Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 89 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow GPEN - GIAC Certified Penetration Testerarrow How difficult is the GWAPT certification
EH-Net
February 10, 2012, 01:42:47 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: How difficult is the GWAPT certification  (Read 10421 times)
0 Members and 1 Guest are viewing this topic.
T_Bone
Full Member
***
Offline Offline

Posts: 190


View Profile
« on: December 29, 2009, 03:17:12 AM »

Hi Guys

Is there anyone out there whom has taken both the GPEN and GWAPT certs? If so which was more difficult please?

Cheers
Logged
Jhaddix
Sr. Member
****
Offline Offline

Posts: 317



View Profile WWW
« Reply #1 on: March 05, 2010, 10:45:27 PM »

Hey T_Bone,

I've taken both classes, passed the GPEN, going on for the GWAPT in the next few weeks.

As far as the content goes Sec542 was harder for me. I never did web development in the past so some of the attacks were new things, for instance attacking/enumerating SOAP web services. i dont see it as much more difficult though.

Ask apollo, he's passed both i think... =)
Logged

apollo
Full Member
***
Offline Offline

Posts: 142


View Profile WWW
« Reply #2 on: March 06, 2010, 01:36:36 AM »

The GWAPT test was harder than GPEN test.  Part of it is that web pen testing is about nuance where many of the things on GPEN are more straight forward.  An app is either vulnerable or it's not, where an XSS or SQL injection can look a number of ways.  We covered Nessus in GPEN, there are 4 or 5 scanners used for GWAPT.  It's the little things that will get you.  I thought the GWAPT class was harder than the GPEN class too.  I think that part of that is due to the fact that Ed Skoudis is a badass when it comes to course devel.  His courses have a great flow to them, and Ed is an excellent educator.  Kevin's class, the web app pen testing class, is very good but the information doesn't have as much of a flow to it.  It is still an excellent class, but the material that has to be covered can't really have as much of a natural flow to it. 

This is more forward than I normally am, but take 560 (GPEN) before you take 542 (GWAPT) I think, the GPEN will get you the business knowledge and the GWAPT covers more skills type things.  Once you're thinking like a pen tester business and skills wise, the GWAPT will go better.  GWAPT was a kick ass class though, and you will learn great stuff.  I haven't seen any course material out there that covers what GWAPT covers as well as it covers it.

Logged

CISSP, CSSLP, MCSE+Security, MCTS, CCSP, GPEN, GWAPT, GCWN, NOP, OSCP, Security+
H1t M0nk3y
Hero Member
*****
Offline Offline

Posts: 660



View Profile
« Reply #3 on: March 06, 2010, 04:59:02 PM »

Other than GWAPT, is there any other courses/certs related to web app pentesting?
Logged

GPEN, GSEC, CEH, CISSP, PMP
xXxKrisxXx
Sr. Member
****
Offline Offline

Posts: 491



View Profile
« Reply #4 on: March 06, 2010, 07:02:37 PM »

@ h1t m0nk3y - Here's an affordable course that I know about related to Web App Testing.

LSO - So You Want To Be A Web App Pentester

Also check out the 3DCPT From Heorot.net - it looks to be focused on web attacks.

http://heorot.net/training/

Cheers
« Last Edit: March 06, 2010, 07:13:04 PM by xXxKrisxXx » Logged

OSCP, OWSP, eCPPT
BigPrince
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #5 on: March 06, 2010, 08:13:58 PM »

542 was harder than 560.  I agree with the above that if you can, do both with 560 first.  Great classes.
Logged
Dark_Knight
Full Member
***
Offline Offline

Posts: 208


View Profile WWW
« Reply #6 on: March 06, 2010, 09:07:06 PM »

For the guys who say the GWAPT was harder than the GPEN, what is your background? Is it in development/programming or network admin stuff?
Logged

CEH, OSCP, GPEN, GWAPT, GCIA
http://sector876.blogspot.com
H1t M0nk3y
Hero Member
*****
Offline Offline

Posts: 660



View Profile
« Reply #7 on: March 07, 2010, 06:36:35 AM »

Thanks xXxKrisxXx, I appreciate it!

GPEN and GWAPT are a bit pricy for me at the moment, these are indeed very good alternatives!
Logged

GPEN, GSEC, CEH, CISSP, PMP
apollo
Full Member
***
Offline Offline

Posts: 142


View Profile WWW
« Reply #8 on: March 07, 2010, 09:31:33 AM »

For the guys who say the GWAPT was harder than the GPEN, what is your background? Is it in development/programming or network admin stuff?

Both, I program in c/c++/php/perl/python/ruby/lua predominantly but am not a true developer.  The reason the web stuff is harder course wise is that there is much more subtlety to what you are doing.  Do you need a ' or a " when you are doing a specific injection.  What happens when the script upper cases every command you type for command injection (unix doesn't like that much).  Those sort of things you don't have to deal with as much in the network pen testing classes.

That said, I should say if you have no programming background at all, you may find 542 even more challenging.  There are days in there to teach basic scripting, but you will be slower than your counterparts who have some very basic experience in programing/scripting.  That said, you don't have to have programming knowledge to take the course, you will do ok without it, but you will have to work harder.
Logged

CISSP, CSSLP, MCSE+Security, MCTS, CCSP, GPEN, GWAPT, GCWN, NOP, OSCP, Security+
Dark_Knight
Full Member
***
Offline Offline

Posts: 208


View Profile WWW
« Reply #9 on: March 07, 2010, 02:42:13 PM »

For the guys who say the GWAPT was harder than the GPEN, what is your background? Is it in development/programming or network admin stuff?

Both, I program in c/c++/php/perl/python/ruby/lua predominantly but am not a true developer.  The reason the web stuff is harder course wise is that there is much more subtlety to what you are doing.  Do you need a ' or a " when you are doing a specific injection.  What happens when the script upper cases every command you type for command injection (unix doesn't like that much).  Those sort of things you don't have to deal with as much in the network pen testing classes.

That said, I should say if you have no programming background at all, you may find 542 even more challenging.  There are days in there to teach basic scripting, but you will be slower than your counterparts who have some very basic experience in programing/scripting.  That said, you don't have to have programming knowledge to take the course, you will do ok without it, but you will have to work harder.

I follow you. I come from a programming background and am currently doing the GWAPT via SansOndemand. Great stuff so far. Kevin Johnson is hilarious Smiley
Logged

CEH, OSCP, GPEN, GWAPT, GCIA
http://sector876.blogspot.com
Salmonella
Newbie
*
Offline Offline

Posts: 1


View Profile
« Reply #10 on: March 10, 2010, 07:49:23 AM »

It depends on your background.  As a developer I found the GPEN to be harder.  Network folks will probably find the GWAPT harder. 
Logged

GPEN, GWAPT, working on GSSP-JAVA
Dengar13
Sr. Member
****
Offline Offline

Posts: 378



View Profile
« Reply #11 on: March 10, 2010, 07:45:06 PM »

I am attending the SANS Sec542 (GWAPT) class right now and think that this is pretty intense.  I agree with Salmonella, I am a networking guy and find this to be pretty advanced.
Logged

A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.186 seconds with 24 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge Training: Build Security Skills to Protect and Defend

offsec_130x200-2_jan-feb2012.png
Offensive Security
AWE Live in the Caribbean!
March 5 - 9, 2012

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: Refer_EHN
Including SANS Phoenix 2012, SANS 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.