Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 52 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
General Certification
Most in-demand certifications
EH-Net
May 21, 2013, 08:02:50 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
General Certification
(Moderator:
don
) >
Most in-demand certifications
Pages:
1
[
2
]
Go Down
« previous
next »
Print
Author
Topic: Most in-demand certifications (Read 14384 times)
0 Members and 1 Guest are viewing this topic.
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: Most in-demand certifications
«
Reply #15 on:
August 04, 2010, 06:10:45 PM »
In Canada, the Communications Security Establishment (CSE) is more or less the equivalent of the NSA in the United-States. They are responsible for evaluating security professionals working for the canadian government. Here are the
ONLY
certs they value:
CISSP from (ISC)2
CISSP / ISSEP from (ISC)2
CISSP / ISSAP from (ISC)2
CISSP / ISSMP from (ISC)2
CISM from ISACA
CISA
GIAC / Any Silver audit certification
GIAC / Any Gold audit certification
GIAC / Any Silver management certification
GIAC / GSFP, GEIT Gold management certification
We are always 5 years behind the american DoD...
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: Most in-demand certifications
«
Reply #16 on:
August 04, 2010, 06:13:52 PM »
BTW, Sil, why don't you write a book?
You are good at teaching others and this would be a great challenge!
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
sil
Hero Member
Offline
Posts: 549
Re: Most in-demand certifications
«
Reply #17 on:
August 04, 2010, 06:56:42 PM »
I thought about it a few times. The fact is, I would likely have a few books to write. Some would make people do a Home Alone (
http://images.eonline.com/eol_images/Articles/20071211/293.home.alone.121107.jpg
). I thought about an "Art of Cyberwarfare" style book based on attacks with explanations of the attack vector and logic behind potential defenses. The problem with this style of writing would be that the moment that the book was quoted as being behind some scriptkiddiot's attack, would be the moment the industry would poop on the book: "How could they publish such a book!"
The reality is, in order to truly comprehend ANY defensive strategy, one MUST be familiar with the attack vector and the inherent and potential dangers behind it. For example, in 2005 Theo DeRaadt @ OpenBSD decided away with ICMP source quenches in the network stack to which I responded... "Nothing new move along" (
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2005-07/0101.html
) I had written about this starting in 1999 and releasing a PoC in 2000 (
http://www2.packetstormsecurity.org/cgi-bin/search/search.cgi?searchvalue=tidcmp&type=archives&
[search].x=0&[search].y=0)
People didn't get it then. Same went for Bubonic and Daemonic. Back then Richard Bejtlich got it (
http://seclists.org/incidents/2000/Aug/277
) others didn't. Right now I have a pretty nasty tool I won't ever release because it literally allows me to turn your device into a firewall like it or not. Imagine that for a moment... I aim it at any networked device you have, that device stops sending and receiving period until I give you room to breathe. I went over the tool and what it does with NANOG, IETF, Cisco, Foundry, Sun and others. Its really nasty, the solution? Rewrite TCP which no one would do. (seriously) Ask yourself, if I can find this tinkering how long before someone has as much time and weird creativity or can fuzz that much.
I did think about the book gig before, the problem: Content... I wouldn't want to do anything anyone else has done. In order for a company to publish it, there has to be an audience. An audience filled with "Go to hell...", "why the f,,, would someone write this book!...", "there goes our networks..." wouldn't make for much appeal
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
yatz
Full Member
Offline
Posts: 222
Re: Most in-demand certifications
«
Reply #18 on:
August 06, 2010, 11:27:05 AM »
Just found this article today, which pretty well sums up what I've been seeing in the industry over the past few years, and what has been said on this site a number of times.
http://www.computerworld.com/s/article/9180194/Let_s_certify_business_savvy
Quote
But no IT certification currently available can gauge whether a professional understands how IT supports and complements the overall business.
And this part too:
Quote
We need a new type of certification, one that measures a person's understanding of how computing integrates into, and drives, today's business. A certification that weighs understanding of business computing concepts, business processes, communications skills and technical acumen would better reflect the package of skills needed in today's IT workforce.
This is probably why PMP is on the above-mentioned list, but PMP really isn't enough.
Still, it always seems to be polarized. At my company we have some very gifted help desk folks and a network admin who manages well and knows his stuff, but none of these guys have much business knowledge and readily pass those tasks to either myself or to one of our database admins. Unfortunately, the DB guy is on the opposite end and knows the business really well and has electrical and computer experience (obviously since he's a DBA), but if you try to talk to him about taking away admin rights of users or antivirus or patching and all he'll say is it hinders the business and puts unnecessary blocks in the way. Absolutely no idea about INTERNAL threats, much less exploited users (social engineering or otherwise). Keep in mind this guy still writes all his apps in VB6 because it's easier, but because of that we've had to deal with insecure and unsupported objects and protected environments, all of which "prevents us from doing business."
I'm caught in the middle, but sometimes its comfy since I can talk to everyone with some level of understanding. Getting into the security side too requires knowledge on both sides of the table, which is probably why I've seen so much of this opinion on this site.
Logged
"Live as though you would die tomorrow, learn as though you would live forever."
CCNA, MCSA, MCTS, Sec+, Net+, Linux+, CEH
impelse
Hero Member
Online
Posts: 565
Re: Most in-demand certifications
«
Reply #19 on:
August 06, 2010, 12:26:53 PM »
Intesting article.
Rember doesn't matter were you are there will be always somebody that will say: does not important, etc, etc
Logged
CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training
Website:
http://blog.thehost1.com/
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: Most in-demand certifications
«
Reply #20 on:
August 06, 2010, 06:21:11 PM »
It takes years of experience to become a good team lead or project manager. It also takes years of experience to become very good in a narrow field in IT. That's why it is difficult to find both qualities in the same person.
Certs test knowledge, not experience...
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
sultanmg
Newbie
Offline
Posts: 5
Re: Most in-demand certifications
«
Reply #21 on:
September 14, 2010, 07:54:26 PM »
That is absolutely true, especially in Canada. I do not know how the similarity comes to have taken place but the truth is the communication security establishment is very much similar or almost similar to the National Security agency of the United States of America. I guess there has been a medical report of someone trying to poison another official there. At least that is what I have heard from the hospital I have worked in USA
Logged
Debt relief solutions
Pages:
1
[
2
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Programming
: Finished Python Course in Codecademy now what?
(11) by
securitian
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
Tutorials
: Need guidance
(8) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.