Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 51 guests and 3 members online
 
Advertisement

You are here: Home arrow Resourcesarrow Career Centralarrow Online penetration testing course advice
EH-Net
May 25, 2013, 04:43:56 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Online penetration testing course advice  (Read 8720 times)
0 Members and 1 Guest are viewing this topic.
lblake
Newbie
*
Offline Offline

Posts: 2


View Profile
« on: April 25, 2011, 04:21:44 AM »

Hello there,


I've been a QA tester for the past 12 years I have good knowledge of operating systems including Linux (command-line level) and can configure systems from scratch.  I can programme in Java, Python and Perl to an immediate level (used 'C' back in the day) and intend to learn some assembly at some point.  I am looking to change my career from QA to penetration tester again.


I've have no experience of penetration testing but I am CEH qualified, I qualified six years ago but found that the qualification didn't open any doors (the catch-22 situation).


Which course from the list below do you advise I take as I don't really want to spend a lot of money only to find the certifcation has no merit without experience (again).


1: Hacking dojo

2: eLearnSecurity

3: SANs.org

4: OSCP training with backtrack


I've looked at the demo from eLearnSecurity and it doesn't seem to be very hands-on?  The OSCP and Hacking dojo courses look to be more hands on?  But I am bit concerned about the time factor with the OSCP course (I would go for the 90 day option).
Logged
xXxKrisxXx
Hero Member
*****
Offline Offline

Posts: 512



View Profile
« Reply #1 on: April 25, 2011, 03:11:22 PM »

hey lblake,

welcome to the forums!

You seem to be leading more towards the OSCP course than the others you listed off. I think it's a big plus you've had years with programming and linux.

Quote
I've have no experience of penetration testing but I am CEH qualified, I qualified six years ago

If you were really aiming for PWB, I'd suggest taking the time to familiarize with some penetration testing. Maybe build a home lab to practice in. I think if you walk in having little familiarity with some of the tools in BackTrack your lab days get spent learning the syntax usages as oppose to getting your hack on. 90 day option is great, you'd learn a ton but it's best to get comfortable with what your going to be using in the course before signing up for it - especially for the OSCP course!

Quote
I've looked at the demo from eLearnSecurity and it doesn't seem to be very hands-on?

eLearnSecurity is as hands-on as you make it. I took the pro courses which came with tons of interactive slides, labs attached to the slides for you to do at your own pace, and video demos. To get the most out of the course, I'd suggest going through and completing all of the labs. Plus they're only working on making their courses better. Check the link below to see what the folks at eLS are working on getting into the course (if they haven't added it in already):
http://www.ethicalhacker.net/component/option,com_smf/Itemid,54/topic,6872.0/

Some more positives about eLearnSecurity, EthicalHacker members get a 5% discount here. Your also given 120 days to go through the course which is great and gives you a lot of time to get things done.

Can't really speak for Hacking Dojo or SANS except all of the training vendors you listed off are great. SANS certifications are well respected in the industry but they're quite pricey!

Quote
I don't really want to spend a lot of money only to find the certifcation has no merit without experience (again).

This is a field where you need the experience and the certifications/education to get hired. I'm OSCP and eCPPT certified but I'm far from being ready to pen-test in an enterprise environment.

In my opinion, I'd say go the eLearnSecurity or HackingDojo route. These will give you a solid foundation then maybe you could venture off into PWB even more prepared.
« Last Edit: April 25, 2011, 03:14:10 PM by xXxKrisxXx » Logged

eCPPT, GCIH, OSCP, OSWP
lblake
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #2 on: April 25, 2011, 05:17:33 PM »

Hello xXxKrisxXx,

Thanks for the information I've started to set up my own lab using the vmware images from the 'Metasploit' website.  I'll take another look at the eLearning course as I feel the OSCP course might be a bit much at this present time.
Logged
millwalll
Guest
« Reply #3 on: April 27, 2011, 06:49:21 AM »

I am doing the Hackindojo course and I love it the only fault I would say with the course is that its part time so my lesson are once a week every Tuesday.

This of course does not stop you learning off your own back.
Logged
MaXe
Hero Member
*****
Offline Offline

Posts: 669


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« Reply #4 on: April 27, 2011, 12:27:51 PM »

Pentesting with BackTrack would be ideal if you have some basic Linux skills and perhaps knowledge about different exploitation vectors etc. since this course really does have a high content to price value in my humble opinion  Smiley

Also it would be an opportunity to gain the OSCP certification which is not that widely known to HR departments yet, but some within e.g. HP are beginning to acknowledge it.
Logged

I'm an InterN0T'er
tturner
Sr. Member
****
Offline Offline

Posts: 432


View Profile WWW
« Reply #5 on: April 27, 2011, 02:29:35 PM »

Searches at Dice return the following:

OSCP - 4 hits http://goo.gl/dWs0J

OSCE - 6 hits http://goo.gl/O5Kll

eCPPT - 0 job (got hits but none actually referenced the cert)

GPEN - 9 hits http://goo.gl/bY2xr

CEH - 89 hits http://goo.gl/uw4KO

CISSP - 1387 hits http://goo.gl/1R3dc

So if you aren't having much luck with CEH, you probably won't have a lot more luck with the other hacking-centric certs from an HR standpoint, but I'd daresay you will probably gain some credibility with technical security folks in the know. Bottom line, I would not advise investing in any cert other than the CISSP if your objective is bypassing an HR filter. Not much value for a pentester true, but that's just how it is. Now going the OSCP/OSCE route to actually learn something useful? That sounds like a much more worthwhile endeavor.
« Last Edit: April 27, 2011, 02:31:46 PM by tturner » Logged

Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP

WIP: OSWP, GSSP-JAVA, GXPN

Udacity on hold, again. I suck.

http://sentinel24.com/blog  @tonylturner http://bsidesorlando.org
millwalll
Guest
« Reply #6 on: April 27, 2011, 02:42:24 PM »

Pentesting with BackTrack would be ideal if you have some basic Linux skills and perhaps knowledge about different exploitation vectors etc. since this course really does have a high content to price value in my humble opinion  Smiley

Also it would be an opportunity to gain the OSCP certification which is not that widely known to HR departments yet, but some within e.g. HP are beginning to acknowledge it.

You say knowledge of different exploitations vectors if you don't have this how can you gain it ? as I planing to do OSCP soon..
Logged
Grendel
Full Member
***
Offline Offline

Posts: 242


View Profile WWW
« Reply #7 on: April 28, 2011, 08:00:31 AM »

I am doing the Hackindojo course and I love it the only fault I would say with the course is that its part time so my lesson are once a week every Tuesday.

This of course does not stop you learning off your own back.

Clarification:

The online classes are held once a week; however videos of all the classes for the Novice (Mukyu) and Foundational (Shodan) courses are online and can be viewed and worked on at any time... for those individuals who want to accelerate the pace of their learning.
Logged

- Thomas Wilhelm, MSCS MSM
ISSMP CISSP SCSECA SCNA IEM

Web Site:
Author:
  • Professional Penetration Testing
  • Ninja Hacking
  • Penetration Tester's Open Source Toolkit
  • Metasploit Toolkit for Penetration Testing
  • Netcat Power Tools
millwalll
Guest
« Reply #8 on: April 28, 2011, 10:42:36 AM »

I am doing the Hackindojo course and I love it the only fault I would say with the course is that its part time so my lesson are once a week every Tuesday.

This of course does not stop you learning off your own back.

Clarification:

The online classes are held once a week; however videos of all the classes for the Novice (Mukyu) and Foundational (Shodan) courses are online and can be viewed and worked on at any time... for those individuals who want to accelerate the pace of their learning.

That indeed is very true! and I should have pointed that out. my bad Tongue
« Last Edit: April 28, 2011, 10:46:20 AM by Jamie.R » Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.067 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.