Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 40 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
My Next Path (Advice)
EH-Net
May 21, 2013, 05:32:03 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
My Next Path (Advice)
Pages: [
1
]
2
3
Go Down
« previous
next »
Print
Author
Topic: My Next Path (Advice) (Read 15421 times)
0 Members and 1 Guest are viewing this topic.
xXxKrisxXx
Hero Member
Offline
Posts: 512
My Next Path (Advice)
«
on:
August 11, 2011, 12:21:58 PM »
Hey EthicalHacker,
It's been awhile since I've posted a topic here! I have recently come up on a decent amount of money and I plan on putting it towards my education. I am one of those IT guys caught between Programming and Pentesting; Can't decide which one I love more because I like them both. My ultimate dream is to do development for awhile then move into Penetration Testing (or even alternate in between the two of them). I am posting because I'm in a bit of a bind on where my path lies ahead and I'm wanting some advice on courses I should take.
GPEN looks great to me, I am considering the OnDemand course. I have always wanted to hold a GIAC certification because they're well respected (although pricey). Do any of you have experience taking the OnDemand version of the course? Does the fee include the certification take cost? I noticed the promo code on here which will save me $150.00, so that is great!
On an alternate end, I'm kind of thinking, I hold an OSCP certification. I've heard there's some information overlapping between GPEN and OSCP, is this necessarily true? If it is true, what path would you recommend going down to obtain the GPEN certification? Self Study?
Somewhere in my twisted brain, I kind of feel the desire for pain - I've had my thoughts on considering doing Offensive-Security's CTP course. If I would be able to become OSCE certified I would feel like someone at the top of their pen test game! I am just kind of skeptic whether I have the skills to go in to the lion's den almost blindfolded, and expect not to get bitten. Surely I have endured til the end in my PWB adventure, but I hear CTP is a whole new level of pain. What are your guys thoughts on me considering this?
And then lastly, for some odd reason I feel the need to want to officially fit in. I never thought it would be on my mind, but obtaining the CEH just to stick it on my resume does not sound like a bad thought to me. I am considering online training for all of these, and would like to hear some of your guys experience taking the training for CEH online (or self-study). Is this certification all that it is hyped up to be? I haven't heard many positive experience on folks who have taken v7 on here.
Anyway, I have an open mind, and money to spend, have CEH, OSCE, and GPEN on my mind. I may just say, "Bring them all on", but i wanted to hear your guys thoughts on what I should go after. If you think I should tackle them all, feel free to list off the order!
Hope to hear from you all!
Cheers,
Kris
Logged
eCPPT, GCIH, OSCP, OSWP
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: My Next Path (Advice)
«
Reply #1 on:
August 11, 2011, 12:47:42 PM »
Here is my 2 cents:
- OSCP covers about 90% of what you need to know for GPEN. The main differences between the two is Windows based tools and some laws. So register for the exam right away, without taking any courses. I personally did that after failing OSCP and scored pretty high on GPEN... With any GIAC/SANS exam, you get a practice exam that is pretty close to the real test. This will give you confidence. Although I heard SANS offers great courses, after OSCP, you can save your money for GPEN.
I am doing OSCE and it is mainly focus on exploit development. If this is your thing, go for it.
You should be able to write CEH by reading a book or two like I did...
But what about a web application penetration testing course? PWB covers only the basic of web app pentest...
Good luck!
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
xXxKrisxXx
Hero Member
Offline
Posts: 512
Re: My Next Path (Advice)
«
Reply #2 on:
August 11, 2011, 03:10:19 PM »
Nice. Good response hit monkey, you just confirmed it for me. I didn't know OSCP covered 90% of it. This is good information and has me thinking I wish I would've known that when I did PWB last year. I might as well just go over all of the videos in PWB and just pay for the exam like you mentioned. Exploit Development sounds hard, I personally don't know any ASM but got a good introduction to registers n such in the PWB course. I suppose my path should be: GPEN -> OSCE, obtain CEH maybe in between or after taking CTP. Good information here. It'd just be my luck if my test consisted of nothing but tons of laws and Windows Tools. Thanks!
Logged
eCPPT, GCIH, OSCP, OSWP
mesho
Newbie
Offline
Posts: 24
Re: My Next Path (Advice)
«
Reply #3 on:
August 11, 2011, 05:41:52 PM »
my recommendation will be a little bit different!
and i'm sure when you follow these steps you will gain the knowledge you seeking for:
review OSCP videos, try to grasp all the hacking technique.
then purchase GPEN exam and try to write down all the laws related, some of this laws will be presented on the practice exam but not all.
when finally acquire the GPEN Certificatoin don't think to go for OSCE still there's something you need to follow which is:
SANS Advanced Penetration Testing SEC 660
http://www.sans.org/security-training/advanced-penetration-testing-exploits-ethical-hacking-1517-mid
SANS Advanced Exploit Development 2 days course or selfstudy materials SEC 710
http://www.sans.org/security-training/advanced-exploit-development-1522-mid
and last you will be ready to take the OSCE Challenge
Logged
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: My Next Path (Advice)
«
Reply #4 on:
August 11, 2011, 06:44:30 PM »
Not a bad idea mesho.
Another very, very good course I had the chance to take last May in Dallas was "Advanced Penetration Testing" with Joe McCray from CAST. There, you learn how to hack into Windows 7 fully patch and things like that.
I highly recommend it.
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
Dark_Knight
Sr. Member
Offline
Posts: 292
Re: My Next Path (Advice)
«
Reply #5 on:
August 11, 2011, 07:14:14 PM »
I actually did the GPEN via OnDemand. I also did it after the OSCP. Nothing compares to the OSCP. The GPEN compliments the OSCP quite well. There is in fact some fact some amount of overlap with the OSCP providing better coverage in some areas.
The difference between the two is more than just laws
the GPEN covers a lot of the business aspects of doing a pen test. Topics such as defining scope, creating a get out of jail free card, defining the rules of engagement etc are covered. So the OSCP gives you that 'raw' skill. The GPEN will help 'refine' it
As mentioned above grab the practice test and gauge your readiness from that. The test costs $99. If you do decide to go the ondemand route then keep checking the website as ever so often there are promos that offer discounts of up to 25%. If a discount is not offered, then go out on a limb and ask for one.
The CEH........that was my first certification. When I did it I knew NOTHING about security. So given that you already have the OSCP getting the CEH should not be difficult.
Logged
CEH, OSCP, GPEN, GWAPT, GCIA
http://sector876.blogspot.com
xXxKrisxXx
Hero Member
Offline
Posts: 512
Re: My Next Path (Advice)
«
Reply #6 on:
August 11, 2011, 07:16:30 PM »
I've decided to kind've combine both of your ideas into one. I've purchased the exam voucher for the GPEN. Apparently it comes with 2 practice tests and the final exam. I'm going to spend time reviewing my OSCP material, and studying some Hacking Laws, plus some of the things Dark_Knight mentioned, then start taking the exams. Taking Sec 660 then 710 sounds like it would definitely prepare me enough to go into CTP very comfortably. Appreciate your responses guys. I'm going to put my head into this material and try one of the practice tests within a week or two.
Cheers,
Kris
Logged
eCPPT, GCIH, OSCP, OSWP
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: My Next Path (Advice)
«
Reply #7 on:
August 11, 2011, 08:58:03 PM »
Dark_Knight is right, there's more than "law" and windows tools in GPEN. I was in a rush at work and couldn't elaborate more... My bad!
But GPEN isn't hard after OSCP. You will get a very accurate feel of the exam with your practice tests.
Good luck xXxKrisxXx
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
idr0p
Newbie
Offline
Posts: 49
Re: My Next Path (Advice)
«
Reply #8 on:
August 12, 2011, 02:38:48 PM »
Wow this actually covers from stuff i am going through right now.
I am scheduled for the CISA in Dec. I wanted to complete a cert in the mean time by end of Oct. then study for the CISA. As I just completed the GPEN, I am up in the air as to if i should do the GWAPT or the OSCP.
P.S. I am also going back to school for my masters in Jan. I will be talking web app development which may compliment the GWAPT
Should i do my OSCP now. then cisa and Gwapt in jan or should i do the gwapt then CISA and OSCP?
«
Last Edit: August 12, 2011, 02:41:57 PM by idr0p
»
Logged
GCIA GCIH GPEN GWAPT
Up Next: CISA CISSP
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: My Next Path (Advice)
«
Reply #9 on:
August 12, 2011, 08:30:23 PM »
Based on the three certs you already have, go for OSCP. You will see it is quite different than GIAC certs. You will feel like it is the best thing you ever did.
So OSCP, no hesitations!
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
hayabusa
Hero Member
Offline
Posts: 1632
Re: My Next Path (Advice)
«
Reply #10 on:
August 12, 2011, 08:49:17 PM »
H1t M0nk3y ++1
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
Dark_Knight
Sr. Member
Offline
Posts: 292
Re: My Next Path (Advice)
«
Reply #11 on:
August 12, 2011, 09:09:23 PM »
Quote from: idr0p on August 12, 2011, 02:38:48 PM
Wow this actually covers from stuff i am going through right now.
I am scheduled for the CISA in Dec. I wanted to complete a cert in the mean time by end of Oct. then study for the CISA. As I just completed the GPEN, I am up in the air as to if i should do the GWAPT or the OSCP.
P.S. I am also going back to school for my masters in Jan. I will be talking web app development which may compliment the GWAPT
Should i do my OSCP now. then cisa and Gwapt in jan or should i do the gwapt then CISA and OSCP
The OSCP will be a lot fun. The GWAPT is also good. Very good introduction to the world of web application penetration testing. Have a go at the OSCP, grab a copy of WAHH. If you like WAHH[Web Application Hackers Handbook] jump into the GWAPT.
«
Last Edit: August 12, 2011, 09:12:37 PM by Dark_Knight
»
Logged
CEH, OSCP, GPEN, GWAPT, GCIA
http://sector876.blogspot.com
idr0p
Newbie
Offline
Posts: 49
Re: My Next Path (Advice)
«
Reply #12 on:
August 13, 2011, 12:30:43 PM »
OSCP IT IS!
Logged
GCIA GCIH GPEN GWAPT
Up Next: CISA CISSP
xXxKrisxXx
Hero Member
Offline
Posts: 512
Re: My Next Path (Advice)
«
Reply #13 on:
August 17, 2011, 01:42:38 PM »
Hey Guys -
I took one of my practice tests last night and didn't end up passing it. I learned what I need to beef up my knowledge on to get a passing score and it turns out my weakness lies in knowing the Laws, Wireless Crypto and Client Attacks, Wireless Fundamentals, and some in-depth knowledge of scanning. I missed a couple other questions in other areas. Since I hadn't been exposed to the WiFi stuff, what I'm going to do right now is sign-up for the OSWP course. It's affordable, will provide me with a solid background in theory and attacks to be able to ace this particular portion of the test, and I'll pick up the certification in the process. Then I plan on studying up on laws and other areas I seem to be weak in.
The positives about the practice tests is at the end of it, your given ranks on each category corresponding to:
http://www.giac.org/certification/penetration-tester-gpen
so you end up knowing where and what you need to study up on. Your actually given 4 months to take your 2 practice tests and schedule your proctored examination, so this should give me a great window for picking up on my weaker areas. I'll keep everyone up-to-date!
Kris
Logged
eCPPT, GCIH, OSCP, OSWP
xXxKrisxXx
Hero Member
Offline
Posts: 512
Re: My Next Path (Advice)
«
Reply #14 on:
August 24, 2011, 05:39:29 PM »
Hello E-H!
Just wanted to keep everyone up-to-date with my progress! I officially was enrolled into OSWP on the 18th, and went through the course within a couple of days. The course isn't nearly as lengthy as PWB. A couple days later I actually sent in challenge request date which happened to be today and I already took my OSWP certification exam. I was able to successfully obtain all the keys and have sent in my results, just awaiting official decision right now.
Had a blast in the class! My aunt loaned me her router, I've had an Alfa card for a couple years now. I had always used point-n-click tools to break into my AP, but now can successfully say I've dabbled in the command-line arts for getting my wifu on. I felt the class really gave a good introduction to the aircrack-ng suite and I may possibly leave a review of it here shortly. Some may think between the amount of time I enrolled versus when I scheduled my exam was pretty quick (less than 1 week of being enrolled in the course), but I actually dedicated a lot of time breaking into my router with various configurations, and wrote down well over 5 pages of notes! It's tons of practice, practice, practice! I definitely picked up on a good amount it makes me wonder how this course stacks up against SANS GAWN course.
Kris
«
Last Edit: August 24, 2011, 05:41:46 PM by xXxKrisxXx
»
Logged
eCPPT, GCIH, OSCP, OSWP
Pages: [
1
]
2
3
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Programming
: Finished Python Course in Codecademy now what?
(13) by
securitian
Network Pen Testing
: Ruby on Rails Vulnerabilities/Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
Network Pen Testing
: AIX Vulnerability Assessments
(1) by
3xban
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
Tutorials
: Need guidance
(8) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.