Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 26 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
OSCP - Offensive Security Certified Professional
Acquiring Knowledge
EH-Net
May 26, 2013, 04:44:24 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
>
OSCP - Offensive Security Certified Professional
(Moderator:
don
) >
Acquiring Knowledge
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Acquiring Knowledge (Read 7181 times)
0 Members and 1 Guest are viewing this topic.
Lubinski
Newbie
Offline
Posts: 26
Acquiring Knowledge
«
on:
December 07, 2010, 12:50:24 PM »
After looking through a few certifications I have come to the end result that I will purchase the PWB courseware from the Offsec guys.
My main goal is to gain knowledge to support the Bachelors in Information Security I have. This looks like a great place to start.
I'm not a huge Linux person atm but I have been working more and more with Backtrack lately.
Is this course appropriate or should I start lower on the ladder?
I see a course from elearnsecurity but It does not look as good or come as highly recommended.
Logged
xXxKrisxXx
Hero Member
Offline
Posts: 512
Re: Acquiring Knowledge
«
Reply #1 on:
December 07, 2010, 01:36:36 PM »
If you have a Bachelors in InfoSec and have been exposed to Penetration Testing and Vulnerability Assessment in your classes I'd say go for it if your willing to suffer a little bit. I don't have a degree in InfoSec, and I opted for the course.
The questions I'd ask myself before taking the class is, how comfortable am I with BackTrack? Personally I walked in knowing a good amount of Metasploit, NMap, Reconnaissance, knew how to compile and run exploits, fix some public versions of exploits, and had some python experience I had gotten from school.
I wouldn't say this is a beginner course, during the exam your basically thrown into a cage with lions and forced to fend for your own *
*
eLearnSecurity's not a bad course at all. I think it depends on your comfortability level in the field of Hacking. I would definitely recommend it for the absolute beginner. You get more Web Application testing knowledge out of it then you do out of PWB, and it's a great course to start with.
I personally had a blast in PWB and thought the OffSec Style of PWB training (which is basically, "Here's the lab guide, here's the course videos, there's 50+ machines spread out across 4 subnets - Happy Hacking), was more of my personal learning style.
There's a few of us who have our OSCP certifications on this board, don't feel hesitant to ask questions!
Welcome to the forums!
-kris
Logged
eCPPT, GCIH, OSCP, OSWP
sil
Hero Member
Offline
Posts: 549
Re: Acquiring Knowledge
«
Reply #2 on:
December 07, 2010, 02:26:34 PM »
Quote from: Lubinski on December 07, 2010, 12:50:24 PM
I see a course from elearnsecurity but It does not look as good or come as highly recommended.
This is like the saying "opinions are like..." Here are a few things I'd like to throw out to you - for you to ponder.... Certification ... Learning... Which do you prefer?
Certification
- overrated at times especially when one is seeking to "dump" - I need to pass this class!!!. You're likely to retain little and not learn at the end of the day.
Learning
- always in fashion
There is no "
wrong
" course to learn from. I haven't taken eLearnSecurity's course because I don't need it - and I'm not saying this to be arrogant. I'd actually LOVE to take it for the sake of learning
something
, but at the end of the day, it doesn't benefit me so I choose to focus my money and time elsewhere. I would STILL learn from it I'm sure though. There are plenty of people here who have taken it and liked it alot. There were some who didn't.
As for the OSCP, you state you have little Linux experience (based off your statement:
I'm not a huge Linux person atm but I have been working more and more with Backtrack lately.
) so my perception/interpretation is, you will find the OSCP difficult and likely fail the first, second and perhaps the third time around. You WILL LEARN doing the OSCP but it might be akin to jumping into trigonometry without understanding basic algebra.
Back in 06/07 I started a "Pentesting 101" write up (
http://infiltrated.net/pentesting101.html
) where I laid down what I felt was a STRONG 52 week step-by-step to become a decent/well rounded pentester. It includes understanding the entire gamut of operating systems, networking, applications, etc.. There will NEVER be an "all inclusive" course to become a "ninja pentester" as there are too many variables (web applications, presentation layers, covert channels(networking), etc.) the key to it all is understanding as much as possible.
E.g., when I did my RWSP, I was completely on all their machines and was completely stumped on MSSQL syntaxing. Guess what? I come from a Linux/BSD/Solaris world. Postgres (check), MySQL (check), Oracle (check)... MSSQL? Nah, not my cup of tea. Had I taken the time for a refresher, I'd of not wasted time - in the end, I ran out of time. Anyhow, because of what you mention (minor *nix) experience, I suggest you start with ELearnSecurity, get comfortable with it, then aim for the OSCP only AFTER you're extremely comfortable with not only Linux, but a variety of topics.
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
xXxKrisxXx
Hero Member
Offline
Posts: 512
Re: Acquiring Knowledge
«
Reply #3 on:
December 07, 2010, 03:10:15 PM »
After reading sil's comment and going over mine, I don't want to make it seem like I'm setting you up for a rough time in PWB Lubinski.
Quote
You WILL LEARN doing the OSCP but it might be akin to jumping into trigonometry without understanding basic algebra.
This is very true in this situation. My first post made it come off like PWB was easy if you had some good background. I hadn't mentioned that I had been using BackTrack since 2007 prior to taking PWB in 2010. I'm not saying you need to have years experience in linux to sign-up, they mainly want you to be comfortable.
Are these the only two vendors you've compared? Have you looked into
HackingDojo
or
LearnSecurityOnline
yet? These are other positive places to get your hands dirty at affordable prices too.
-kris
Logged
eCPPT, GCIH, OSCP, OSWP
Lubinski
Newbie
Offline
Posts: 26
Re: Acquiring Knowledge
«
Reply #4 on:
December 07, 2010, 04:42:40 PM »
Thanks for the replies, I am currently looking at the various other options posted here.
I did not mean to portray elearnsecurity as a bad option, just that the PWB course looks better after looking at both. Price is sort of a major factor here so we will see what the budget boils down to.
I will keep you posted and thanks for all the info.
Logged
MaXe
Hero Member
Offline
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: Acquiring Knowledge
«
Reply #5 on:
December 07, 2010, 05:34:20 PM »
Courses by Offensive Security, are highly recommendable and you will learn a lot but also go through a rough period of learning, including trial and error
I've done OSCE, and that was pain inserted directly into my cerebrum
It was awesome though, and it has given me something I can use for the rest of my life.
I haven't tried LSO, eLearnSecurity and Heorot (Hacking Dojo) yet, but in the future I most likely will
Logged
I'm an InterN0T'er
alucian
Full Member
Offline
Posts: 225
Re: Acquiring Knowledge
«
Reply #6 on:
December 09, 2010, 08:58:24 AM »
In my opinion, in your case, the best place to start will be hacking dojo. It will start you from the basic, and while it will cost you less money you'll get an inside view of the pentest world. If you'll like it you'll learn a lot, if you'll not like... you'll save money and find yourself a new career path (firewalls, compliance...)
One of the biggest advantages of hackingdojo is that you will actually talk with the instructor (Tom) and you can ask him almost anything. On the oposites, doing OSCP you'll be on your own (in a lions cage
).
Logged
CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
Lubinski
Newbie
Offline
Posts: 26
Re: Acquiring Knowledge
«
Reply #7 on:
December 11, 2010, 06:23:21 PM »
I will take another look at the dojo. Thanks for tip. Can someone describe the experience they have had with hackingdojo.com? I got some information off of their site but if you can fill in the spaces that would be wonderful.
Logged
hayabusa
Hero Member
Offline
Posts: 1633
Re: Acquiring Knowledge
«
Reply #8 on:
December 11, 2010, 07:12:06 PM »
While I've not taken the courses from the Dojo, yet, I have Tom's book (Professional Penetration Testing,) and it's a good read. In addition, Tom is a member here (Grendel,) so along with others' experiences, you can ask him plenty, as well.
Good luck.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
Lubinski
Newbie
Offline
Posts: 26
Re: Acquiring Knowledge
«
Reply #9 on:
December 11, 2010, 09:56:19 PM »
Excellent. I feel like i stumbled upon a golden trove of usefulness here..
Logged
cd1zz
Recruiters
Hero Member
Offline
Posts: 561
Re: Acquiring Knowledge
«
Reply #10 on:
December 22, 2010, 06:50:45 PM »
I don't think that just because you don't have that much Linux experience that you shouldn't take the course. I didn't have that much linux exp either and I passed on my first try. BUT I did have to work my ass off at it. I had to ramp up my Linux skills really fast and now they're acceptable. I just passed a couple weeks ago and documented my experience here if you're interested:
http://networkadminsecrets.blogspot.com/2010/12/offensive-security-certified.html
The bottom line is if you have solid fundamentals, meaning you understand routing/protocols and how an OS works, you could probably get to where you need to be in 60-90 days. Quite frankly if you don't pass on the first try its not that big of a deal because you can retake for $60. Its not like you have to drop $500 to retake the exam. Put in the hard word and it will pay off.
Logged
OSCE | OSCP | GXPN | OSWP | CISSP
http://www.pwnag3.com
http://www.networkadminsecrets.com
mayjune
Guest
Re: Acquiring Knowledge
«
Reply #11 on:
December 23, 2010, 04:51:48 PM »
Thank you so much guys for your inputs....
It was highly valuable. I am considering hackingDojo, and more imp to brushing up my fundamental skills side by side.
Thanks again.
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Network Pen Testing
: Tomcat authentication with sqlmap
(14) by
trieffist
Ethical Hacktivism
: EH perception of Anonymous
(7) by
VeifyVido
News Items and General Discussion About EH-Net
: Салют фанаты
(10) by
VeifyVido
Calendar Of Events
: IANS DC InfoSec Forum
(2) by
VeifyVido
Network Pen Testing
: You'll find this funny but I'm pretty serious. Need my own servers "hacked"
(8) by
VeifyVido
General Certification
: Security Tube Python Scripting Expert - Community content?
(3) by
VeifyVido
Calendar Of Events
: Cyber Readiness Challenge - Prague, CZ
(3) by
VeifyVido
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(95) by
zeebee
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(30) by
don
Tools
: Symbolic Exploit Assistant project is looking for collaborators
(0) by
galapag0
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.