Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 101 guests online
You are here:
Home
Resources
Career Central
High barrier for entry to career X
EH-Net
May 23, 2013, 11:28:47 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Resources
>
Career Central
(Moderator:
don
) >
High barrier for entry to career X
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: High barrier for entry to career X (Read 3456 times)
0 Members and 1 Guest are viewing this topic.
tturner
Sr. Member
Offline
Posts: 432
High barrier for entry to career X
«
on:
December 22, 2010, 10:07:59 AM »
There seems to be a trend at EH.net where an experienced member will indicate what a world class pentester, malware analyst, etc needs to do their job. For the newbies here, of which I sometimes qualify, it can be very easy to get discouraged at the mountain of knowledge necessary that seems insurmountable. Sure, those lists are ideal but there are hundreds if not thousands of people working in these fields with a small subset of this entire knowledge and many of them are providing excellent value for their customers. And yes, some of them are charlatans. I was talking to an IBM ISS pentester the other day who told me many of the people on his team don't write exploits. they have people who can of course, but not everyone on the team has those skills and quite often the engagement does not allow time for it anyway. The point here is that in many cases it's a team environment. Not every person has to be able to be a ninja in every area. I think it's helpful to define a bare minimum baseline and I have seen some posts that do that and appreciate that but sometimes I think even that baseline gets set a little high.
The purpose of this post is not to discourage these "end game" threads or criticize those who have compiled these lists because that information is extremely valuable, but more to provide some encouragement to our less experienced folks. You have to start somewhere. Don't be scared. Take the leap!
Logged
Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP
WIP: OSWP, GSSP-JAVA, GXPN
Udacity on hold, again. I suck.
http://sentinel24.com/blog
@tonylturner
http://bsidesorlando.org
sil
Hero Member
Offline
Posts: 549
Re: High barrier for entry to career X
«
Reply #1 on:
December 22, 2010, 11:11:09 AM »
tturner makes some excellent points. You don't have to know the industry full circle (writing exploits, AND exploiting machines, AND analyzing the post forensics, AND etc, etc,) but it will help you understand as much as you can, which 1) makes you more valuable to a company 2) helps make your own job easier
On my RWSP review, I believe I pointed out the need for "teamwork" in order to pass that exam. There can BE NO all inclusive expert however, there can be those who are versatile. This is one of the reasons I'm a stickler for understanding things from the ground up (
http://www.ethicalhacker.net/component/option,com_smf/Itemid,54/topic,6202.msg34503/#msg34503
). The more you know, the better prepared you will be.
It all boils down to "determine what it is you want to do." If you want to focus on exploit writing, so be it, as I explained in the Assembly post (
http://www.ethicalhacker.net/component/option,com_smf/Itemid,54/topic,6426.msg34507/#msg34507
) there is A LOT of overlap in many fields. Certainly understanding as much as you can from the core level will help you. NO ONE and I mean NO ONE I have come across is an expert in all levels of security. While I may know some bad ass exploit writers, fact is, they'll often suck initially at response/forensics because they haven't been exposed. However, they do have the capacity to figure things out if they understand other aspects of the OSI (networking, process intercommunications, etc)
So tturner makes some excellent points to those in this arena. I'm always (rinse and repeat... ALWAYS) trying to learn something, anything while ALWAYS retaining knowledge of the underlying scope...
SOAP, XML, JAVA, ASP, C# do you think I know these areas enough to make a career in the field, heck no. But I do know enough to state they all have the same fundamentals: they're networked and they either receive or send data somehow. Now I need to figure out how and why. Forget trying to program in the language, I just need a bare understanding of the interprocessing of the application from the host and network layers. The rest is what Google is for.
To add more to tturners excellent post, I will say this... DO NOT BE INTIMIDATED BY ANYONE or ever feel "I will never get to that level." 1) There is no level, there is only what you're willing to learn - with that said, you are either your best friend or your own anchor. 2) Read, read, read, break break break and FIX FIX FIX. In doing so, you're exposing yourself to many processes in the mix. Even purposefully misconfiguring machines is a learning experience! 3) Have fun. When you view the field as a fun, challenging game, it becomes more interesting. I play Chess against myself... I do my best not to deceive myself but play as I were competing against myself. It's a PITA but the experience allows me to go back and remember what I was thinking at the time, what I intended on doing, how I would have done things differently.
So when I POST something like: "This is what I would do..." it's a suggestion based on experience I may have in the industry. What worked for me. I in no shape form or fashion try to discourage anyone in fact, I would hope that I do the opposite (encourage) those to look at things differently from the ground up.
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
H1t M0nk3y
Hero Member
Offline
Posts: 865
Re: High barrier for entry to career X
«
Reply #2 on:
December 22, 2010, 12:04:20 PM »
I totally agree with tturner too!
Baby steps are the key of every big successes. I rate myself about 4/10 on where I want to be, but last year, I was at 2/10, so I am happy!
That being said, I and many others on this forum try to ask newcomers to be a little bit more precise. Like in the Assembly post mentioned by sil above, we asked the guy what he really wanted to do. Then we try to adapt our language and help him as much as we can.
But that being said, we are all grown adults here. If someone's goal is to reverse-engineer malware, learning these skills will not happen overnight. Same as forensic investigator, like it has been posted on this site about a month ago, when you bring someone to court, you better know what you are doing. Samething with a pen test, before you can feel confident that the server/network/application cannot be hacked, you need a lot of experience.
Maybe it is because I have been in tne infantry, but I am more for telling the plain truth BUT doing so by being encouraging and by helping and guiding people. I myself really want to know what I am against to before starting...
Also, to me, it depends on the topic the thread is about. Questions like "I am new to the field and want to get advice on getting prepared for CEH" is not the same as "I have written about 20 exploits so far and I need advice on creating a new Metasploit payload". The answers will be totally different on this forum.
So my view on this is like you tturner, jump in and discover this fascinating world, on step at the time. But at the same time, I feel that this forum is probably the "easiest" at newcomers on the entire web. Anyway, when I started posting here a year ago, I didn't felt discouraged at all. In fact, I was (and still) saying "thanks a lot for this awesome response" all the time!
But being a consultant, the barrier to me is VERY high!
So let's keep this site like it is, ok?
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
Dark_Knight
Sr. Member
Offline
Posts: 292
Re: High barrier for entry to career X
«
Reply #3 on:
December 22, 2010, 12:53:54 PM »
Quote
NO ONE and I mean NO ONE I have come across is an expert in all levels of security.
I don't think we have met kind sir
Quote
DO NOT BE INTIMIDATED BY ANYONE or ever feel "I will never get to that level."
Now he tells me. Too late
Great posts though guys. All very well said.
Logged
CEH, OSCP, GPEN, GWAPT, GCIA
http://sector876.blogspot.com
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(3) by
H1t M0nk3y
Greetings
: Hi from the UK
(3) by
UKSecurityGuy
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(0) by
prats84
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(27) by
don
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.