Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 46 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
General Certification
Noob Question
EH-Net
May 22, 2013, 05:05:16 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
General Certification
(Moderator:
don
) >
Noob Question
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: Noob Question (Read 9282 times)
0 Members and 1 Guest are viewing this topic.
TechMonK3y
Newbie
Offline
Posts: 2
Noob Question
«
on:
December 30, 2010, 08:15:22 AM »
I have been researching and researching on what schools are the best for training in ethical hacking or pentesting and have still came up empty. I mean which one is better to have i know some parts are the same but then you have offensive security with their version of pentesting with back track. Any info on this would help especially if you have completed some of these certs
Logged
sgt_mjc
Sr. Member
Offline
Posts: 294
Re: Noob Question
«
Reply #1 on:
December 30, 2010, 08:21:55 AM »
What industry are you looking to get into? The DoD recognizes a few certifications as meeting training requirements. CEH, CISSP, and CompTIA Security + are just a few. This is not an all inclusive list but it may help. However, any Ethical Hacking cert will help you gain more knowledge. The Offsec cert is a great cert and is very hands on. It is not for some one new to Linux or ethical hacking. Before going straight to the hacking certs, look at the Security+ and the Network+ certs. Then build from there.
Logged
Mike Conway
CISSP
CompTia Security +
C|EH
TechMonK3y
Newbie
Offline
Posts: 2
Re: Noob Question
«
Reply #2 on:
December 30, 2010, 10:21:12 AM »
I am just looking to expand my areas I have a degree in networking and currently work in that field just trying to get some ideas on what next i heard that the OffSec was tough i do have some knowledge of linux not as much as i would like to
Logged
rabray
Newbie
Offline
Posts: 38
Re: Noob Question
«
Reply #3 on:
January 15, 2011, 07:58:56 AM »
Install linux on a laptop or your home system and get started.
I would also recommend reading the CEH materials as a good place to start, you do get a broad understanding of various issues around security.
eCPPT is also good in terms of making you focus on web application testing and the security issues surrounding this area, which realy should become more of a challenge and focused role as more people move into the "cloud".
Logged
---------------------------------------
CEH, eCPPT, MCT, MCSA, MCDST, A+, Net+
Never been the flamin type.
Pookie
Newbie
Offline
Posts: 47
Re: Noob Question
«
Reply #4 on:
January 25, 2011, 10:46:07 AM »
Quote from: rabray on January 15, 2011, 07:58:56 AM
Install linux on a laptop or your home system and get started.
I have been using Ubuntu/Mint Linux as my primary OS(es) for almost 2 years but don't feel like I truly know Linux since most of what I use is accessed through the graphical interface. What commands and skills would you suggest I look into? I was thinking of getting some books for the Comptia Linux+ cert, since that gets 3 certs for the price of one. do you think that would help me learn best?
Logged
Certifications: A+, Network+, Security+
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Noob Question
«
Reply #5 on:
January 25, 2011, 10:56:54 AM »
Pookie,
in my experience trying to 'learn' Linux never works, as I can't retain anything I learn for when I actually need to use the knowledge in real life. Only way I can improve my Linux skills is to actually use it.
If you're mostly using the GUI, don't (I know, sorry) try running on a system without a GUI (all my servers are CLI only), for example take advantage of one of the many free/cheap virtual service hosts and use that to setup something that you're interested in. Or if you don't have a project in mind, setup a LAMP system to run a wiki/blog for you to record the skills/knowledge you're learning whilst doing it.
The knowledge comes with time, in my case I was working on a system (throwing commands at it, seeing what it does) and had an out of body experience, "when did I learn to do that?". It's easier to learn when you don't know you're learning.
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
ziggy_567
Sr. Member
Offline
Posts: 361
Re: Noob Question
«
Reply #6 on:
January 25, 2011, 11:06:00 AM »
I'm not that familiar with the Linux+ certification, but I can tell you that Linux is really pretty easy to learn once you get your hands dirty a bit. My advice would be to stop relying on the GUI for day-to-day maintenance of your destkop. If you need to update some software, don't use the graphical aptitude repositories, see what you can do on the command line. It may take longer, but you'll get more comfortable with the command line over time, and eventually it becomes faster to use the command line for a lot of things.
Another thing you can do, turn off automatic log rotation and write your own script to do this. This is on a junior sysadmin level of task, so its definitely doable. In fact, google will likely spoonfeed you pretty much whatever you need. But, this is a great exercise to teach yourself shell scripting. You will be amazed at how quickly you'll be able to string a bunch of commands together to accomplish a single task once you become somewhat proficient at shell scripting, because that's basically all you're doing with a shell script.
Another idea to learn command line. Build a VM without installing Gnome or KDE. Then set up an LAMP server on it. You don't have to actually do anything in depth with html/mysql/php. Just get a very rudimentary website setup. You'll learn a lot about the command line doing this.
Feel free to PM me if you need anything.
Logged
--
Ziggy
eCPPT - GSEC - GCIH - GCUX - RHCE - SCSecA - Security+ - Network+
DrivinTin
Jr. Member
Offline
Posts: 51
Net+, Sec+, C|EH, ECSA, CISSP, CASP
Re: Noob Question
«
Reply #7 on:
January 25, 2011, 01:36:16 PM »
In my opinion if you are going to really learn linux you don't go with Ubuntu or some other drop in install. Go grab the min install cd of Gentoo and work your way through the install guide. Not only will it help you setup a base system, but Gentoo has an amazing amount of HOWTOs and a great community for trouble shooting issues.
Logged
Currently working on:
A UAV Project
Speaking and conferences
Pookie
Newbie
Offline
Posts: 47
Re: Noob Question
«
Reply #8 on:
January 25, 2011, 02:38:38 PM »
I am getting a new computer (to me anyway) soon so I will have an opportunity to do these things, since my old computer is an ancient beast and can barely handle one OS, much less virtual machines.
Thanks to those who have replied to my Linux questions and I hope more people add their opinions and advice.
Logged
Certifications: A+, Network+, Security+
hell_razor
Jr. Member
Offline
Posts: 90
Re: Noob Question
«
Reply #9 on:
January 25, 2011, 03:31:09 PM »
Quote from: DrivinTin on January 25, 2011, 01:36:16 PM
In my opinion if you are going to really learn linux you don't go with Ubuntu or some other drop in install. Go grab the min install cd of Gentoo and work your way through the install guide. Not only will it help you setup a base system, but Gentoo has an amazing amount of HOWTOs and a great community for trouble shooting issues.
Ever heard of learning to crawl before you walk? Throwing a new user in a minimal install in Gentoo may not be the best way to get a long term user. I would say that installing any current mainstream enthusiast distro (ubuntu,fc,suse,etc) would be sufficient. It will allow the user to have ease of use and still allow the user to compile code, update the kernel, etc. at their own pace.
This is kind of like learning to ride a motorcycle for the first time on a modern sportbike...it can be done, but may also result in a quick death.
Logged
A+, Network+, Server+, CISSP, GSEC, GCIH, GPEN, GCIA, GISP, GCFW
DrivinTin
Jr. Member
Offline
Posts: 51
Net+, Sec+, C|EH, ECSA, CISSP, CASP
Re: Noob Question
«
Reply #10 on:
January 27, 2011, 09:59:36 AM »
Quote from: hell_razor on January 25, 2011, 03:31:09 PM
Ever heard of learning to crawl before you walk? Throwing a new user in a minimal install in Gentoo may not be the best way to get a long term user. I would say that installing any current mainstream enthusiast distro (ubuntu,fc,suse,etc) would be sufficient. It will allow the user to have ease of use and still allow the user to compile code, update the kernel, etc. at their own pace.
This is kind of like learning to ride a motorcycle for the first time on a modern sportbike...it can be done, but may also result in a quick death.
I agree if the user is a new linux user, but the reply was more at Pookie. He said he had been using Ubuntu for over 2 years, but feels like he still doesn't know linux that well because of the GUI. Walking through the Gentoo install guide is not daunting at all, it walks you through the entire process telling you every command to type. If you find that overwhelming then I think the Linux+ might not be for you.
Logged
Currently working on:
A UAV Project
Speaking and conferences
hell_razor
Jr. Member
Offline
Posts: 90
Re: Noob Question
«
Reply #11 on:
January 27, 2011, 12:56:12 PM »
Just because Ubuntu/Mint have GUIs doesn't mean he should jump ship on the distro and move to something else. He can learn everything he needs to in Ubuntu/Mint, he just needs to take the time to do so. I am not trying to start a distro war or anything like that, at the root they are all about the same. However, if I was looking to learn more about linux from nearly any front (support, pen testing, etc) I would look to redhat, centos, and debian based distros because that is what you will see more of in the wild. If I were to branch someone out, I would send them to BSD world rather than some other linux distro. Did not mean to start a fight or anything.
Logged
A+, Network+, Server+, CISSP, GSEC, GCIH, GPEN, GCIA, GISP, GCFW
ziggy_567
Sr. Member
Offline
Posts: 361
Re: Noob Question
«
Reply #12 on:
January 27, 2011, 01:08:52 PM »
<sarcasm>
Awwww....come on....DamnSmallLinux is where its at for building Desktops!
</sarcasm>
Linux is Linux...If you learn one, you can easily learn another...
Logged
--
Ziggy
eCPPT - GSEC - GCIH - GCUX - RHCE - SCSecA - Security+ - Network+
DrivinTin
Jr. Member
Offline
Posts: 51
Net+, Sec+, C|EH, ECSA, CISSP, CASP
Re: Noob Question
«
Reply #13 on:
January 27, 2011, 03:24:14 PM »
Haha, you are not a real man until you build your own Linux from Scratch!
hell_razor: I completely agree about being familiar with Redhat/CentOS/Debian, that is pretty much all you will find, and knowing the ends and outs is going to help you the most.
Now can someone find a great pic that shows a distro war?
Logged
Currently working on:
A UAV Project
Speaking and conferences
Pookie
Newbie
Offline
Posts: 47
Re: Noob Question
«
Reply #14 on:
January 27, 2011, 04:51:53 PM »
oops, I started a distro fight... Sorry
I really do appreciate the input, I will likely set up a virtual machine on my new lappy with some minimal install (the Gentoo solution sounds interesting, and I have another target vm to practice on when I am done). I also found some stuff at
http://training.linuxfoundation.org/
to look into.
I have been branching over to the terminal for stuff (changing permissions, wget, iwconfig, and I think mtr is awesomely neat) vi keeps throwing me off though but practice brings familiarity.
Logged
Certifications: A+, Network+, Security+
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: "Free Monthly Giveaways" - Details
(21) by
BeecyGorror
News Items and General Discussion About EH-Net
: Burberry UK,2013 Burberry Safety-valve Online Available in London
(10) by
BeecyGorror
ChicagoCon 2007
: s going to be critical to have universal identity in order for these systems to talk ...
(0) by
Loyatoitada
Special Events
: [Article]-Video: Deep Dive into Red Teaming with the Metasploit Framework
(3) by
BeecyGorror
Calendar Of Events
: ChicagoCon 2008f
(2) by
BeecyGorror
Malware
: New zero-day exploit for Internet Explorer 7, 8, and 9 on Windows XP, Vista & 7
(13) by
BeecyGorror
Special Events
: [Article]-Webcast: Deep Dive into Red Teaming with the Metasploit Framework
(19) by
BeecyGorror
News Items and General Discussion About EH-Net
: but it needs more help: they Sac Louis Vuitton
(0) by
Loyatoitada
Special Events
: [Article]-Survey of Hacking Movies: Framing the Debate on the Gateway Drug into the H...
(12) by
BeecyGorror
Greetings
: but the desperate effort that comes from being hopeful Nike Blazers Uk
(0) by
Loyatoitada
ChicagoCon 2007
: waterfall Cheap Air Max Sale
(0) by
Loyatoitada
News Items and General Discussion About EH-Net
: The advent of the web happened slowly Nike Blazer Uk
(0) by
Loyatoitada
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.