Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 25 guests and 1 member online
You are here:
Home
Resources
Career Central
Update: its been a while since I posted my " I want to be a p/tester noob thread
EH-Net
May 26, 2013, 01:01:05 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Resources
>
Career Central
(Moderator:
don
) >
Update: its been a while since I posted my " I want to be a p/tester noob thread
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Update: its been a while since I posted my " I want to be a p/tester noob thread (Read 6699 times)
0 Members and 1 Guest are viewing this topic.
YuckTheFankees
Sr. Member
Offline
Posts: 324
Update: its been a while since I posted my " I want to be a p/tester noob thread
«
on:
July 20, 2011, 02:06:30 AM »
Hey everyone,
«
Last Edit: August 21, 2012, 06:17:29 AM by YuckTheFankees
»
Logged
OSCP in progress
tturner
Sr. Member
Offline
Posts: 432
Re: Update: its been a while since I posted my " I want to be a p/tester noob thread
«
Reply #1 on:
July 20, 2011, 09:00:25 AM »
Quote from: YuckTheFankees on July 20, 2011, 02:06:30 AM
Do professionals use metasploit? or is there a more professional framework platform they use?
Professionals use whatever get's the job done while maintaining acceptable risk levels for the client and staying in the confines of the rules of engagement and test scope. That might mean Metasploit, it might not. Your rules of engagement might specify only the use of built-in utilities or limit the types of exploits that can be used. Metasploit is a great tool but don't rely on it too heavily. Real pentesters can still do what they need to do without it, but usually don't unless they have to.
Logged
Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP
WIP: OSWP, GSSP-JAVA, GXPN
Udacity on hold, again. I suck.
http://sentinel24.com/blog
@tonylturner
http://bsidesorlando.org
hayabusa
Hero Member
Offline
Posts: 1633
Re: Update: its been a while since I posted my " I want to be a p/tester noob thread
«
Reply #2 on:
July 20, 2011, 09:15:51 AM »
Quote from: tturner on July 20, 2011, 09:00:25 AM
Real pentesters can still do what they need to do without it, but usually don't unless they have to.
<nod>
You'll find that many pentesters, who do it for a living, will often have access to the big, paid tools, as well (Metasploit Pro, Core, CANVAS, etc) Comes with the territory. The really good ones (pentesters) will tell you, though, that they don't always 'rely' on those tools, but having automated tools, which speed some of their testing, certainly comes in handy, and saves time, depending on the needs and scope of the engagement they're working on. But again, the GOOD folks know how to accomplish the same tasks without having to rely on or use any given framework, at all.
That said, if you're a new 'up and comer' to the field, which you are, by nature of your own admission ;-), make certain you get your feet wet with Metasploit Framework, and understand what it does, and how it does it, at each step of the process, as that'll help you grow outside the box, when you start working on learning to perform the same tasks, for yourself, without it.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
YuckTheFankees
Sr. Member
Offline
Posts: 324
Re: Update: its been a while since I posted my " I want to be a p/tester noob thread
«
Reply #3 on:
July 20, 2011, 02:45:32 PM »
Thanks for the comments.
So if they dont use one of the framework platforms, how would they exploit the targert system? I dont know if I'm asking the right question, Im just trying to figure out how to word my question properly.
Logged
OSCP in progress
hayabusa
Hero Member
Offline
Posts: 1633
Re: Update: its been a while since I posted my " I want to be a p/tester noob thread
«
Reply #4 on:
July 20, 2011, 03:00:37 PM »
Many 'sploits can be used without the framework. Case in point, being able to pass the proper overflow to a vulnerable service, or something (me hints of some learning they teach from OSCP.)
The framework is just one tool for making an exploit run, but isn't always needed to accomplish the same thing. A lot of what you'll learn, as you move on, is to analyze the source code for an exploit, and use or modify it, yourself, to accomplish the job.
Frameworks just consolidate things, combine steps, etc, to speed the process. They are great for time-sensitive tests, sometimes, where you really need to be quick, but not always as thorough. But sometimes you need to step / think outside of the box, to accomplish something, or at a minimum, be able to port an existing exploit INTO the framework.
I'm of the camp that believes in understanding what is going on underneath the covers of a tool or exploit, not just being rather 'script-kiddie-ish' and using precanned stuff against targets. You'll learn more and grow more, in the end, and if you're like me, it's very rewarding.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
YuckTheFankees
Sr. Member
Offline
Posts: 324
Re: Update: its been a while since I posted my " I want to be a p/tester noob thread
«
Reply #5 on:
July 20, 2011, 03:13:21 PM »
That does help. So alot of people who use metasploit are script kiddies? I'm thinking about joining hacking dojo, hacker academy, or elearnsecurity.com but after reading some reviews...I dont know if they are really worth the money.
Are you working in the security field?
Logged
OSCP in progress
hayabusa
Hero Member
Offline
Posts: 1633
Re: Update: its been a while since I posted my " I want to be a p/tester noob thread
«
Reply #6 on:
July 20, 2011, 03:21:57 PM »
Don't mistake what I said / meant, there. My point was in reference to learning, and relying solely on frameworks.
I use it all the time, as do MANY of the more seasoned people. But you can't RELY solely on that, especially when you're learning, as if you do, you'll miss out on a lot of important understanding.
THAT is / was my message...
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
YuckTheFankees
Sr. Member
Offline
Posts: 324
Re: Update: its been a while since I posted my " I want to be a p/tester noob thread
«
Reply #7 on:
July 20, 2011, 03:33:21 PM »
I understand what you meant. I was just surpised script kiddies use metasploit. When I heard of SK's, I imagined someone using wireshark, nmap, or nessus and not really understanding what they are doing. Metasploit seems complicated, so I didnt think script kiddies used it.
Logged
OSCP in progress
hayabusa
Hero Member
Offline
Posts: 1633
Re: Update: its been a while since I posted my " I want to be a p/tester noob thread
«
Reply #8 on:
July 20, 2011, 04:35:48 PM »
Depends on the script kiddie. You'd be surprised at what I've seen...
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
YuckTheFankees
Sr. Member
Offline
Posts: 324
Re: Update: its been a while since I posted my " I want to be a p/tester noob thread
«
Reply #9 on:
July 20, 2011, 09:15:25 PM »
I wouldnt mind hearing some of your personal experiences. I dont want to be a script kiddie haha
Logged
OSCP in progress
cd1zz
Recruiters
Hero Member
Offline
Posts: 561
Re: Update: its been a while since I posted my " I want to be a p/tester noob thread
«
Reply #10 on:
July 20, 2011, 11:01:17 PM »
Find some 0 days on your own and put them in a safe. When you interview to be a pentester bust them out. The result? You're hired and you're not a "script kiddie."
Logged
OSCE | OSCP | GXPN | OSWP | CISSP
http://www.pwnag3.com
http://www.networkadminsecrets.com
hayabusa
Hero Member
Offline
Posts: 1633
Re: Update: its been a while since I posted my " I want to be a p/tester noob thread
«
Reply #11 on:
July 21, 2011, 08:52:35 AM »
Here's one example (I'll post THIS one to the thread, as it's more vague, and doesn't directly name anyone.) Nearby, in the area where I live, there is a fairly new company, who promotes 'KNOWING HOW A HACKER THINKS, AND WHAT THEY LOOK FOR AND USE TO GET YOU." I've seen copies of their 'pentests' from some customers, who have since called me. The reports are canned output from nessus and MSF, but don't even go as far as showing they achieved any compromise, or any real detail, aside of the fact that nessus SAYS there are vulnerabilities, and that MSF SAYS they can be exploited. In fact, in one such report, they show an attempt (that failed) to use MSF to exploit the weakness, and leave it at a statement of "Given time, we're certain that we could've compromised your system." (yeah..... given LOTS of time, for them to call in someone with a clue.) I'm sorry, but the point is to actually achieve the compromise, to prove the validity of the discovery. A little extra work by them, to understand the exploit and tweak it, and they could've easily made it work. But instead, they proved (to me, anyway) that they're more or less script kiddies, who memorized their way through certifications (or not even,) but don't truly understand the realities and flaws they were seeing.
This is one of a handful I could give you, from personal experiences. There have been several, not only by that company, but by others I've seen. I've also seen reports and findings from other companies who've claimed to have found really serious holes, only to have to relate to my clients (whom I did NOT test, at all) that the holes were neither valid, nor exploitable, in the way that said company claimed. I went on, in one case to show it was IMPOSSIBLE to have gotten in, via one reported finding, and the contracted pentest company later acknowledged to the customer they doctored up things a bit, since they hadn't proven anything, otherwise. They had also been contracted for services in maintaining patching,etc, so they wanted to prove there was reason to pay them for their time and services. Needless to say, said company will NEVER be called by that particular customer, again. I give the company in my first paragraph props, at least, for leaving it at, "we didn't get it, but could've." At least they didn't outright lie...
Just goes to show, like in the thread where sil is discussing certified versus experienced, etc, that folks really need to vet out their employees, and need to research carefully on anyone they are contracting in for security work, to make sure the credentials and knowledge are accurate, and not just a ticket to open the front door and make some $$.
«
Last Edit: July 21, 2011, 02:47:02 PM by hayabusa
»
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
impelse
Hero Member
Offline
Posts: 565
Re: Update: its been a while since I posted my " I want to be a p/tester noob thread
«
Reply #12 on:
July 21, 2011, 10:38:24 AM »
Good post hayabusa, I saw similar situation but not only in the security side.
Logged
CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training
Website:
http://blog.thehost1.com/
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(95) by
zeebee
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(30) by
don
Tools
: Symbolic Exploit Assistant project is looking for collaborators
(0) by
galapag0
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.