hooked up to the wireless cable modem from my ISP. Lab? Well, I have IE5 and a command prompt. SSID? 800CALLBILL, open for everyone
On a more serious note....
Quote from: maumercado
I was thinking more like general questions, like what is xss, what can i gain from doing it?, but I think this kind of questions do not ensure that the guy does know how it is done...
If you want to find out whether they know
how
to do things, you'll probably want some deeper than 'general' questions. Perhaps you can ask for an example of how to perform XSS, or ask them to write down a simple 'alert' script. Same goes for SQL injection, ask them what they can put into the input field to test. Maybe ask what a web proxy can be used for.
Or to really test, you could setup a test web application (you could use one of the many available, but they may have already seen it) and let them have at it.
Bill
Logged
LSOChris
Guest
Re: 5 Questions you would ask to a future web pen tester!
«
Reply #10 on:
May 21, 2008, 05:27:06 PM »
you could also ask them to explain what happens when you do a:
ping
www.cnn.com
there is ALOT of room for depth of answers on that one.
Logged
geekyone
Full Member
Offline
Posts: 180
Re: 5 Questions you would ask to a future web pen tester!
«
Reply #11 on:
May 21, 2008, 06:48:20 PM »
I really like that question Chris! You can tell how much they know simply by how deeply they could explain that simple command. I am going to have to remember that one.
Logged
CISSP, CEH, GPEN, GCIH, GCFA
eth3real
Sr. Member
Offline
Posts: 309
Re: 5 Questions you would ask to a future web pen tester!
«
Reply #12 on:
May 22, 2008, 02:45:09 AM »
I might also ask what percentage of the pentest is based on a Nessus scan.
I know a small company in town that offers a "security analysis", and all they do is a Nessus scan. Nothing else.
They really are not pentesters or security analysts, though. They mostly work with setting up Microsoft domains, Exchange servers, terminal services, etc., so they don't do it very often.
Still something worth considering; how much time is spent using automated tools compared to how much research and information gathering is done by a real person?
Logged
Put that in your pipe and grep it!
dean
Guest
Re: 5 Questions you would ask to a future web pen tester!
«
Reply #13 on:
May 22, 2008, 07:57:21 AM »
I would assume that if the individual is actually applying for a position as a pentester he would know the difference between a 'hacker' and pentester.
The idea is to test knowledge, both technical and presentation/speaking skills.
A couple of initial questions I always ask when interviewing a candidate are:
1. Present/explain vulnerability X in system Y to management level individuals.
I generally look for presentation skills, technical knowledge, the ability to explain the impact (qualitative & quantitative) to a person and the ability to explain that threat in terms managers can relate to. Their ability to move beyond the single vuln and to look at the environment as a whole and how that vuln impacts it.
2. What research/personal projects are you working on?
Here I look for their dedication and interest in the field. I expect, at the very least that they should be reading/testing/learning about something new. "I turn off my computer at home" is not the answer I would expect.
3. My personal favorite:
Host-A <---> Router-A <---> Router-B <---> Host-B
Explain how A communicates with B using FTP, TELNET, HTTP, ETC (pick one) and use the OSI model as a reference.
Here I look for their knowledge of protocols, tcp/ip, etc... If they cannot explain how ARP works I don't need them.
There have been some good discussions on the securityfocus mailing lists about this topic in the past.
dean
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Gates
: Isabelle Marant if you're|a really wonderful|pc|whether you are having a lesson
(0) by
ddogs42zm
News Items and General Discussion About EH-Net
: 1000 страшно пол
(0) by
quohaphoday
GPEN - GIAC Certified Penetration Tester
: Karen Millen Outlet as an example SFTP
(0) by
dtree28yt
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(27) by
don
Greetings
: Hi from the UK
(2) by
n37sh@rk
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.