Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 86 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow Career Centralarrow Update: its been a while since I posted my " I want to be a p/tester noob thread
EH-Net
May 26, 2012, 04:59:11 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Update: its been a while since I posted my " I want to be a p/tester noob thread  (Read 4462 times)
0 Members and 1 Guest are viewing this topic.
YuckTheFankees
Sr. Member
****
Offline Offline

Posts: 276


View Profile
« on: July 20, 2011, 02:06:30 AM »

Hey everyone,
 
Its been about 3 months since I found this website and I posted my annoying " I want to be a pentester" thread. Now I know how you guys feel when newbies just randomly come up with the idea of hey I want to become a pentester but I have no knowledge of the field..blah blah blah

So I took everyones advise and built my knowledge up ( get some certs/ read books/degree). I was told to learn about the following:

-computers hardware, how they work, blah blah
- Networking
- linux
- programming (python, perl, ruby)
- and many others..

In the past 3 months with no prior IT experience, I have gained my A+, S+, and CCNA. I'm currently working towards my  CCNA: S and Linux +. Also I bought a book about python, so Im teaching myself how to program.

I feel like I'm close to preparing for the CEH (which I heard isnt that impressive) but my real goal is to take the OSCP course and move on to the OSCE. The more I learn.. the more I realize I love this stuff and would be awesome to actually get a security job where I could actually security tools.

I feel like I have built my basic knowledge to where I can start looking at hacking tools and building a lab. I bought the backtrack 4 book (I read it over the weekend) and it was really interesting. Backtrack is still a mysterious beast to me. I dont know how to use any of the tools but Nmap, wireshark, Nessus, and Metasploit definitely interest me. I already pre-ordered the metasploit book that is coming out next week and I really want to learn how to use it. Alot of people talk about script kiddies, and I dont want to be one. I want to learn how the exploits actually work and how to create my own but I feel like Im probably a good 6 months away from that. How do people learn the commands for metasploit? Ive watched some youtube clips on it but it looks confusing.

Do professionals use metasploit? or is there a more professional framework platform they use?


Thanks for listening to my story and I look forward to any comments. I hipe to get some comments about anything Im doing wrong, what I should do next, or anything else relating to my thread.

Thanks everyone, you guys are awesome and a huge help.
Logged

Let's go Red Wings!
tturner
Sr. Member
****
Offline Offline

Posts: 329


View Profile WWW
« Reply #1 on: July 20, 2011, 09:00:25 AM »



Do professionals use metasploit? or is there a more professional framework platform they use?


Professionals use whatever get's the job done while maintaining acceptable risk levels for the client and staying in the confines of the rules of engagement and test scope. That might mean Metasploit, it might not. Your rules of engagement might specify only the use of built-in utilities or limit the types of exploits that can be used. Metasploit is a great tool but don't rely on it too heavily. Real pentesters can still do what they need to do without it, but usually don't unless they have to.
Logged

Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GSEC, OPSE, CSWAE, VCP

Next 6 months: GCIH, CSTP, STI MSISE
hayabusa
Hero Member
*****
Offline Offline

Posts: 1304



View Profile
« Reply #2 on: July 20, 2011, 09:15:51 AM »

Real pentesters can still do what they need to do without it, but usually don't unless they have to.

<nod>

You'll find that many pentesters, who do it for a living, will often have access to the big, paid tools, as well (Metasploit Pro, Core, CANVAS, etc)  Comes with the territory.  The really good ones (pentesters) will tell you, though, that they don't always 'rely' on those tools, but having automated tools, which speed some of their testing, certainly comes in handy, and saves time, depending on the needs and scope of the engagement they're working on.  But again, the GOOD folks know how to accomplish the same tasks without having to rely on or use any given framework, at all.

That said, if you're a new 'up and comer' to the field, which you are, by nature of your own admission ;-), make certain you get your feet wet with Metasploit Framework, and understand what it does, and how it does it, at each step of the process, as that'll help you grow outside the box, when you start working on learning to perform the same tasks, for yourself, without it.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCP , GPEN, C|EH
YuckTheFankees
Sr. Member
****
Offline Offline

Posts: 276


View Profile
« Reply #3 on: July 20, 2011, 02:45:32 PM »

Thanks for the comments.

So if they dont use one of the framework platforms, how would they exploit the targert system? I dont know if I'm asking the right question, Im just trying to figure out how to word my question properly.
Logged

Let's go Red Wings!
hayabusa
Hero Member
*****
Offline Offline

Posts: 1304



View Profile
« Reply #4 on: July 20, 2011, 03:00:37 PM »

Many 'sploits can be used without the framework.  Case in point, being able to pass the proper overflow to a vulnerable service, or something (me hints of some learning they teach from OSCP.)

The framework is just one tool for making an exploit run, but isn't always needed to accomplish the same thing.  A lot of what you'll learn, as you move on, is to analyze the source code for an exploit, and use or modify it, yourself, to accomplish the job. 

Frameworks just consolidate things, combine steps, etc, to speed the process.  They are great for time-sensitive tests, sometimes, where you really need to be quick, but not always as thorough.  But sometimes you need to step / think outside of the box, to accomplish something, or at a minimum, be able to port an existing exploit INTO the framework.

I'm of the camp that believes in understanding what is going on underneath the covers of a tool or exploit, not just being rather 'script-kiddie-ish' and using precanned stuff against targets.  You'll learn more and grow more, in the end, and if you're like me, it's very rewarding.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCP , GPEN, C|EH
YuckTheFankees
Sr. Member
****
Offline Offline

Posts: 276


View Profile
« Reply #5 on: July 20, 2011, 03:13:21 PM »

That does help. So alot of people who use metasploit are script kiddies? I'm thinking about joining hacking dojo, hacker academy, or elearnsecurity.com but after reading some reviews...I dont know if they are really worth the money.

Are you working in the security field?



Logged

Let's go Red Wings!
hayabusa
Hero Member
*****
Offline Offline

Posts: 1304



View Profile
« Reply #6 on: July 20, 2011, 03:21:57 PM »

Don't mistake what I said / meant, there.  My point was in reference to learning, and relying solely on frameworks.

I use it all the time, as do MANY of the more seasoned people.  But you can't RELY solely on that, especially when you're learning, as if you do, you'll miss out on a lot of important understanding.

THAT is / was my message...
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCP , GPEN, C|EH
YuckTheFankees
Sr. Member
****
Offline Offline

Posts: 276


View Profile
« Reply #7 on: July 20, 2011, 03:33:21 PM »

I understand what you meant. I was just surpised script kiddies use metasploit. When I heard of SK's, I imagined someone using wireshark, nmap, or nessus and not really understanding what they are doing. Metasploit seems complicated, so I didnt think script kiddies used it.
Logged

Let's go Red Wings!
hayabusa
Hero Member
*****
Offline Offline

Posts: 1304



View Profile
« Reply #8 on: July 20, 2011, 04:35:48 PM »

Depends on the script kiddie.  You'd be surprised at what I've seen...
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCP , GPEN, C|EH
YuckTheFankees
Sr. Member
****
Offline Offline

Posts: 276


View Profile
« Reply #9 on: July 20, 2011, 09:15:25 PM »

I wouldnt mind hearing some of your personal experiences. I dont want to be a script kiddie haha
Logged

Let's go Red Wings!
cd1zz
Sr. Member
****
Offline Offline

Posts: 393


View Profile WWW
« Reply #10 on: July 20, 2011, 11:01:17 PM »

Find some 0 days on your own and put them in a safe. When you interview to be a pentester bust them out. The result? You're hired and you're not a "script kiddie."
Logged

hayabusa
Hero Member
*****
Offline Offline

Posts: 1304



View Profile
« Reply #11 on: July 21, 2011, 08:52:35 AM »

Here's one example (I'll post THIS one to the thread, as it's more vague, and doesn't directly name anyone.)  Nearby, in the area where I live, there is a fairly new company, who promotes 'KNOWING HOW A HACKER THINKS, AND WHAT THEY LOOK FOR AND USE TO GET YOU."  I've seen copies of their 'pentests' from some customers, who have since called me.  The reports are canned output from nessus and MSF, but don't even go as far as showing they achieved any compromise, or any real detail, aside of the fact that nessus SAYS there are vulnerabilities, and that MSF SAYS they can be exploited.  In fact, in one such report, they show an attempt (that failed) to use MSF to exploit the weakness, and leave it at a statement of "Given time, we're certain that we could've compromised your system."  (yeah.....  given LOTS of time, for them to call in someone with a clue.)  I'm sorry, but the point is to actually achieve the compromise, to prove the validity of the discovery.  A little extra work by them, to understand the exploit and tweak it, and they could've easily made it work.  But instead, they proved (to me, anyway) that they're more or less script kiddies, who memorized their way through certifications (or not even,) but don't truly understand the realities and flaws they were seeing.

This is one of a handful I could give you, from personal experiences.  There have been several, not only by that company, but by others I've seen.  I've also seen reports and findings from other companies who've claimed to have found really serious holes, only to have to relate to my clients (whom I did NOT test, at all) that the holes were neither valid, nor exploitable, in the way that said company claimed.  I went on, in one case to show it was IMPOSSIBLE to have gotten in, via one reported finding, and the contracted pentest company later acknowledged to the customer they doctored up things a bit, since they hadn't proven anything, otherwise.  They had also been contracted for services in maintaining patching,etc, so they wanted to prove there was reason to pay them for their time and services.  Needless to say, said company will NEVER be called by that particular customer, again.  I give the company in my first paragraph props, at least, for leaving it at, "we didn't get it, but could've."  At least they didn't outright lie...

Just goes to show, like in the thread where sil is discussing certified versus experienced, etc, that folks really need to vet out their employees, and need to research carefully on anyone they are contracting in for security work, to make sure the credentials and knowledge are accurate, and not just a ticket to open the front door and make some $$.
« Last Edit: July 21, 2011, 02:47:02 PM by hayabusa » Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCP , GPEN, C|EH
impelse
Sr. Member
****
Offline Offline

Posts: 493


View Profile
« Reply #12 on: July 21, 2011, 10:38:24 AM »

Good post hayabusa, I saw similar situation but not only in the security side.
Logged

CCNA, Security+, 70-290, 70-291
CCNA Security, Working Windows 7 70-680
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.279 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.