Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
Nov 2008 Free Giveaway Sponsor - CWNP
Daemon - A Contest Begins Now
It Happened One Friday - Answers and Winners
Daemon - A Contest
Scooby Doo and the Crypto Caper
MS Blue Hat Hackers Headline Chicago Security Con
The Pen Testing Perfect Storm Webcast Series with Skoudis, Wright, Johnson
The IDA Pro Book
Column 0: Human Exploitation 101
Intercepted! Windows Hacking via DLL Redirection
What the Splunk?
Spiceworks Redux: Review of v3
Aug 2008 Free Giveaway Sponsor - ChicagoCon
Maltego Part I - Intro and Personal Recon
June 2008 Free Giveaway - Winner
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 22 guests and 1 member online
EH-Net Donations
Enter Amount:
$
CAD
USD
GBP
AUD
JPY
EUR
Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations
You are here:
Home
Forum
EH-Net
News Items and General Discussion About EH-Net
Another new member intro
Ethical Hacker Community Forums
December 01, 2008, 05:17:33 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100!
www.chicagocon.com/content/view/103/51/
Home
Help
Calendar
Login
Register
Ethical Hacker Community Forums
>
EH-Net
>
News Items and General Discussion About EH-Net
(Moderator:
don
) >
Another new member intro
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: Another new member intro (Read 7506 times)
0 Members and 1 Guest are viewing this topic.
Cheap5.0
Newbie
Offline
Posts: 10
Another new member intro
«
on:
July 28, 2008, 08:29:39 PM »
Hello everyone!
I will start with a quick run down of how i got here. I am 2 classes away from finishing an associates in managment. About 18 months ago I was bitten by the tech bug (building little static sites for small businesses) and it has only gotten stronger. Now i am thinking about switching from my management degree to an IT degree once i get my A.S. this semester (my current school has a CNSS endorsed B.S. in info tech and security).
I started researching this IT field about a week ago after talking with a few people who are knowledgeable about this topic (for those who want to know, i found this site by googling "CNSS"...1st page results). So far i have had a hard time finding solid info from a "hands on" source.
I really just want to know what i should expect to get out of this type of work? What knowledge do you use the most (hardware, programming, neither)? Is a specific degree that focuses on info security the way to go or should i get a more general degree (computer sciences?)
And lastly, is there any way i could jump in before switching majors and try some of this kind of work at home? I have been playing with HTML, CSS, JS, and a little php for the past 18 months...will any of that carry over to this?
Thanks, and hello again
Logged
Manu Zacharia (-M-)
Full Member
Offline
Posts: 195
Re: Another new member intro
«
Reply #1 on:
July 28, 2008, 08:53:16 PM »
Hey Cheap5.0,
Welcome on board EH-Net.
Most of the questions projected by you are already discussed in detail under various forums here. Go through it and you will get what you looking for. However, let me try to answer few:
What i should expect to get out of this type of work? - 100% Job Satisfaction – that would be my first answer if you are really passionate about security.
What knowledge do you use the most (hardware, programming, neither)? - Common Sense and a combination of hardware, programming, networking and system concepts
Is a specific degree that focuses on info security the way to go or should i get a more general degree (computer sciences?) - Yes there are many Universities and educational institutions that provide various courses that specialize on information security and information assurance.
Is there any way i could jump in before switching majors and try some of this kind of work at home? - Yes, you can setup a hack lab at your home and do all your R&D. There are various threads on EH-Net that discusses on how to setup or the ideal configuration for a home lab. You can start off with Virtualization also.
Hope I covered most of your questions and expect more contributions from your side also. All the best and Happy Hacking (Ethical)
Logged
Manu Zacharia
Certified ISO 27001:2005 (Information Security Management System) Lead Auditor
Promote the Information Security Day
Visit -
http://www.informationsecurityday.com
Cheap5.0
Newbie
Offline
Posts: 10
Re: Another new member intro
«
Reply #2 on:
July 28, 2008, 10:11:31 PM »
Quote from: Manu Zacharia (-M-) on July 28, 2008, 08:53:16 PM
Hey Cheap5.0,
Welcome on board EH-Net.
Most of the questions projected by you are already discussed in detail under various forums here. Go through it and you will get what you looking for. However, let me try to answer few:
What i should expect to get out of this type of work? - 100% Job Satisfaction – that would be my first answer if you are really passionate about security.
What knowledge do you use the most (hardware, programming, neither)? - Common Sense and a combination of hardware, programming, networking and system concepts
Is a specific degree that focuses on info security the way to go or should i get a more general degree (computer sciences?) - Yes there are many Universities and educational institutions that provide various courses that specialize on information security and information assurance.
Is there any way i could jump in before switching majors and try some of this kind of work at home? - Yes, you can setup a hack lab at your home and do all your R&D. There are various threads on EH-Net that discusses on how to setup or the ideal configuration for a home lab. You can start off with Virtualization also.
Hope I covered most of your questions and expect more contributions from your side also. All the best and Happy Hacking (Ethical)
Thanks for the help! I noticed after posting that this is probably the most popular topic on the forums
Oooops....
I have been reading and searching and reading some more, and from what it looks like, security is:
-One of the more difficult IT professions to get into(?)
-a career requires more exp than education(?)
-a state of mind, not a job
The first two are general questions that i assume are true, correct?
You answered my education question, but i want to make sure i understand completely. You would recommend a specific degree specializing in security rather than a more general network degree if someone wanted to work in security?
Thanks!
Logged
BillV
Hero Member
Offline
Posts: 868
Re: Another new member intro
«
Reply #3 on:
July 31, 2008, 03:01:51 PM »
Hi Cheap5.0! Welcome to the community.
Is security harder to get into compared to other areas of IT? Perhaps. Mostly because to be good at security, you have to have a good understanding of a lot of other areas. For example, if you're going to be protecting web applications but don't know anything about the code that is running those applications, you'll soon find yourself in trouble
Does an InfoSec career require more experience than education? In my opinion, I would say yes. I myself don't have anything more than a high school diploma and a few college credits, but I'm also still early in my career. I know there are several others floating around here that are in the same boat. This doesn't mean that an HR person or a recruiter isn't going to think highly of someone with a lot of education, but when you really get down to it, hands-on experience with the technology or being able to manage those technical folks is really what's going to help out. If you're considering a degree, and you're 100% sure that you want to stick with security, then I would agree that you should find one that specializes in security. There are multiple schools out there that are recognized by the NSA for their information assurance programs. Check into one of those. Steer clear from 'computer science,' though.. that's typically "programming" in disguise. You would want a computer information systems program or something that puts more emphasis on networking (unless of course you want to program).
HTH (and again, welcome
BillV
Logged
Cheap5.0
Newbie
Offline
Posts: 10
Re: Another new member intro
«
Reply #4 on:
August 01, 2008, 09:30:11 AM »
Thanks BillV, I just got done with my college adviser yesterday. I am finishing my current degree in November, and will start on the info sec degree in January of '09. I am going to go for the A+ cert before the new year just to get a little bit of a start and try to get in somewhere (anywhere!) to start working in the IT field asap.
When you say i should know how ________ programming language works, do you mean i should be able to code using it or just be able to look at it and understand why it does what it does?
I am comfortable with PHP right now, but if i had to sit down and make a program that would interact with a dbase forget it...lol. However, i can look at php files and see what they do and why without viewing them in a browser.
Logged
BillV
Hero Member
Offline
Posts: 868
Re: Another new member intro
«
Reply #5 on:
August 01, 2008, 02:57:46 PM »
Nope, you certainly don't need to be an "enterprise developer" in any language. More so like you have stated... that you can look at the code and understand it well enough to determine what's going on and where the security holes are.
So, for the PHP example, when you see something like...
Code:
<form action="" method="post">
<input type="text" name="username"><br />
<input type="password" name="pass"><br />
<input type="submit" value="Login">
</form>
<?php
if (
$_POST
[
submit
]) {
$sql
=
"SELECT * FROM users WHERE username='$_POST[username]' AND password='$_POST[password]'"
;
}
?>
You would know that we quite obviously have a problem. I also don't mean that you need to know 'every' language either.
Also, going along with your 'studying for A+' idea and wanting to get into something... you may also want to have a look at the Microsoft MCDST (Desktop Support Technician). You can study for the exam for FREE directly though Microsoft with their E-Learning site...
https://www.microsoftelearning.com/eLearning/offerDetail.aspx?offerPriceId=54989
Good luck
BillV
Logged
Cheap5.0
Newbie
Offline
Posts: 10
Re: Another new member intro
«
Reply #6 on:
August 06, 2008, 09:31:24 AM »
Thanks for the suggestion Bill! Did M$ just start doing the trainging courses online? I thought i saw that pop up recently on del.ico.us....?
That makes me feel better about the language's. If i was going to take a wild guess as to whats wrong with the php you posted, i would guess its something to do with how the sql is delivered to the db or modified by the inputs? I really dont know, i need to get more comfortable with it i guess.
Logged
RobMongoose
Newbie
Offline
Posts: 28
Re: Another new member intro
«
Reply #7 on:
August 06, 2008, 07:30:54 PM »
Quote from: Cheap5.0 on August 01, 2008, 09:30:11 AM
I am going to go for the A+ cert before the new year just to get a little bit of a start and try to get in somewhere (anywhere!) to start working in the IT field asap
If you're looking at getting some industry certs to start of with I would suggest going for one of the MS ones first rather than a CompTIA cert. In my experience they're cheaper, more interesting (less basic) and are worth more as far as employers are concerned. By all means go for one later on, maybe the Security+, Network+ or Linux+. A+ is very basic hardware/software maintenance, the sort of skills you tend to pick up after a couple of PC builds, whereas the MS certs demonstrate a high level of proficiency with (unfortunate but true) the dominant industry OSs.
As someone else suggested, I would definitely look at setting up some sort of lab to play around in also. VMWare is very useful for this if you don't want a load of old PCs lying around.
Logged
Mutterings of an evil genius in training -
http://robmongoose.blogspot.com/
Cheap5.0
Newbie
Offline
Posts: 10
Re: Another new member intro
«
Reply #8 on:
August 06, 2008, 08:02:20 PM »
Quote from: BillV on August 01, 2008, 02:57:46 PM
Nope, you certainly don't need to be an "enterprise developer" in any language. More so like you have stated... that you can look at the code and understand it well enough to determine what's going on and where the security holes are.
So, for the PHP example, when you see something like...
Code:
<form action="" method="post">
<input type="text" name="username"><br />
<input type="password" name="pass"><br />
<input type="submit" value="Login">
</form>
<?php
if (
$_POST
[
submit
]) {
$sql
=
"SELECT * FROM users WHERE username='$_POST[username]' AND password='$_POST[password]'"
;
}
?>
You would know that we quite obviously have a problem. I also don't mean that you need to know 'every' language either.
Also, going along with your 'studying for A+' idea and wanting to get into something... you may also want to have a look at the Microsoft MCDST (Desktop Support Technician). You can study for the exam for FREE directly though Microsoft with their E-Learning site...
https://www.microsoftelearning.com/eLearning/offerDetail.aspx?offerPriceId=54989
Good luck
BillV
I just signed up and I am starting this course, thanks for pointing this out!
Logged
BillV
Hero Member
Offline
Posts: 868
Re: Another new member intro
«
Reply #9 on:
August 07, 2008, 07:57:53 AM »
Quote from: Cheap5.0
Thanks for the suggestion Bill! Did M$ just start doing the trainging courses online? I thought i saw that pop up recently on del.ico.us....?
No problem. I'm not sure how long they have been offering training courses online. I would guess a while judging by the availability of different courses. I know I came across them sometime last year.
Quote from: Cheap5.0
That makes me feel better about the language's. If i was going to take a wild guess as to whats wrong with the php you posted, i would guess its something to do with how the sql is delivered to the db or modified by the inputs? I really dont know, i need to get more comfortable with it i guess.
Yup, you'd be correct. Taking a variable (username) that's input from a form and placing it directly into a SQL query with no proper validation is not a good idea
Quote from: Cheap5.0
I just signed up and I am starting this course, thanks for pointing this out!
Good luck!! Let us know how it goes
BillV
«
Last Edit: August 07, 2008, 08:12:40 AM by BillV
»
Logged
BillV
Hero Member
Offline
Posts: 868
Re: Another new member intro
«
Reply #10 on:
August 07, 2008, 08:11:07 AM »
Quote from: RobMongoose
If you're looking at getting some industry certs to start of with I would suggest going for one of the MS ones first rather than a CompTIA cert. ... A+ is very basic hardware/software maintenance, the sort of skills you tend to pick up after a couple of PC builds, whereas the MS certs demonstrate a high level of proficiency with (unfortunate but true) the dominant industry OSs.
I agree and disagree.
I used to have the same thinking back when I knew what the objectives were for the old A+ version when it was Cord Hardware and Core Operating Systems.
Recently, now that I've taken a closer look at the new A+ objectives (Essentials + IT Tech/Remote Tech/Depot Tech), I've been suggesting that to people looking at getting into IT. And, as I replied above, I also send them in the direction of that MCDST since that's a good place to start and the training is free from MS.
I really think that the A+ has changed a lot compared to what it used to be.
Logged
Cheap5.0
Newbie
Offline
Posts: 10
Re: Another new member intro
«
Reply #11 on:
August 07, 2008, 09:15:28 AM »
Quote from: BillV on August 07, 2008, 07:57:53 AM
Yup, you'd be correct. Taking a variable (username) that's input from a form and placing it directly into a SQL query with no proper validation is not a good idea
Good luck!! Let us know how it goes
BillV
That would be a SQL injection right?
I am about 14% into that course (when you are logged in and "learning", there is a small meter that tells you how far along you are in the current course). Its very useful, and explains everything quite well in basic computer terms that anyone with some experience would understand. My only complaint is they introduce concepts abruptly. Its hard to explain, but they use terms that they have not defined or explained. If you go back through the lesson though, it all becomes quite clear. But if you were just to watch/listen only once you would have a hard time getting through it. Also the scenarios in which they teach you change from demo to demo. In one you will be "working" on the host computer, then in the very next demostration you are working remotely on a computer in "London" while you are in "Vancouver". If you miss that little fact the lesson gets very confusing quickly! lol
Logged
sgt_mjc
Full Member
Offline
Posts: 158
Re: Another new member intro
«
Reply #12 on:
August 07, 2008, 04:11:51 PM »
One last piece of advice Cheap, and this is the easy part, ask questions. If you don't know something, ask around here. Some one will know the answer. I got in to he security field more by accident than design. I had a friend that knew me back when we served together and served as a mentor. He steered me towards this line of work and I love it. Good luck on your own journey.
Logged
Mike Conway
CompTia Security +
C|EH
RobMongoose
Newbie
Offline
Posts: 28
Re: Another new member intro
«
Reply #13 on:
August 07, 2008, 08:56:23 PM »
Quote from: BillV on August 07, 2008, 08:11:07 AM
I really think that the A+ has changed a lot compared to what it used to be.
Fair enough
. It's been a few years since I saw the material and it was very basic at that point. Thinking about it that was nearly 10 years ago so no surprise that it's been updated really
Logged
Mutterings of an evil genius in training -
http://robmongoose.blogspot.com/
BillV
Hero Member
Offline
Posts: 868
Re: Another new member intro
«
Reply #14 on:
August 07, 2008, 09:00:53 PM »
Yeah, I'd imagine we're probably on the same page. Take a look over at the CompTIA website at the A+ objectives when you get a chance. You'll probably be pretty surprised at the changes. I know I was! Especially when I saw that 'security' is one of the domains. It's a much more well-rounded certification than it used to be
Logged
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Special Events
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009
=> News Items and General Discussion About EH-Net
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> Certification
===> The Charter Study Group - Pen Test
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
=====> CEH - Official Course Modules v4
=====> CEH - Official Course Modules v5
=====> CEH - Official Course Modules v6
===> CPTS - Certified Pen Testing Specialist
=====> CPTS - Official Course Modules v5
===> CPTE - Certified Pen Testing Expert
=====> CPTE - Official Course Modules v1
===> ECSA - EC-Council Certified Security Analyst
=====> ECSA - Official Course Modules v1.2
=====> ECSA / LPT - Official Course Modules v3
===> OSCP - Offensive Security Certified Professional
===> GPEN - GIAC Certified Penetration Tester
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
=====> CHFI - Official Course Modules v2
===> EnCE - EnCase® Certified Examiner
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Hardware
=> Malware
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Gates
=> Heffner
=> Hoffman
=> RichM
=> Murray
=> J. Peltier
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
Loading...
Sponsors
Polls
During the most recent election, I:
Chose a paper ballot.
Trusted the machines.
Didn't care, just voted.
Didn't have a choice. It was paper.
Didn't have a choice. It was electronic.
Didn't vote.
Support EH-Net
Support EH-Net by
Buying all of your
Amazon items using
the search bar above.
Try CBT Nuggets Free!
Recent Forum Topics
Programming
: not static?
(7) by
RoNNie_13
Calendar Of Events
: BOSS Conference 2009
(0) by
don
Calendar Of Events
: CSI SX 2009
(0) by
don
Calendar Of Events
: Security OPUS Spring 2009
(0) by
don
Calendar Of Events
: CanSecWest 2009
(0) by
don
Calendar Of Events
: Carolinacon 2009
(0) by
don
Calendar Of Events
: Black Hat USA 2009
(0) by
don
Calendar Of Events
: Black Hat Europe 2009
(0) by
don
Calendar Of Events
: Black Hat DC 2009
(0) by
don
Calendar Of Events
: Cyber Warfare 2009
(0) by
don
Calendar Of Events
: White Hat Ball 2009
(0) by
don
Calendar Of Events
: RSA Conference 2009
(0) by
don
Calendar Of Events
: SOURCE Boston 2009
(0) by
don
Calendar Of Events
: Notacon 6
(0) by
don
Calendar Of Events
: ShmooCon 2009
(0) by
don
Calendar Of Events
: SANS Pen Testing Summit 2009
(0) by
don
Calendar Of Events
: SANS 2009
(0) by
don
Calendar Of Events
: SANS Security West 2009
(0) by
don
Calendar Of Events
: SANS CDI 2008
(0) by
don
Forensics
: The Julie Amero Case: A Dangerous Farce
(0) by
don
Other
: Early Details of Vista, Server 2008 SP2 Due in April
(0) by
don
Career Central
: 7 Tips for Career Growth in Tight Times
(0) by
don
Other
: Do we or Dont we...
(7) by
pseud0
Special Events
: Pen Testing Perfect Storm Webcast Series: Part 2 - Teaser
(6) by
don
News from the Outside World
: Would you trade your privacy for a smartphone?
(5) by
jason
Hardware
: Key Duplication from Photos
(5) by
jason
Career Central
: Confused about future
(8) by
Artful Dodger
Tools
: Cain & Abel v4.9.24 Released
(1) by
RoleReversal
CEH - Certified Ethical Hacker
: MSS from EC-Council?
(13) by
shednik
Book Reviews
: Network Intrusion Alert
(1) by
don
Hardware
: Lenovo Introduces Remote Disable Feature for Laptops
(16) by
jason
Wireless
: Jamming by babycam
(6) by
jason
Other
: What kind of lab, machines you have for your security testing?
(6) by
MadmanTM
Wireless
: help wid wifi !!!!
(1) by
jason
Malware
: Military Bans Removable Media
(10) by
ChrisG
Network Pen Testing
: Metasploit Question
(4) by
ethicalhack3r
Other
: SANS CDI
(1) by
jason
Hardware
: Recommendations for IDS Hardware
(1) by
jason