Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 47 guests and 2 members online
Free Business and Tech Magazines and eBooks
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
My roadmap to InfoSec
EH-Net
May 23, 2013, 01:22:51 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
My roadmap to InfoSec
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: My roadmap to InfoSec (Read 8840 times)
0 Members and 1 Guest are viewing this topic.
MrTuxracer
Newbie
Offline
Posts: 43
My roadmap to InfoSec
«
on:
December 30, 2011, 12:11:06 PM »
Hello EH-Community,
I'm new to this community, but I have read a lot of good & interesting articles in here and that's the reason why I need your advice
I'm currently working as a network administrator for about 4 years now (it's my first job) and would like to go deeper into InfoSec. I spent most time of my day on router, switch and firewall shells, so I've got quite good networking fundamentals. Beside this I am a LPI - certfied Linux fanboy - well, I don't use Windows unless there's no other way, like in the world of Active Directory
and I am a VMware enthusiast, because I love this technology and its impact.
I've got coding knowledge in VB.NET, PHP/SQL and basic ASM, C++.
Now I would like to realign my focus on InfoSec like attack and prevention mechanisms. I'm interested in InfoSec for over a year now and already have some basic fundamentals (like WebSecurity, BufferOverflows, usage of Metasploit and some other common tools) but I'm missing the in-depth details. That's the reason why I started to blog about things but this only helps a little. Now I've read a lot about certifications on EH and think those courses and (practical) exams are the best way to learn the details.
I'm currently thinking of going this way during the next 2 years:
CEH -> eCPPT Pro -> OSCP -> OSCE
(Taking the CEH and eCPPT Pro until summer, and the OSCP until end of 2012).
What do you think ?
By the way: My problem is that I have to pay most of the courses/exams out of my own pocket because my employer doesn't want to pay them. I hope that they'll pay at least the CEH
Thanks & Regards
Logged
eCPPT, HP ASE (Networking), LPIC-1, OSCP, WCSP
www.inshell.net
xXxKrisxXx
Hero Member
Offline
Posts: 512
Re: My roadmap to InfoSec
«
Reply #1 on:
December 30, 2011, 01:19:19 PM »
Hi MrTuxracer,
Welcome to the forums. Great background! Your experience in programming will help you out big time. Looks like a solid track you've set up for yourself, but with you having the fundamentals under your belt, I would say its time to go out there and have at it. VMware is great for practice! Setup some vulnerable VMs, get some vulnerable software, and hack away.
Having taken the eCPPT Pro and OSCP courses, I can tell your going to learn a good amount. Plus with the practical exams versus written, after you earn the certifications, they'll look better to employers (although I haven't seen the eCPPT recognized yet by HR. OSCP/E is getting its recognition barely, and CEH they love to see - thoughthe exam is written). Be sure when you sign up for the eCPPT course, you obtain the 5% voucher offered for EH-NET members, which could be redeemed
here
.
There are several of us here who pay out of pocket for our training. Sounds like were all in the same boat in relating to getting the best training for buck. Although not initially mentioned, alternate positive resources at affordable prices are:
Hacking Dojo
Strategic Security
- which I believe was previously LearnSecurityOnline
SecurityTube
I think you've picked a solid route to take and your in for a fun ride (especially by the time you get to taking Cracking the Perimeter). Were all here to help along the way. For future references if you want to go the route of practicing in your own lab, below are a few links that will help out:
Virtual Images of Windows XP, Vista, and 7 - Compatible with
Virtual PC
http://www.microsoft.com/download/en/details.aspx?id=11575
VMware's Virtual Appliance Marketplace - Containing Windows 2003 & Various Linux Distros
http://www.vmware.com/appliances/
Vulnerable Web Applications for Learning
https://securitythoughts.wordpress.com/2010/03/22/vulnerable-web-applications-for-learning/
OldApps - Find older software to practice exploitation on
http://www.oldapps.com/
Vulnerable by Design - Links to tons of vulnerable VMs, Web Apps, War Games & More
http://g0tmi1k.blogspot.com/2011/03/vulnerable-by-design.html
«
Last Edit: January 10, 2012, 06:37:42 PM by xXxKrisxXx
»
Logged
eCPPT, GCIH, OSCP, OSWP
Seen
Full Member
Offline
Posts: 134
Re: My roadmap to InfoSec
«
Reply #2 on:
December 30, 2011, 01:21:03 PM »
Honestly, I would take the eCPPT first, and strongly read these forums in regards to the CEH. It looks good on a resume, but from what I hear you don't get a lot of knowledge from the CEH. The eCPPT, on the other hand is a great entry-level cert, and way cheaper than the CEH unless you don't have to take the class.
Logged
Sec+, eCPPT
MrTuxracer
Newbie
Offline
Posts: 43
Re: My roadmap to InfoSec
«
Reply #3 on:
December 30, 2011, 03:26:18 PM »
Thanks xXxKrisxXx & Seen for your answers!
@xXxKrisxXx:
I thought about the SMFE course made by SecurityTube too, but it's quite too new and more specific. If there is more feedback on the SMFE available, I think it's good to take it after the eCPPT and before the OSCP/E. Have you planned to take it ?
Thanks for the list of ressources, I already know some of them, especially oldapps.com. I used them to rebuild a bufferoverflow exploit by myself...well an easy one, but at least it worked like a charme
And the last one is really nice!
@Seen:
Yes, you're right! I think that the CEH is only a HR relevant certificate. I don't like multiple-choice exams, even though the VCP exam was quite hard work, but they do not say a lot about the real skill of the holder...well in times of braindumps.... they do not say anything
Logged
eCPPT, HP ASE (Networking), LPIC-1, OSCP, WCSP
www.inshell.net
xXxKrisxXx
Hero Member
Offline
Posts: 512
Re: My roadmap to InfoSec
«
Reply #4 on:
December 30, 2011, 03:43:31 PM »
Hi MrTuxracer,
The SMFE course I think is barely starting. I don't think there are any reviews on it currently. I did hear Vivek mention in his SMFE video that he planned on rolling out a Metasploit book early 2012. It's going to be great and accommodate the course well.
I went for the eCPPT after OSCP, but I agree on attempting it before the OSCP course. I plan on taking CTP eventually here but to be honest, the reviews on it, and how much it is hyped up I don't know if I'm ready for it. They make it out like you have to be an Exploitation guru and require you to pass their
http://fc4.me/
challenge before even signing up. The course looks intimidating to me, filled with tons of pain, but with the cert your guaranteed respect by any serious InfoSec peers.
If you replicated a buffer overflow example, your well on your way for Pentesting with BackTrack. I was going to mention you could either do CEH or eCPPT in any order but didn't want to bash CEH too hard like I have been guilty for doing in the past. Its' very HR relevant, and taking it before the eCPPT may help you even more in the PTP Pro course. What I enjoyed about eLearnSecurity's course was not only the amount of time they give you to go through all of the material in the class, but the solid material on the Web App module which will get you prepared for the eCPPT exam.
Logged
eCPPT, GCIH, OSCP, OSWP
MrTuxracer
Newbie
Offline
Posts: 43
Re: My roadmap to InfoSec
«
Reply #5 on:
January 02, 2012, 11:10:10 AM »
Hi xXxKrisxXx,
I just enrolled for the eCPPT and started to study on it. The study material is quite good and organized and there are a lot of interesting new things in it. I do not have regrets about this purchase - looks like this gonna be much fun
It's been the right decision to take the eCPPT before the OSCP!
The CTP is indeed very intimidating...you really have to like pain to enroll for it...so what are you waiting for ? go for it
Well I'll skip the CEH for now, let's have a look how I'm doing after the eCPPT.
Logged
eCPPT, HP ASE (Networking), LPIC-1, OSCP, WCSP
www.inshell.net
xXxKrisxXx
Hero Member
Offline
Posts: 512
Re: My roadmap to InfoSec
«
Reply #6 on:
January 02, 2012, 12:07:00 PM »
Hi MrTuxracer,
Excellent to hear you enrolled. Your going to have a blast! If you run into a bind, don't forget about their
forum
for students. Plus were here to help on our end. There is a few of us here who have taken either the student or pro course with eLS so never hesitate!
Until I reach the level of masochist is the only time I'll be fully prepped to enroll in CTP. It's definitely on my list of, 'To do things in 2012'. I just need to go back through the PWB material and knock out the BoF extra miles and prep on Exploit-DB before officially going in.
Goodluck on your journey, may the force be with you!
Logged
eCPPT, GCIH, OSCP, OSWP
vp75
Jr. Member
Offline
Posts: 78
Re: My roadmap to InfoSec
«
Reply #7 on:
January 04, 2012, 03:39:25 PM »
Quote from: MrTuxracer on January 02, 2012, 11:10:10 AM
Hi xXxKrisxXx,
I just enrolled for the eCPPT and started to study on it. The study material is quite good and organized and there are a lot of interesting new things in it. I do not have regrets about this purchase - looks like this gonna be much fun
It's been the right decision to take the eCPPT before the OSCP!
The CTP is indeed very intimidating...you really have to like pain to enroll for it...so what are you waiting for ? go for it
Well I'll skip the CEH for now, let's have a look how I'm doing after the eCPPT.
Hi Mr.Tuxracer,
I'm in the same course, except joined during christmas....
Probably might meet in community
there...
V
Logged
eCPPT
MrTuxracer
Newbie
Offline
Posts: 43
Re: My roadmap to InfoSec
«
Reply #8 on:
January 06, 2012, 08:44:12 AM »
Quote from: vp75 on January 04, 2012, 03:39:25 PM
Hi Mr.Tuxracer,
I'm in the same course, except joined during christmas....
Probably might meet in community
there...
V
Great one, isn't it ?
Nice, message me if you like
Logged
eCPPT, HP ASE (Networking), LPIC-1, OSCP, WCSP
www.inshell.net
isgillen
Newbie
Offline
Posts: 3
Re: My roadmap to InfoSec
«
Reply #9 on:
January 09, 2012, 05:08:28 AM »
eCPPT is a good choice to start with, I was new to security and it takes you from a noob to having a good understanding.
the course assumes that you have a basic knowledge of programming but i would suggest you need to have a bit more than basic if you intend to do the professional course straight away also TCP/IP.
They do offer a student course prior to the pro but i decided to go straight in at pro and was pretty comfortable. A plus point about the eCPPT is that they offer you a whole module on scripting which it not the norm but very beneficial.
The forums are very helpful and there is always someone there that will answer your questions.
The only downside is that there are some grammatical errors and a few slide early on do get a little confusing because the examples they use do not exist in the real world so you cant follow them. The staff are aware of this and are addressing it.
The future for eCPPT look promising and there are changes happening all the time. The best thing is that one you have paid up once you get life time access to both forums and course material so you can always stay up to date what ever changes they make. They also offer discounts to current members on anything new they try and listen to suggestions from the community.
Hope this helps in your decision, good luck
Logged
3xban
Hero Member
Offline
Posts: 608
Re: My roadmap to InfoSec
«
Reply #10 on:
January 10, 2012, 08:55:53 AM »
Wow, eCPPT is pretty affordable. I actually may sign up for that this month. I like the idea of life time access. I think I will try the demo and see how I like it. Judging by the responses here it seems to be a good prep for getting a head start in OSCP.
Logged
Certs: GCWN
(@)Dewser
coding_fury
Newbie
Offline
Posts: 1
Re: My roadmap to InfoSec
«
Reply #11 on:
January 10, 2012, 06:25:41 PM »
Hello everyone,
I heard a lot of good things regarding eCPPT (in this thread and elsewhere). However when going to elearnsecurity website, I stumbled on this page for
penetrating testing pro
. Is it just me or it looks like a really bad sham-wow tv commercial ? I expected to read "but wait! if you order right now we double up the offer!" at any time. I'ld like some feedback for people that actually did the course (PTP and eCPPT exam) to see if my worries are founded or not.
Also, is it possible to spend between 20-30 hours at most per week studying /practicing and still make the exam in the 120 days ? I presume it depends a lot on where you start but I'ld like an opinion.
Thank you,
Logged
xXxKrisxXx
Hero Member
Offline
Posts: 512
Re: My roadmap to InfoSec
«
Reply #12 on:
January 10, 2012, 06:34:42 PM »
Hello coding_fury,
Welcome to EthicalHacker.net. After checking out that page, it mainly seems like they're just trying to recommend/sell their course. Being a PTP alumni, I can confirm the course is legit.
You can definitely get the exam completed if you put in that many hours per week studying. You could even start practicing on the exam prior to officially starting your time to pen-test it (meaning you'll be given your exam target with eLS PTP credentials, and details on what needs to be done).
Kris
Logged
eCPPT, GCIH, OSCP, OSWP
gromic
Newbie
Offline
Posts: 38
Re: My roadmap to InfoSec
«
Reply #13 on:
January 11, 2012, 03:06:03 PM »
Hi Tuxracer! Welcome to the forum!
Congrats on enrolling in eCPPT... I am also planning to sign up for the course shortly. Actually I wanted to do that already in december, but since you can defer the lab time only for 90 days once you bought it... and I will be really busy till april ... I haven't done it yet... Hopefully the next couple of weeks
Time ...time...time... it's always the issue...
@coding_fury
I know the site sometimes looks like a "I make you rich quickly page". Next to what kris said... from what you read around here it must be a really good course...
Logged
Thinking .... Please Wait...
MrTuxracer
Newbie
Offline
Posts: 43
Re: My roadmap to InfoSec
«
Reply #14 on:
January 12, 2012, 03:34:19 AM »
Hi gromic,
Thanks. It's been a good investment so far, and as far as I can say now, I don't need 120 days to complete the whole course. I think, it's quite a good preparation for the offensive-security courses.
@coding_fury / @3xban:
I agree...the website is not looking very serious, but the members-area and the course pages are well-made and a great benefit for someone who's new to the pentest topic.
Logged
eCPPT, HP ASE (Networking), LPIC-1, OSCP, WCSP
www.inshell.net
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Editor-In-Chief
: Special Xmas Deal: 10% Off eLearnSecurity Courses
(3) by
hekvvddtest
Greetings
: Hello
(6) by
hekvvddtest
Greetings
: Obtain The Scoop On mulberry bags Before You Are Too Late
(13) by
hekvvddtest
Calendar Of Events
: HITBSecConf2013 – Amsterdam
(9) by
hekvvddtest
Special Events
: [Article]-Webcast: Deep Dive into Red Teaming with the Metasploit Framework
(19) by
hekvvddtest
Network Pen Testing
: HackaServer - Anyone tried it?
(4) by
hekvvddtest
Greetings
: Good day ...
(7) by
hekvvddtest
Gates
: Chris Gates' Blog RSA Finalist
(5) by
hekvvddtest
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(1) by
hekvvddtest
General Certification
: nth topic on Career Advice
(9) by
hekvvddtest
General Certification
: Direction
(5) by
hekvvddtest
Hardware
: Discreet Hacking Devices
(8) by
hekvvddtest
Calendar Of Events
: CanSecWest 2013
(5) by
hekvvddtest
Forensics
: Burn Note
(5) by
hekvvddtest
Calendar Of Events
: Cyber Readiness Challenge - Rome
(1) by
hekvvddtest
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(0) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(0) by
prats84
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(27) by
don
Greetings
: Hi from the UK
(2) by
n37sh@rk
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.