Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 58 guests online
You are here:
Home
EH-Net
News Items and General Discussion About EH-Net
Another new member intro
EH-Net
May 23, 2013, 12:24:22 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
EH-Net
>
News Items and General Discussion About EH-Net
(Moderator:
don
) >
Another new member intro
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: Another new member intro (Read 20773 times)
0 Members and 1 Guest are viewing this topic.
Cheap5.0
Newbie
Offline
Posts: 10
Another new member intro
«
on:
July 28, 2008, 08:29:39 PM »
Hello everyone!
I will start with a quick run down of how i got here. I am 2 classes away from finishing an associates in managment. About 18 months ago I was bitten by the tech bug (building little static sites for small businesses) and it has only gotten stronger. Now i am thinking about switching from my management degree to an IT degree once i get my A.S. this semester (my current school has a CNSS endorsed B.S. in info tech and security).
I started researching this IT field about a week ago after talking with a few people who are knowledgeable about this topic (for those who want to know, i found this site by googling "CNSS"...1st page results). So far i have had a hard time finding solid info from a "hands on" source.
I really just want to know what i should expect to get out of this type of work? What knowledge do you use the most (hardware, programming, neither)? Is a specific degree that focuses on info security the way to go or should i get a more general degree (computer sciences?)
And lastly, is there any way i could jump in before switching majors and try some of this kind of work at home? I have been playing with HTML, CSS, JS, and a little php for the past 18 months...will any of that carry over to this?
Thanks, and hello again
Logged
Manu Zacharia (-M-)
Sr. Member
Offline
Posts: 393
c0c0n Hacking Conference - where hackers unite
Re: Another new member intro
«
Reply #1 on:
July 28, 2008, 08:53:16 PM »
Hey Cheap5.0,
Welcome on board EH-Net.
Most of the questions projected by you are already discussed in detail under various forums here. Go through it and you will get what you looking for. However, let me try to answer few:
What i should expect to get out of this type of work? - 100% Job Satisfaction – that would be my first answer if you are really passionate about security.
What knowledge do you use the most (hardware, programming, neither)? - Common Sense and a combination of hardware, programming, networking and system concepts
Is a specific degree that focuses on info security the way to go or should i get a more general degree (computer sciences?) - Yes there are many Universities and educational institutions that provide various courses that specialize on information security and information assurance.
Is there any way i could jump in before switching majors and try some of this kind of work at home? - Yes, you can setup a hack lab at your home and do all your R&D. There are various threads on EH-Net that discusses on how to setup or the ideal configuration for a home lab. You can start off with Virtualization also.
Hope I covered most of your questions and expect more contributions from your side also. All the best and Happy Hacking (Ethical)
Logged
Manu Zacharia
MVP (Enterprise Security), ISLA-2010 (ISC)˛, C|EH, C|HFI, CCNA, MCP,
Certified ISO 27001:2005 Lead Auditor
There are 3 roads to spoil; women, gambling & hacking. The most pleasant with women, the quickest with gambling, but the surest is hacking - c0c0n
Cheap5.0
Newbie
Offline
Posts: 10
Re: Another new member intro
«
Reply #2 on:
July 28, 2008, 10:11:31 PM »
Quote from: Manu Zacharia (-M-) on July 28, 2008, 08:53:16 PM
Hey Cheap5.0,
Welcome on board EH-Net.
Most of the questions projected by you are already discussed in detail under various forums here. Go through it and you will get what you looking for. However, let me try to answer few:
What i should expect to get out of this type of work? - 100% Job Satisfaction – that would be my first answer if you are really passionate about security.
What knowledge do you use the most (hardware, programming, neither)? - Common Sense and a combination of hardware, programming, networking and system concepts
Is a specific degree that focuses on info security the way to go or should i get a more general degree (computer sciences?) - Yes there are many Universities and educational institutions that provide various courses that specialize on information security and information assurance.
Is there any way i could jump in before switching majors and try some of this kind of work at home? - Yes, you can setup a hack lab at your home and do all your R&D. There are various threads on EH-Net that discusses on how to setup or the ideal configuration for a home lab. You can start off with Virtualization also.
Hope I covered most of your questions and expect more contributions from your side also. All the best and Happy Hacking (Ethical)
Thanks for the help! I noticed after posting that this is probably the most popular topic on the forums
Oooops....
I have been reading and searching and reading some more, and from what it looks like, security is:
-One of the more difficult IT professions to get into(?)
-a career requires more exp than education(?)
-a state of mind, not a job
The first two are general questions that i assume are true, correct?
You answered my education question, but i want to make sure i understand completely. You would recommend a specific degree specializing in security rather than a more general network degree if someone wanted to work in security?
Thanks!
Logged
BillV
Hero Member
Offline
Posts: 1892
Re: Another new member intro
«
Reply #3 on:
July 31, 2008, 03:01:51 PM »
Hi Cheap5.0! Welcome to the community.
Is security harder to get into compared to other areas of IT? Perhaps. Mostly because to be good at security, you have to have a good understanding of a lot of other areas. For example, if you're going to be protecting web applications but don't know anything about the code that is running those applications, you'll soon find yourself in trouble
Does an InfoSec career require more experience than education? In my opinion, I would say yes. I myself don't have anything more than a high school diploma and a few college credits, but I'm also still early in my career. I know there are several others floating around here that are in the same boat. This doesn't mean that an HR person or a recruiter isn't going to think highly of someone with a lot of education, but when you really get down to it, hands-on experience with the technology or being able to manage those technical folks is really what's going to help out. If you're considering a degree, and you're 100% sure that you want to stick with security, then I would agree that you should find one that specializes in security. There are multiple schools out there that are recognized by the NSA for their information assurance programs. Check into one of those. Steer clear from 'computer science,' though.. that's typically "programming" in disguise. You would want a computer information systems program or something that puts more emphasis on networking (unless of course you want to program).
HTH (and again, welcome
BillV
Logged
Cheap5.0
Newbie
Offline
Posts: 10
Re: Another new member intro
«
Reply #4 on:
August 01, 2008, 09:30:11 AM »
Thanks BillV, I just got done with my college adviser yesterday. I am finishing my current degree in November, and will start on the info sec degree in January of '09. I am going to go for the A+ cert before the new year just to get a little bit of a start and try to get in somewhere (anywhere!) to start working in the IT field asap.
When you say i should know how ________ programming language works, do you mean i should be able to code using it or just be able to look at it and understand why it does what it does?
I am comfortable with PHP right now, but if i had to sit down and make a program that would interact with a dbase forget it...lol. However, i can look at php files and see what they do and why without viewing them in a browser.
Logged
BillV
Hero Member
Offline
Posts: 1892
Re: Another new member intro
«
Reply #5 on:
August 01, 2008, 02:57:46 PM »
Nope, you certainly don't need to be an "enterprise developer" in any language. More so like you have stated... that you can look at the code and understand it well enough to determine what's going on and where the security holes are.
So, for the PHP example, when you see something like...
Code:
<form action="" method="post">
<input type="text" name="username"><br />
<input type="password" name="pass"><br />
<input type="submit" value="Login">
</form>
<?php
if (
$_POST
[
submit
]) {
$sql
=
"SELECT * FROM users WHERE username='$_POST[username]' AND password='$_POST[password]'"
;
}
?>
You would know that we quite obviously have a problem. I also don't mean that you need to know 'every' language either.
Also, going along with your 'studying for A+' idea and wanting to get into something... you may also want to have a look at the Microsoft MCDST (Desktop Support Technician). You can study for the exam for FREE directly though Microsoft with their E-Learning site...
https://www.microsoftelearning.com/eLearning/offerDetail.aspx?offerPriceId=54989
Good luck
BillV
Logged
Cheap5.0
Newbie
Offline
Posts: 10
Re: Another new member intro
«
Reply #6 on:
August 06, 2008, 09:31:24 AM »
Thanks for the suggestion Bill! Did M$ just start doing the trainging courses online? I thought i saw that pop up recently on del.ico.us....?
That makes me feel better about the language's. If i was going to take a wild guess as to whats wrong with the php you posted, i would guess its something to do with how the sql is delivered to the db or modified by the inputs? I really dont know, i need to get more comfortable with it i guess.
Logged
RobMongoose
Newbie
Offline
Posts: 28
Re: Another new member intro
«
Reply #7 on:
August 06, 2008, 07:30:54 PM »
Quote from: Cheap5.0 on August 01, 2008, 09:30:11 AM
I am going to go for the A+ cert before the new year just to get a little bit of a start and try to get in somewhere (anywhere!) to start working in the IT field asap
If you're looking at getting some industry certs to start of with I would suggest going for one of the MS ones first rather than a CompTIA cert. In my experience they're cheaper, more interesting (less basic) and are worth more as far as employers are concerned. By all means go for one later on, maybe the Security+, Network+ or Linux+. A+ is very basic hardware/software maintenance, the sort of skills you tend to pick up after a couple of PC builds, whereas the MS certs demonstrate a high level of proficiency with (unfortunate but true) the dominant industry OSs.
As someone else suggested, I would definitely look at setting up some sort of lab to play around in also. VMWare is very useful for this if you don't want a load of old PCs lying around.
Logged
Mutterings of an evil genius in training -
http://robmongoose.blogspot.com/
Cheap5.0
Newbie
Offline
Posts: 10
Re: Another new member intro
«
Reply #8 on:
August 06, 2008, 08:02:20 PM »
Quote from: BillV on August 01, 2008, 02:57:46 PM
Nope, you certainly don't need to be an "enterprise developer" in any language. More so like you have stated... that you can look at the code and understand it well enough to determine what's going on and where the security holes are.
So, for the PHP example, when you see something like...
Code:
<form action="" method="post">
<input type="text" name="username"><br />
<input type="password" name="pass"><br />
<input type="submit" value="Login">
</form>
<?php
if (
$_POST
[
submit
]) {
$sql
=
"SELECT * FROM users WHERE username='$_POST[username]' AND password='$_POST[password]'"
;
}
?>
You would know that we quite obviously have a problem. I also don't mean that you need to know 'every' language either.
Also, going along with your 'studying for A+' idea and wanting to get into something... you may also want to have a look at the Microsoft MCDST (Desktop Support Technician). You can study for the exam for FREE directly though Microsoft with their E-Learning site...
https://www.microsoftelearning.com/eLearning/offerDetail.aspx?offerPriceId=54989
Good luck
BillV
I just signed up and I am starting this course, thanks for pointing this out!
Logged
BillV
Hero Member
Offline
Posts: 1892
Re: Another new member intro
«
Reply #9 on:
August 07, 2008, 07:57:53 AM »
Quote from: Cheap5.0
Thanks for the suggestion Bill! Did M$ just start doing the trainging courses online? I thought i saw that pop up recently on del.ico.us....?
No problem. I'm not sure how long they have been offering training courses online. I would guess a while judging by the availability of different courses. I know I came across them sometime last year.
Quote from: Cheap5.0
That makes me feel better about the language's. If i was going to take a wild guess as to whats wrong with the php you posted, i would guess its something to do with how the sql is delivered to the db or modified by the inputs? I really dont know, i need to get more comfortable with it i guess.
Yup, you'd be correct. Taking a variable (username) that's input from a form and placing it directly into a SQL query with no proper validation is not a good idea
Quote from: Cheap5.0
I just signed up and I am starting this course, thanks for pointing this out!
Good luck!! Let us know how it goes
BillV
«
Last Edit: August 07, 2008, 08:12:40 AM by BillV
»
Logged
BillV
Hero Member
Offline
Posts: 1892
Re: Another new member intro
«
Reply #10 on:
August 07, 2008, 08:11:07 AM »
Quote from: RobMongoose
If you're looking at getting some industry certs to start of with I would suggest going for one of the MS ones first rather than a CompTIA cert. ... A+ is very basic hardware/software maintenance, the sort of skills you tend to pick up after a couple of PC builds, whereas the MS certs demonstrate a high level of proficiency with (unfortunate but true) the dominant industry OSs.
I agree and disagree.
I used to have the same thinking back when I knew what the objectives were for the old A+ version when it was Cord Hardware and Core Operating Systems.
Recently, now that I've taken a closer look at the new A+ objectives (Essentials + IT Tech/Remote Tech/Depot Tech), I've been suggesting that to people looking at getting into IT. And, as I replied above, I also send them in the direction of that MCDST since that's a good place to start and the training is free from MS.
I really think that the A+ has changed a lot compared to what it used to be.
Logged
Cheap5.0
Newbie
Offline
Posts: 10
Re: Another new member intro
«
Reply #11 on:
August 07, 2008, 09:15:28 AM »
Quote from: BillV on August 07, 2008, 07:57:53 AM
Yup, you'd be correct. Taking a variable (username) that's input from a form and placing it directly into a SQL query with no proper validation is not a good idea
Good luck!! Let us know how it goes
BillV
That would be a SQL injection right?
I am about 14% into that course (when you are logged in and "learning", there is a small meter that tells you how far along you are in the current course). Its very useful, and explains everything quite well in basic computer terms that anyone with some experience would understand. My only complaint is they introduce concepts abruptly. Its hard to explain, but they use terms that they have not defined or explained. If you go back through the lesson though, it all becomes quite clear. But if you were just to watch/listen only once you would have a hard time getting through it. Also the scenarios in which they teach you change from demo to demo. In one you will be "working" on the host computer, then in the very next demostration you are working remotely on a computer in "London" while you are in "Vancouver". If you miss that little fact the lesson gets very confusing quickly! lol
Logged
sgt_mjc
Sr. Member
Offline
Posts: 294
Re: Another new member intro
«
Reply #12 on:
August 07, 2008, 04:11:51 PM »
One last piece of advice Cheap, and this is the easy part, ask questions. If you don't know something, ask around here. Some one will know the answer. I got in to he security field more by accident than design. I had a friend that knew me back when we served together and served as a mentor. He steered me towards this line of work and I love it. Good luck on your own journey.
Logged
Mike Conway
CISSP
CompTia Security +
C|EH
RobMongoose
Newbie
Offline
Posts: 28
Re: Another new member intro
«
Reply #13 on:
August 07, 2008, 08:56:23 PM »
Quote from: BillV on August 07, 2008, 08:11:07 AM
I really think that the A+ has changed a lot compared to what it used to be.
Fair enough
. It's been a few years since I saw the material and it was very basic at that point. Thinking about it that was nearly 10 years ago so no surprise that it's been updated really
Logged
Mutterings of an evil genius in training -
http://robmongoose.blogspot.com/
BillV
Hero Member
Offline
Posts: 1892
Re: Another new member intro
«
Reply #14 on:
August 07, 2008, 09:00:53 PM »
Yeah, I'd imagine we're probably on the same page. Take a look over at the CompTIA website at the A+ objectives when you get a chance. You'll probably be pretty surprised at the changes. I know I was! Especially when I saw that 'security' is one of the domains. It's a much more well-rounded certification than it used to be
Logged
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Editor-In-Chief
: Special Xmas Deal: 10% Off eLearnSecurity Courses
(3) by
hekvvddtest
Greetings
: Hello
(6) by
hekvvddtest
Greetings
: Obtain The Scoop On mulberry bags Before You Are Too Late
(13) by
hekvvddtest
Calendar Of Events
: HITBSecConf2013 – Amsterdam
(9) by
hekvvddtest
Special Events
: [Article]-Webcast: Deep Dive into Red Teaming with the Metasploit Framework
(19) by
hekvvddtest
Network Pen Testing
: HackaServer - Anyone tried it?
(4) by
hekvvddtest
Greetings
: Good day ...
(7) by
hekvvddtest
Gates
: Chris Gates' Blog RSA Finalist
(5) by
hekvvddtest
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(1) by
hekvvddtest
General Certification
: nth topic on Career Advice
(9) by
hekvvddtest
General Certification
: Direction
(5) by
hekvvddtest
Hardware
: Discreet Hacking Devices
(8) by
hekvvddtest
Calendar Of Events
: CanSecWest 2013
(5) by
hekvvddtest
Forensics
: Burn Note
(5) by
hekvvddtest
Calendar Of Events
: Cyber Readiness Challenge - Rome
(1) by
hekvvddtest
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(0) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(0) by
prats84
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(27) by
don
Greetings
: Hi from the UK
(2) by
n37sh@rk
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.