Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 29 guests and 2 members online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
Why employ a graduate?
EH-Net
May 22, 2013, 11:47:47 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
Why employ a graduate?
Pages:
1
[
2
]
Go Down
« previous
next »
Print
Author
Topic: Why employ a graduate? (Read 11003 times)
0 Members and 1 Guest are viewing this topic.
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: Why employ a graduate?
«
Reply #15 on:
February 22, 2011, 07:12:56 AM »
Thanks Sil, I always appreciate your comments and I do take the time to read your posts.
It's hard to be told "try harder", but it is even harder to realize they are right saying it. My mindset is so different now than it was before my OSCP attemps. I learned way more front failed exams than from anything else so far.
Quote
There is more to experience than working a nine-to-five.
I have to say you, more than everyone else, showed me this is true. After OSCE and a few other things, I will pursuit this route. Thanks Sil. I find that you and MaXe (amonst others!) are very knowledgeable and always ready to help the others. I try to help others too, but you guys know a lot.
I love studying in this field!
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
mallaigh
Jr. Member
Offline
Posts: 65
Re: Why employ a graduate?
«
Reply #16 on:
February 22, 2011, 05:17:26 PM »
skitch, in your post you are talking about a Junior Pentest role, but have you considered also looking internships? An internship, still counts as experience, and could serve as some decent experience for you. Maybe this anecdote will help clairify: at my current employer, I have seen 3 interns get promoted into full-time positions in the last year. These persons came into the company as recently graduated interns, proved they know a thing or two, and in return were offered permanent positions (not pentesters, but other tech roles). Now, lets get one thing straigt, I'm
NOT
saying intership=job, but I am saying, it could help you get a foot in the door
which could
result in a job.
Me personally, I have been working as the corporate IT / help desk person at said company for about a year. I manage the VOIP, user workstations, windows servers, and parts of the corp network. For the most part, I can do my job in my sleep. But, I'm working on building my skills and knowledge in my off-time (no one said I can't read an article or two while watching progress bars right)
. A couple of the admins will ask me questions, for example: the other day one of the guys was asking me if they should be using RSA or DSA for SSH signing.
Point of this, if you read the link from sil, he talks about his back ground and how he got into security. From the sounds of it, sil didn't start out as the security guru he is. H1t M0nk3y has recently started to transition into security (from being a developer if memory serves (see H1t, I read your posts)). So, it won't hurt trying to get a pentesting gig, but it might also be a good idea to look for something else (developer, sys admin, etc). What is the worst thing that could happen when applying for a job? But, it isn't a bad idea to have a "plan B".
«
Last Edit: February 22, 2011, 05:24:15 PM by mallaigh
»
Logged
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: Why employ a graduate?
«
Reply #17 on:
February 22, 2011, 06:01:38 PM »
Thanks mallaigh for reading my posts, I feel better now!
(I know the others read them too).
In IT Security like in everything else in life, we have to be humble, patient and stay focus to our goal.
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
sil
Hero Member
Offline
Posts: 549
Re: Why employ a graduate?
«
Reply #18 on:
February 22, 2011, 08:27:48 PM »
Quote from: mallaigh on February 22, 2011, 05:17:26 PM
sil, he talks about his back ground and how he got into security. From the sounds of it, sil didn't start out as the security guru he is. H1t M0nk3y has recently started to transition into security (from being a developer if memory serves (see H1t, I read your posts)). So, it won't hurt trying to get a pentesting gig, but it might also be a good idea to look for something else (developer, sys admin, etc). What is the worst thing that could happen when applying for a job? But, it isn't a bad idea to have a "plan B".
Nope, when I first landed my "security position" it was still non-existent, I kind of made it exist. I was a heavy systems/network admin engineer. I had worked on AIX, AS/400, Irix, FreeBSD and Linux servers. Security was an afterthought. Hell I remember when SATAN came out because I remember Dan Farmer was at SGI and I think he left either because of it or SGI fired him or something like that. Back then one was a systems admin and security really fell under that umbrella. Heck I remember re-writing Titan for FreeBSD on my own before TrustedBSD was a thought. I've seen alot, seeing even more fun stuff now with my VoIP Abuse Project... For H1tM0nk3y, I would say he'd likely excel at any web based pentesting or even the CSSLP because it's likely in his every day routine right now.
So this brings us all back to you now skitch, you started a post and have yet to respond back to anyone
Which either means that you're overwhelmed and your head is spinning, you're confused, or still uncertain... What is it you *truly* want to do... I say this from the following perspective now... Do you want to make a career pentester for the sake of loving what you do? If so, you're the one who makes an experience at the end of day, not a job... Or is it you just want to find a job as a pentester... A "job" becomes boring... Anyone can be taught to push buttons... A career is fulfilling, exciting and never dull
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
skitch
Newbie
Offline
Posts: 5
Re: Why employ a graduate?
«
Reply #19 on:
March 27, 2011, 01:18:42 PM »
Wow a month already! Sorry for the delay, its a busy time for graduating students at the mo.. No disrespect intended.
Quote
So this brings us all back to you now skitch, you started a post and have yet to respond back to anyone Which either means that you're overwhelmed and your head is spinning, you're confused, or still uncertain... What is it you *truly* want to do... I say this from the following perspective now... Do you want to make a career pentester for the sake of loving what you do? If so, you're the one who makes an experience at the end of day, not a job... Or is it you just want to find a job as a pentester... A "job" becomes boring... Anyone can be taught to push buttons... A career is fulfilling, exciting and never dull
Tbh its a bit of both, however ultimately this thread has provided strong indications that I still have much to learn. It discomforts me to say that because I always thought I was ahead of my competition, but realistically my theoretical knowledge is not up to par. I think from here my plan is to continue applying to junior positions, however if unsuccessful pursue a masters degree in Information security, more specifically one with built in certs.
As for the latter, infosec has dug its claws in for almost 10 years, it is certainly a passion which I have invested a lot of time into. While I love my current degree (digital forensics) I've been lucky enough to meet some of the biggest names in the field. Their stories however have lead me to question if could I withstand the psychological trauma of the content involved. While the private sector is an option, my heart has always been with pen testing.. Even to the point that I took my current degree in pursuit of a career in this field.
A big thanks to you guys for levelling my perceptions.
Logged
Pages:
1
[
2
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.