Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 67 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow GPEN - GIAC Certified Penetration Testerarrow To be A pen tester
EH-Net
May 25, 2012, 10:58:53 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: To be A pen tester  (Read 6536 times)
0 Members and 1 Guest are viewing this topic.
it experts
Newbie
*
Offline Offline

Posts: 4


View Profile
« on: August 06, 2010, 11:06:13 AM »

To be a pen tester, shall i go for SANS 504 or 560 training and othre than that what is the best book you cab advice me to read before and after the training ??

Logged
COm_BOY
Full Member
***
Offline Offline

Posts: 129


LivinG DeaD


View Profile
« Reply #1 on: August 06, 2010, 11:12:46 AM »

Can you let us know your skill level ? this can include degrees, certs, experience, age etc.
Logged

It has become appallingly obvious that our technology has exceeded our humanity.
hayabusa
Hero Member
*****
Offline Offline

Posts: 1304



View Profile
« Reply #2 on: August 06, 2010, 11:24:24 AM »

Funny... I just asked 'kind of' similar in response to his other post. 

Please do your best, 'it experts' to find a specific forum section, relative to your needs, and post once, only.  It saves repetition...  additionally, those of us who are regulars on here see posts in ALL forums, anyway, so I can assure you, we'll see it, whichever forum you post it in, and if it's NOT in a proper section, don or the moderators can move it...
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCP , GPEN, C|EH
it experts
Newbie
*
Offline Offline

Posts: 4


View Profile
« Reply #3 on: August 06, 2010, 12:08:57 PM »

Thanks for the reply and sorry for posting the subject twice.

my experience in security is manly with network security, i have lots of certification in this side (CCIE Security, Juniper Specialist, and others) you can say in the security as a (firewall, IPS, VPN, ..etc) i am expert in most of the top vendor.
Also i am expert in information security (I am CISSP, and CISM certified) and I am specialized in ISO 27001.
The week point I have is I do not have any experience in programming  Sad .
Related to OS I have little knowledge
I am working as security consultant and would like to enhance my knowledge and be Penetration tester. For the pen testing I know the basic theory part but no hands on experience at all 
My plan is to be a network pen testing then focus on application and DB pen testing. I start reading the bible in network security for Eric Col. And planning to go for SANS training  after 2 months.
Now to achieve my aims to be expert in Pen testing. I need your support and guide of what to do and which training to take (SANS 504, 560)
BTW, my company depends on me to add this service to our customer. So please I do not want to let them down.
I hope thing become clear now Smiley
Logged
hayabusa
Hero Member
*****
Offline Offline

Posts: 1304



View Profile
« Reply #4 on: August 06, 2010, 12:22:03 PM »

No worries, on the duplicate posts... was more or less just noting it, as a common courtesy!   Wink

As for your knowledge range, you've got quite the resume there.  With the knowledge you have, my personal experience says you could go ahead and go with the 560.  I know you said you had little OS or programming experience, but if you truly have achieved CCIE Security and some of the others you've listed, I think you'll be OK, and you can come up to speed, quickly enough, to go at 560. 

Are you looking at vLive, or classroom?  Obviously, the face-to-face experience, especially if you get Ed Skoudis teaching you, would be 'best possible scenario.'  (Not that other instructors or methods wouldn't suffice, as well, just that, coming in, cold, sometimes, having the instructor at your fingertips can be of benefit.) 

Pentesting, full-time, you'll eventually want to delve more into programming and such, as well as learning more of web application and programming languages, but I think the concepts and knowledge you'll need will continue to build, with experience and further education / learning, as you grow with it. 

Now, to be fair, I WILL say, I think you'd have an easier go at either of the SANS courses, if you first had Security+ and / or CEH, and had more fundamental base knowledge specific to this field.  However, again, if you're capable enough to hold the certs you list, I think you'll be alright.

My opinions, anyway...   Grin
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCP , GPEN, C|EH
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 650


aka dynamik


View Profile WWW
« Reply #5 on: August 06, 2010, 11:22:32 PM »

*sigh*

I swear, whenever I end up responding to a duplicate post, it's always the one that isn't popular.

You really shouldn't have a problem with GPEN. It's more network based than anything, and if you have a CCIE, the material should come to you quickly.
Logged

WIP: OSCP | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
hayabusa
Hero Member
*****
Offline Offline

Posts: 1304



View Profile
« Reply #6 on: August 07, 2010, 07:33:16 AM »

LOL...  Good morning, dynamik!  Wink
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCP , GPEN, C|EH
COm_BOY
Full Member
***
Offline Offline

Posts: 129


LivinG DeaD


View Profile
« Reply #7 on: August 07, 2010, 11:31:30 AM »

I would recommend you going for the PWB course by offsec , its way better and cheaper than other courses out there also its not a spoon-fed course and you need to refer to quite a lof of guides/books/tuts inorder to get things settled down so I would say you can enjoy much more in PWB then in GPEN
Logged

It has become appallingly obvious that our technology has exceeded our humanity.
it experts
Newbie
*
Offline Offline

Posts: 4


View Profile
« Reply #8 on: August 07, 2010, 04:46:20 PM »

Thanks all for the reply.

Actually, the 504 course will be run by: Ed Skoudis, and the course 560 by someone else and I am planning to go for SANS in Singapor , I am thinking to take the basic with Ed in 504 and I can continue self study and practice, and since he is the author of 560, defiantly I will get benefit and he will guide me to the right direction. The 560 course will be in London by some one else (that’s why I do not want to take it). Any way my concerns is if I take the 504 course with Ed, can I start doing pen-test for network or I need to attend 560???

Also can you help me in the following?
1. What is the best list of books to start and become expert in pen testing?
2. Any video or other resources  I need?
3. What is the offsec course.

Thanks again for your support and guide.
Logged
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 650


aka dynamik


View Profile WWW
« Reply #9 on: August 07, 2010, 05:39:16 PM »

While there's a lot of technical overlap between the two courses, they are taught from different perspectives. The difference is responding to someone attacking you and performing the attacks yourself. If you are going to be performing penetration testing, I strongly encourage you to take the 560. It covers other non-technical items that are important for penetration testers to know. Report writing, legal issues, providing value to organizations, etc. You can view a day-by-day breakdown of the topics covered at each course's website. If you cannot attend locally, there are also vLive and On-Demand options where you can take the course remotely.

http://www.amazon.com/Professional-Penetration-Testing-Creating-Operating/dp/1597494259/ref=sr_1_1?ie=UTF8&s=books&qid=1281220361&sr=8-1 would be a good book to start with.
Logged

WIP: OSCP | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
Dark_Knight
Full Member
***
Offline Offline

Posts: 215


View Profile WWW
« Reply #10 on: August 07, 2010, 07:02:56 PM »

I am currently reading Counter Hack Reloaded, and am finding that it's basically the Sans 560.

Logged

CEH, OSCP, GPEN, GWAPT, GCIA
http://sector876.blogspot.com
impelse
Sr. Member
****
Offline Offline

Posts: 493


View Profile
« Reply #11 on: August 07, 2010, 09:04:31 PM »

I am currently reading Counter Hack Reloaded, and am finding that it's basically the Sans 560.



Is it not to old (2006)?

I never read the book that why I am asking.
Logged

CCNA, Security+, 70-290, 70-291
CCNA Security, Working Windows 7 70-680
hayabusa
Hero Member
*****
Offline Offline

Posts: 1304



View Profile
« Reply #12 on: August 07, 2010, 09:39:38 PM »

dynamik gives good advice.  If you're looking to do more of the pentesting, then 560 is definitely more along that line, based on what I've heard and read.  (Again, I haven't taken either, yet, so...)
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCP , GPEN, C|EH
Dark_Knight
Full Member
***
Offline Offline

Posts: 215


View Profile WWW
« Reply #13 on: August 07, 2010, 10:49:45 PM »

I am currently reading Counter Hack Reloaded, and am finding that it's basically the Sans 560.



Is it not to old (2006)?

I never read the book that why I am asking.
Just a tad Smiley It covers up to windows server 2003. However the attack principles are more or less the same.

To the OP, check out the OSCP offered by offsec. 
Logged

CEH, OSCP, GPEN, GWAPT, GCIA
http://sector876.blogspot.com
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 7.165 seconds with 23 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.