
Read some good books, take note of what is said (and of course make sure what you are doing is legal)
A couple of books I recommend for a noob to get a nice grounding of protocols, tools and what to look for:
Network Security Assessment (2nd Edit)
HackNotes (old but good)
Hacking thru email - don't you get enough spam in your own inbox with zip file attachments or links to PAYPOL (and no I have spelt that right)
Phishing was okay and still gets the unsuspecting, spear phishing is more direct but takes more time. Profiling is the way forward