Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 40 guests and 3 members online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow General Certificationarrow What do you think of SANS Penetration Testing and Ethical Hacking training
EH-Net
May 24, 2013, 08:27:07 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: What do you think of SANS Penetration Testing and Ethical Hacking training  (Read 9281 times)
0 Members and 1 Guest are viewing this topic.
janugu
Newbie
*
Offline Offline

Posts: 3


View Profile
« on: February 02, 2011, 08:06:54 AM »

Hi there,

I have been working as a QA tester (from development background) and am thinking to change my carrier path to Penetration Testing. I was wondering how you think of SANS training. Is it really practical as they claim on their website? Will I able to get a job as a pen tester after?

I am also interested in wireless security as well? I believe SANS offers "Web" and "Wireless" pen testing training.

Any advice and feedback will be welcome.

Thank you very much for your help in advance!
Logged
MaXe
Hero Member
*****
Offline Offline

Posts: 669


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« Reply #1 on: February 02, 2011, 08:46:43 AM »

I would rather do WiFu+OSWP from Offensive Security, cheaper but the quality to content ratio is also most likely higher, and a lot more technical, so be prepared to get into the details Cheesy

The Web Application Security courses from SANS are okay, from what I heard (from people who did them) and read (on their website and blogs). But the things you learn are basic, and won't get you that near a real hacker within "WebAppSec". Unfortunately, I don't know any courses within this category I can recommend yet, but check out a few of my blog entries if you're going into this category within WebAppSec, you might enjoy them if you don't already know them  Wink

Link: http://www.exploit-db.com/category/maxe/

Anyway, if you want to do Penetration Testing you should be prepared to learn a lot, and also enjoy it with passion even in your time off work if you want to be really good  Grin But that is of course just my opinion and I'm glad to hear another person is getting hopefully into serious pentesting as well.
Logged

I'm an InterN0T'er
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #2 on: February 02, 2011, 11:01:25 AM »

The SANS certs will help with HR filters. To an extent. But that's kind of the point of all certs and degrees. To show you can put up with BS / while investing in your own education. They make you look better, while saying you can jump through hoops instead of plowing through them.
Logged

OSWP, Sec+
janugu
Newbie
*
Offline Offline

Posts: 3


View Profile
« Reply #3 on: February 02, 2011, 11:49:24 AM »

Thanks very much for your advice!

I checked out WiFu+OSWP and it does seem interesting and much cheaper than other training.

I have some concerns about the prerequisites though... Because I only have basic knowledge of TCP/IP, Networking and Linux since I was a .net devleoper. Do you think I will be okay with my experience to take these courses?

I would rather do WiFu+OSWP from Offensive Security, cheaper but the quality to content ratio is also most likely higher, and a lot more technical, so be prepared to get into the details Cheesy

The Web Application Security courses from SANS are okay, from what I heard (from people who did them) and read (on their website and blogs). But the things you learn are basic, and won't get you that near a real hacker within "WebAppSec". Unfortunately, I don't know any courses within this category I can recommend yet, but check out a few of my blog entries if you're going into this category within WebAppSec, you might enjoy them if you don't already know them  Wink

Link: http://www.exploit-db.com/category/maxe/

Anyway, if you want to do Penetration Testing you should be prepared to learn a lot, and also enjoy it with passion even in your time off work if you want to be really good  Grin But that is of course just my opinion and I'm glad to hear another person is getting hopefully into serious pentesting as well.
Logged
xXxKrisxXx
Hero Member
*****
Offline Offline

Posts: 512



View Profile
« Reply #4 on: February 02, 2011, 12:22:26 PM »

Quote
Do you think I will be okay with my experience to take these courses?

I think you will be a perfect fit into the WiFu+OSWP course. I hear they actually teach you the basics and take you from there on out with attacking wifi access points. I'm sure you qualify for the pre-reqs by just having a general understanding of what you mentioned you know. Their syllabus can be found below entailing other pre-requisites one should have before entering:

http://www.offensive-security.com/documentation/wifu-syllabus.pdf

Quote
I believe SANS offers "Web" and "Wireless" pen testing training.

Since your just wanting to get your feet in the door, I'm sure you could go the SANS route, but if your looking for a cheaper price and more at a beginner friendly level, LearnSecurityOnline has a cheap course with no certification offer entitled, "So You Want To Be A WebApp Pentester". eLearnSecurity may also be another great resource for you to check out - they're affordable, beginner friendly, have a solid web application security module built, and you would get introduced into other topics too like network and system security. Just wanted to let you know you do have other options; but if you do have the cash SANS certs are indeed respected.
Logged

eCPPT, GCIH, OSCP, OSWP
Dark_Knight
Sr. Member
****
Offline Offline

Posts: 292


View Profile WWW
« Reply #5 on: February 02, 2011, 02:24:39 PM »

Hi there,

I have been working as a QA tester (from development background) and am thinking to change my carrier path to Penetration Testing. I was wondering how you think of SANS training. Is it really practical as they claim on their website? Will I able to get a job as a pen tester after?

I am also interested in wireless security as well? I believe SANS offers "Web" and "Wireless" pen testing training.

Any advice and feedback will be welcome.

Thank you very much for your help in advance!

Sans training is very good. You won't turn into a 133t hacker when your done. But the material is very good and offers up a good foundation on which to further develop your skills.

I have done both the GPEN(Network Pentesting) and the GWAPT(Web Application Pen Testing). Both were very good.

I have also done the OSCP which is the equivalent to the SANS GPEN. The OSCP is like no other in it's class. As I have said repeatedly on this site the GPEN is good compliment to the OSCP.

Logged

CEH, OSCP, GPEN, GWAPT, GCIA
http://sector876.blogspot.com
alucian
Full Member
***
Offline Offline

Posts: 225



View Profile
« Reply #6 on: February 02, 2011, 02:47:33 PM »

For the moment I would say that OSWP is outdated, look for the topics here and you'll convince yourself. I am waiting for the version 2 (if it will be one).
Logged

CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
hayabusa
Hero Member
*****
Offline Offline

Posts: 1633



View Profile
« Reply #7 on: February 03, 2011, 08:13:57 AM »

Welcome, ptamashahq

Out of respect, please refrain from posting the same comment to multiple pages.  One would've sufficed.

Anyway, I hope you find value here, and again, welcome.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
rabray
Newbie
*
Offline Offline

Posts: 38


View Profile
« Reply #8 on: February 05, 2011, 03:40:59 AM »

With regards to the cheaper option at Elearn security. I am on that course at the moment. The web application assessment is very hands on. The courseware presents you with a number of concepts on the tools and techniques aswell as a number of training videos to get you off and running, with a focus on delivering a report like you would be expected to do as part of the job. The course also forces you to think for yourself, which in my opinion is a good thing.

The forums provide the main mechanism for support and do contain other useful information and a chance to submit questions, where either other students will assist or refer you to other external materials or you will get an answer from armando the trainer.

At the moment there is no official material for WiFi, but I've asked questions about this area in the forums and still recieved useful info even though its not part of the curriculum yet.

Hope this is useful.
Logged

---------------------------------------
CEH, eCPPT, MCT, MCSA, MCDST, A+, Net+

Never been the flamin type.
janugu
Newbie
*
Offline Offline

Posts: 3


View Profile
« Reply #9 on: February 05, 2011, 08:22:25 AM »

Sans training is very good. You won't turn into a 133t hacker when your done. But the material is very good and offers up a good foundation on which to further develop your skills.

I have done both the GPEN(Network Pentesting) and the GWAPT(Web Application Pen Testing). Both were very good.

I have also done the OSCP which is the equivalent to the SANS GPEN. The OSCP is like no other in it's class. As I have said repeatedly on this site the GPEN is good compliment to the OSCP.



First of all, thanks so much for all the valuable comments!!!

I am leaning toward SANS... But, I can't decide which one between "GPEN(Network Pentesting)" and "GWAPT(Web Application Pen Testing)". GPEN seems more intensive than GWAPT and I am not sure if my development/testing background would be enough to take that course. On the other hand, I should consider taking GWAPT in order to extend my knowledge/experience from web/windows applications.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.084 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.