Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 42 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Web Applications
Where should I start
EH-Net
May 20, 2013, 02:09:15 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Web Applications
(Moderator:
don
) >
Where should I start
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Where should I start (Read 5599 times)
0 Members and 1 Guest are viewing this topic.
alucian
Full Member
Offline
Posts: 225
Where should I start
«
on:
March 05, 2010, 08:15:52 AM »
I am really interested in this field, and I would like to study more about it, in order be able to do penetration testing on it.
Unfortunatelly my company doesn't want to pay for any certification. My boss says that I have enough certifications and I need more experience (he is 50% right, but I already had all my certifications when I came to them, so they just want to profit of my hard work and my personal money spent on education).
So, my actual plan is to start with "The web application hackers handbook" and to use websec dojo's live cd. Is this enough in order to have a good start, or there are other books to start with?
I mention that I don't have programming skills in the web field, only some C++.
Thank you!
Logged
CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
UNIX
Hero Member
Offline
Posts: 1234
Re: Where should I start
«
Reply #1 on:
March 05, 2010, 08:32:34 AM »
Learning to program in some web-based programming languages definitely wouldn't hurt, at least it would help if you could read and understand it. The book you mentioned is a good read. Additionally you might take a look at the WebGoat Project, which should keep you occupied for quite a while.
Logged
apollo
Full Member
Offline
Posts: 146
Re: Where should I start
«
Reply #2 on:
March 05, 2010, 08:33:41 AM »
While you don't have to learn any web programming to be a web app pen tester, you will have to learn some to be a good one. The resources that you have listed are good, but I might try to go ahead and start working on picking up some php, javascript, etc.
So.. good web resources:
RSnake has some great resources. Check them out at
http://ha.ckers.org/
. Specifically check out the XSS Cheat Sheet. I go back and reference it from time to time when folks have mostly gotten data validation done correctly but have missed something.
Samurai WTF: Samurai Web Testing Framework can be found at http://samurai.inguardians.com/ . This live cd distribution has many of the tools that you will want to become familiar with. This is a pretty lightweight distribution with great tools, and is a great start
I'm sure others will post more
Logged
CISSP, CSSLP, MCSE+Security, MCTS, CCSP, GPEN, GWAPT, GCWN, NOP, OSCP, Security+
UNIX
Hero Member
Offline
Posts: 1234
Re: Where should I start
«
Reply #3 on:
March 05, 2010, 08:36:51 AM »
Another place you might take a look at if you haven't already, is the Web App Lab Setup tutorial at securityaegis. Currently I am getting a 'Not Found Error', but it would be
here
.
Logged
unsupported
Sr. Member
Offline
Posts: 318
Unofficial Newbie Moderator
Re: Where should I start
«
Reply #4 on:
March 05, 2010, 08:59:40 AM »
First off, I think the answer your manager gave you is an asshat managers answer. A manager should be supportive of an employees desire to certify/educate.
What exactly do you do for your company? Does the certification directly relate to your job? If so, it would be an easier sell... but anyway...
I think you might find some great resources from OWASP,
http://www.owasp.org
.
Good luck!
Logged
-Un
CISSP, GCIH, GCIA, C|EH, Sec+, Net+, MCP
alucian
Full Member
Offline
Posts: 225
Re: Where should I start
«
Reply #5 on:
March 05, 2010, 09:16:30 AM »
Thank you guys. I started already the webgoat project. I already visited all the websites you mentioned in your posts, so I'll keep myself busy for a while.
@unsupported: I am working as security analyst for a small security consulting company. When they hired me (4 month ago) they told me that I'll do penetration testing, general security consulting and many more. But I have no work to do, and this bothers me. I came to this company to do a lot of things in order to became a better professional. But... I was wrong. So I am studying a lot of things regarding security (penetration testing, governance, risk analysis, I even started to do wargames - first level, and many more).
I study penetration testing because I like that it makes your brain work and I consider that it is of outmost importance in order to protect a company.
The problem is that my boss didn't gave me any path to follow, any particular field in which he'll need me. And this is very frustating.
Thank you guys for the advices.
Logged
CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
xXxKrisxXx
Hero Member
Offline
Posts: 512
Re: Where should I start
«
Reply #6 on:
March 05, 2010, 10:31:41 AM »
Here's a couple more links that might be useful! (If you haven't taken a look into them yet)
Damn Vulnerable Web App:
http://dvwa.co.uk/
And maybe even look into LearnSecurityOnline's, "So You Want To Be A Web App Pentester" course. It looks like a good price.
http://www.learnsecurityonline.com/offerings/courses/224-so-you-wanna-be-a-webapp-pentester
-Cheers
Logged
eCPPT, GCIH, OSCP, OSWP
alucian
Full Member
Offline
Posts: 225
Re: Where should I start
«
Reply #7 on:
March 05, 2010, 12:41:12 PM »
Quote from: xXxKrisxXx on March 05, 2010, 10:31:41 AM
And maybe even look into LearnSecurityOnline's, "So You Want To Be A Web App Pentester" course. It looks like a good price.
http://www.learnsecurityonline.com/offerings/courses/224-so-you-wanna-be-a-webapp-pentester
-Cheers
I saw the course and it really has a good price, but I didn't saw any review of it. Maybe I'll convince the sponsor (wife) and I'll do it. Then I'll do a review if there isn't another one here.
Thanks!
Logged
CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
alucian
Full Member
Offline
Posts: 225
Re: Where should I start
«
Reply #8 on:
March 07, 2010, 06:17:35 PM »
Well.. me again.
As I mentioned in one post I had a lot of free time at my job, because they don't have many contracts (they are a consulting company). And it wasn't only me, there were more guys that did almost nothing. But because I was the last one employed I got fired Friday. This wasn't fair because I have quit my previous job only because they promised me that I'll have a lot of things to do and I'll learn a lot by doing contracts under the supervision of someone more experienced. But the reality was different.
So, now I have a lot of free time. My dilemma is if I should continue with studying penetration testing (by myself only) or I should go on another direction.
I know that there are many opportunities in firewalls field, but I don't have experience and knowledge (even if I am able to study them). Also, I really don't like this domain, it is not suitable with my personality and way of thinking.
So my problem, should I continue and study hard for the next few months penetration testing (network, web application and system) or I should change the field just to be able to have more chances to find a decent job.
Besides pentesting I will improve my knowledge in risk analysis and project management.
Thank you!
Logged
CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
Ketchup
Hero Member
Offline
Posts: 1021
Re: Where should I start
«
Reply #9 on:
March 07, 2010, 06:34:58 PM »
Sorry to hear the bad news alucian. On the bright side of things, it seems like the job market is picking up. I can' tell you which direction you should pursue, only you can determine that. However, since you have prior consulting experience, you can consider search for a company that does some penetration testing, but it is not their only source of revenue. In today's market, it really helps to be balanced.
Logged
~~~~~~~~~~~~~~
Ketchup
alucian
Full Member
Offline
Posts: 225
Re: Where should I start
«
Reply #10 on:
March 07, 2010, 07:07:26 PM »
@ Ketchup
This was the type of company I was working for, only that it was very small, 10 employees. Also, most of the companies wants to hire you as a consultant and send you to do contracts. They only want to make money on you, not to train you at all.
Logged
CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
UNIX
Hero Member
Offline
Posts: 1234
Re: Where should I start
«
Reply #11 on:
March 08, 2010, 01:39:27 AM »
That's not the best news, indeed. As Ketchup already stated, I too think that only oneself can decide where to head. As you have written that your field of interest is penetration testing, then personally I would continue in this direction, even if it might be hard. I probably wouldn't go into firewalls, if I am not really interested in them. But then again there could be some other factors etc., and everything could look different.
I wish you the best luck.
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(86) by
impelse
Tutorials
: Need guidance
(8) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
General Certification
: CPT Practical Submission
(0) by
z28power4u
Web Applications
: Nessus and Nikto
(4) by
Seen
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.