Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 60 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
How to convince your boss to allow linux in the workplace
EH-Net
May 24, 2013, 07:12:24 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
How to convince your boss to allow linux in the workplace
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: How to convince your boss to allow linux in the workplace (Read 7129 times)
0 Members and 1 Guest are viewing this topic.
eyenit0
Jr. Member
Offline
Posts: 51
How to convince your boss to allow linux in the workplace
«
on:
December 16, 2011, 09:09:43 PM »
So, I just started my first job where my main responsibility is pen testing. In my previous experience, I have mostly used linux when doing any sort of testing/hacking. My new job, they only use Windows. I asked about using linux for pen testing and was told it's not allowed, but exceptions could be made (we deal with very sensitive information, so everything is very restricted). I was told this is because they don't have anything in place to tie it into the network, as far as authentication, management, etc. We have a few linux servers, so I'm not sure what they do with those.
Since many of the tools I know are either linux only, or natively linux, so I feel like I'm without my arms if I don't have it.
What advice could some of you give on how to convince my boss and the IT department that linux has it's place in our testing toolkit? Even just being able to load up a live CD like Backtrack would be enough.
On the flipside, I could get used to these jobs were they give you a Nessus Pro feed on your first day...
Logged
l33t5h@rk
Jr. Member
Offline
Posts: 79
Re: How to convince your boss to allow linux in the workplace
«
Reply #1 on:
December 16, 2011, 10:19:27 PM »
I would do a formal write up on the advantages of incorporating linux in the environment, including a cost savings angle. IT Suits (as I am one - unfortunately
) will always be pressured from the biz folks for $$$ savings so perhaps you could breakdown how certain tools can help automate certain tasks and thus save time, etc. Hard to believe they are doing pen testing on just windows though, I would assume this is for a particular reason but opening their eyes to backtrack would undoubtedly be worth everyone's while.
Logged
chrisj
Hero Member
Offline
Posts: 1163
Re: How to convince your boss to allow linux in the workplace
«
Reply #2 on:
December 17, 2011, 03:42:02 PM »
Sounds like they don't have anyone on staff that really understands linux. Authenticating to windows domain controller's while a pain isn't that hard. they probably also have issues with not being able to push patches, and I suspect have a way to get into your system via domain admin to check to see what they're doing.
In your write up, include the fact that it can be added to the network no problem via the domain controllers, and that most backup solutions provide a linux client. Also include that the attackers aren't going to limit themselves to just windows and you're testing shows more real world equivalent instead of just check box security. Just don't word it that way.
Logged
OSWP, Sec+
WCNA
Full Member
Offline
Posts: 187
Re: How to convince your boss to allow linux in the workplace
«
Reply #3 on:
December 18, 2011, 04:16:26 PM »
I think I'd point out that if they don't allow you to use linux then they need to come up with some big bucks for the windows pentesting apps. Otherwise you can't do your job properly.
Logged
ISC2 Associate, WCNA, CWNA, OSCP, Network+
l33t5h@rk
Jr. Member
Offline
Posts: 79
Re: How to convince your boss to allow linux in the workplace
«
Reply #4 on:
December 18, 2011, 08:21:12 PM »
Quote from: WCNA on December 18, 2011, 04:16:26 PM
I think I'd point out that if they don't allow you to use linux then they need to come up with some big bucks for the windows pentesting apps. Otherwise you can't do your job properly.
I thought about that too. I know it's not kosher to divulge a lot of info but has your company spent a decent amount on commercial products? I suppose there is a bit of rationale if they have a standardized suite but it is more unexpected than anything that linux just for certain tools wouldn't be part of the environment.
Logged
millwalll
Guest
Re: How to convince your boss to allow linux in the workplace
«
Reply #5 on:
December 19, 2011, 03:58:44 AM »
I agree with comments so far write up a review of the os and detail your reason why you want to use Linux.
Maybe say that using linux there more tools and you can get better coverage of whatever you testing. also any attackers are going to be using linux so by not having access to the same tools you cant be 100% sure the system would be safe.
Logged
3xban
Hero Member
Offline
Posts: 608
Re: How to convince your boss to allow linux in the workplace
«
Reply #6 on:
December 19, 2011, 08:24:14 AM »
you can also add that it doesn't need to be a physical system, you can utilize virtualization to leverage linux clients for pen testing, so in a sense you would still be using your windows system, but the particular tool would be a linux vm
Also what is the scope they want you to cover as an internal pen tester? Is this a consulting company? or just one that wants to have an internal guy testing things?
Logged
Certs: GCWN
(@)Dewser
sgt_mjc
Sr. Member
Offline
Posts: 294
Re: How to convince your boss to allow linux in the workplace
«
Reply #7 on:
December 19, 2011, 09:10:32 AM »
As 3xban pointed out, a VM might be your best bet of getting a Linux box. If you do go that route though, pick the hyper-visor that will work best with both the host and the guest. And don't forget that backtrack was not built to be a secure OS but a pentest OS.
Logged
Mike Conway
CISSP
CompTia Security +
C|EH
ajohnson
Recruiters
Hero Member
Offline
Posts: 1060
aka dynamik
Re: How to convince your boss to allow linux in the workplace
«
Reply #8 on:
December 19, 2011, 10:28:33 AM »
At my previous job, I had a group of "Attack VMs" that I used with VMware Workstation. I didn't want one of those as my main OS anyway. I used that primarily for writing reports, email, etc. I could be on the domain, receive patches and AV updates, etc., but I still had the flexibility and tools that I preferred during testing.
Although, it totally depends on the organization (or rather, the customers). Sometimes you're required to use commercial tools, and that's just the way it is.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
eyenit0
Jr. Member
Offline
Posts: 51
Re: How to convince your boss to allow linux in the workplace
«
Reply #9 on:
December 19, 2011, 06:06:18 PM »
Thanks for the replies, there's some good stuff in here. Sorry I didn't respond earlier...I forgot to subscribe to my own post again.
I had thought about the VM solution and am going to talk with my boss about it. Without going into too much detail, I will be doing more internal pentesting than anything and we don't have an official, established toolkit as of yet.
Part of my job is to research and build our toolkit before the testing begins. There is some money in the budget for commercial apps, which we will be getting, but I'm not sure of the amount.
I think all the advice on setting up a VM and only using it when testing is the way I'm going to present it to them. I don't really need to use it on a daily basis, but I do feel pretty lost testing without it, even if we do get some pretty nice commercial tools. The advantage of using what an attacker is most likely using is a big thing too.
As of right now, only a few of the IT people are familiar with linux and by boss hasn't even heard of backtrack. I think if I can explain some of the points that you guys have made, along with demonstrating Backtrack and the usefulness of some of the tools, I'll be able to get somewhere.
Let me know if you've got anything else to add. I'm probably not going to get to the actual testing for another few weeks, but I'll try to update on the outcome.
Logged
ajohnson
Recruiters
Hero Member
Offline
Posts: 1060
aka dynamik
Re: How to convince your boss to allow linux in the workplace
«
Reply #10 on:
December 20, 2011, 09:30:05 AM »
If you're going the BackTrack route and not just discussing Linux in general, I'd really emphasis that Offensive Security is an established organization that provides professional penetration testing services and training. I think a lot of open source projects are viewed negatively from a corporate perspective because of the lack of structure, support, etc. I think you will be able to quell a lot of the concerns if you can successfully make the case for BackTrack being a professional platform that's commonly used by experienced penetration testers.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: ÌÀÃÀÇÈÍ ÌÎÄÍÎÉ ÎÄÅÆÄÛ APPLE-FASHION!
(0) by
Infabeemace
News Items and General Discussion About EH-Net
: When your benjamin will be to your own car and truck clean up
(0) by
areluctes
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(8) by
ajohnson
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(29) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
Greetings
: Hi from the UK
(4) by
MrTuxracer
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.