Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 28 guests online
You are here:
Home
Resources
Tutorials
Where to start?
EH-Net
May 23, 2013, 06:47:13 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Resources
>
Tutorials
(Moderator:
don
) >
Where to start?
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: Where to start? (Read 19158 times)
0 Members and 1 Guest are viewing this topic.
uz3r
Newbie
Offline
Posts: 10
Where to start?
«
on:
February 25, 2011, 02:31:44 AM »
I have been a computer user most of my life and know my way around windows and ubuntu. I know my way around desktop pc hardware but have no hacking or programming experience. I just started school and am planning on taking CIS classes in hopes of later becoming a network security admin and penetration tester as well as a comp hardware technician. Recently my financial aid was dropped because I didn't renew my fafsa and now I have 5 months of nothing to do as I am an unemployed felon (lol)
Now I've discovered several different courses of action in the last week as I have decided to go the way of working towards dynamic studies towards certification. I am considering CompTIA A+ because I've heard its a good place to start for someone with no experience in the field. However, I've also checked out Career Academy (which teaches CompTIA course) as well as elearn security and Hacking DOJO. I heard that CEH certification is not as thorough and deep rooted and is more the understanding of how to use specific tools. I want a full and thorough understanding for when the government takes over the internet XD
So my questions:
Where is the best place to start for a beginner like myself?
If CompTIA A+ is the best route, would I go with the CompTIA site's A+ courses or Career Academy's A+ courses?
I have a good number of reading material on the subject but as I have nothing to do for the next 5 months, I wouldn't mind spending my money where I have actual instructors and labs for which to get support and experiment with. Any other suggestions would be very appreciated. Thanks!
Logged
chrisj
Hero Member
Offline
Posts: 1163
Re: Where to start?
«
Reply #1 on:
February 25, 2011, 09:27:29 AM »
Welcome to the forum.
This is actually a pretty common question on the forum, so common infact that there are pinned topics in the Pentester section. You'll probably find the answer to your questions there.
As for labs. Some classes will let you use there lab for a fixed amount of time, or you could build your own. Building your own lab will give you some extra skills, like running VMWare, and system installation of different kinds.
You'll want programming skills too. They make some good network simulators that will work for what you want to do, or you could hit up ebay and buy used equipment.
Logged
OSWP, Sec+
uz3r
Newbie
Offline
Posts: 10
Re: Where to start?
«
Reply #2 on:
February 25, 2011, 06:28:36 PM »
I actually have VMware on my windows 7 boot. I'm running a windows/ubuntu x64 dual. I have been looking at CompTIA.org with their elearning bundles but I've also seen careeracademy and learnkey are viable options. Any suggestions or preferences? I'll likely be teaching myself python as I go seeing as how I have pretty much limitless time on my hands.
Logged
UNIX
Hero Member
Offline
Posts: 1235
Re: Where to start?
«
Reply #3 on:
March 02, 2011, 08:43:23 AM »
If you can afford it, take a look at courses offered by
InfoSec Institute
. Their basic Ethical Hacking course goes through some of the most important basics and offers enough hands-on practice to get your hands dirty. If you can't take the live course, you could opt for the online version, which is a recorded version of a live training. The course also prepares for both CEH and CPT.
Logged
uz3r
Newbie
Offline
Posts: 10
Re: Where to start?
«
Reply #4 on:
March 02, 2011, 12:09:18 PM »
I already checked out InfoSec and they are way too expensive. I'm taking TestOut's 7-day free trial and I got the CBT Nuggets 2009 A+ videos. Do you think TestOut + CBT Nugs will be sufficient? I'm teaching myself out of my house, just taking mad notes and reviewing everything. I have a good knowledge of hardware and software installation and operating systems.
Logged
chrisj
Hero Member
Offline
Posts: 1163
Re: Where to start?
«
Reply #5 on:
March 04, 2011, 09:00:26 AM »
To add to my recommendation above, get a copy of Dissecting the Hack: The F0rb1dd3n Network by Jayson Street, Brian Baskin, and Kent Nabors.
I got a copy the other week and have been reading it. It's pretty good, broken up in to a story section that gives you an idea of the tools are used, and the STARS (Security Threats Are Real) section that goes a little more indepth on the tools and tricks used in the story.
The book won't make you a hacker overnight, but it will give you some ideas of things to look at and play with.
Logged
OSWP, Sec+
WCNA
Full Member
Offline
Posts: 187
Re: Where to start?
«
Reply #6 on:
March 04, 2011, 09:52:16 AM »
Don't forget about metasploitable. If you don't have a lab, it'll definitely help beginners.
Logged
ISC2 Associate, WCNA, CWNA, OSCP, Network+
lorddicranius
Sr. Member
Offline
Posts: 447
Re: Where to start?
«
Reply #7 on:
March 04, 2011, 02:05:27 PM »
Quote from: WCNA on March 04, 2011, 09:52:16 AM
Don't forget about metasploitable. If you don't have a lab, it'll definitely help beginners.
Thanks for the metasploitable recommendation, that looks like a great tool to use to learn metasploit (which is currently on my list of things to do
).
Logged
GSEC, eCPPT, Sec+
WCNA
Full Member
Offline
Posts: 187
Re: Where to start?
«
Reply #8 on:
March 05, 2011, 07:37:02 PM »
Y
our welcome. I don't know why someone hasn't already done this but I think it might be a very good opportunity for someone to open a site that would let security students vpn into a lab with a whole bunch of vulnerable machines. Sorta like what muts does with the OSCP course. You could have deepfreeze on the machines and they would reboot every hour, wiping out all the pwnage. You could even have contests to see how many machines you can compromise before the hour is up.
Logged
ISC2 Associate, WCNA, CWNA, OSCP, Network+
jason
Hero Member
Offline
Posts: 1012
Re: Where to start?
«
Reply #9 on:
March 07, 2011, 06:26:28 PM »
Stay tuned. Something very much like what you describe is in the works, and we hope to have exactly such an environment available in the near future. When we have the beta environment nailed down, we'll be pinging the EH netters to test it out, so get your l337 h4X0r Sk1ll2 warmed up.
Logged
AndyB
Full Member
Offline
Posts: 100
Re: Where to start?
«
Reply #10 on:
March 10, 2011, 01:41:54 AM »
Quote from: WCNA on March 05, 2011, 07:37:02 PM
Y
our welcome. I don't know why someone hasn't already done this but I think it might be a very good opportunity for someone to open a site that would let security students vpn into a lab with a whole bunch of vulnerable machines. Sorta like what muts does with the OSCP course. You could have deepfreeze on the machines and they would reboot every hour, wiping out all the pwnage. You could even have contests to see how many machines you can compromise before the hour is up.
Check out
http://www.hacking-lab.com/events/swiss-cyber-storm-3-cargame-challenge.html
. They have competitions running for hacking their systems. Currently not doing it to win the car, just gain experience!
Logged
Net+ Sec+ More to come
lorddicranius
Sr. Member
Offline
Posts: 447
Re: Where to start?
«
Reply #11 on:
April 02, 2011, 09:39:45 PM »
So I've finally gotten around to setting up some VM's (using VMWare Player), went to download Metasploitable and I can't seem to find a link that works. Initially started
here
and found that the "torrent" link doesn't work anymore. I tried a few searches around metasploit.com with no luck either. Anybody know of a good link to download from?
Logged
GSEC, eCPPT, Sec+
millwalll
Guest
Re: Where to start?
«
Reply #12 on:
April 03, 2011, 10:39:44 AM »
There is a a link here
http://www.metasploit.com/learn-more/how-do-i-use-it/test-lab.jsp
This show how to setup a lab
http://www.securityaegis.com/pentest-lab-web-application-edition/
If you need any help let me know as I was at same stage you are around 6 months ago send me a PM
Logged
lorddicranius
Sr. Member
Offline
Posts: 447
Re: Where to start?
«
Reply #13 on:
April 03, 2011, 04:14:48 PM »
Awesome, thanks Jamie
Logged
GSEC, eCPPT, Sec+
uz3r
Newbie
Offline
Posts: 10
Re: Where to start?
«
Reply #14 on:
April 09, 2011, 03:20:27 PM »
So I think I'll check out the books you all suggested and the metasploit thing. I consider myself pretty apt with computers. Though I have no real programming knowledge, I figure I'll be starting with A+ which is more in my familiarity zone. I can upgrading and install hardware/software on windows no problem and have basic understanding of networking and troubleshooting so I think I'll just hit the books instead of fork out the cash for a fast track certification.
Logged
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(5) by
MrTuxracer
Greetings
: Hi from the UK
(4) by
MrTuxracer
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(0) by
prats84
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(27) by
don
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.