Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 41 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Other
From Web Developer to Penetration Tester
EH-Net
May 22, 2013, 02:02:28 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Other
(Moderator:
don
) >
From Web Developer to Penetration Tester
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: From Web Developer to Penetration Tester (Read 8234 times)
0 Members and 1 Guest are viewing this topic.
moosa
Newbie
Offline
Posts: 5
From Web Developer to Penetration Tester
«
on:
March 15, 2012, 09:27:39 AM »
Hello EH!
i am a web developer having an experience of 5+ years. I started hacking into boxes as a script kiddie. Went for a CEH and CISSP training. But may be i was over confident and went directly for a CISSP exam which i failed. Web development is something is started when i was 14. Now i wanted to get back to the penetrating testing ethical hacking. I need suggestions on how i can pursue my career in info-sec, i m currently working as a web administrator but still my passion is in info-sec domain. All suggestions are welcomed.
P.S i am now a days trying to get some experience in Backtrack5
Cheers
«
Last Edit: March 15, 2012, 09:32:57 AM by moosa
»
Logged
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: From Web Developer to Penetration Tester
«
Reply #1 on:
March 15, 2012, 09:39:47 AM »
Welcome to the forums
It seems like the most logical / natural route would be to get into web application hacking. What technologies are you working with for your web development and administration responsibilities?
This would be a good starting place, if you haven't seen it yet:
http://www.amazon.com/The-Web-Application-Hackers-Handbook/dp/1118026470/ref=sr_1_2?ie=UTF8&qid=1331822345&sr=8-2
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
vp75
Jr. Member
Offline
Posts: 78
Re: From Web Developer to Penetration Tester
«
Reply #2 on:
March 15, 2012, 12:15:57 PM »
Hi
Try checking eCPPT certification, It will be a good place to start rather jumping more advanced stuff....
Cheers
V
Logged
eCPPT
3xban
Hero Member
Offline
Posts: 608
Re: From Web Developer to Penetration Tester
«
Reply #3 on:
March 15, 2012, 12:53:15 PM »
CEH and CISSP give management and HR warm and fuzzies. CISSP requires a bit more work than say CEH as far as knowing material. They both cover a lot but they cover different areas. CEH covers the pen testing aspects, but not necessarily in detail. CISSP covers a number of domains and in order to maintain the CISSP you need to have a certain amount of exerpience in some of those domains. There are also a number of changes being made to the cert which you should read up on.
eCPPT would be a good choice for a decent technical cert. Becoming familiar with OWASP and joining a local OWASP chapter will get your foot in the door with the community. Maybe look into companies like Veracode who do Application testing, see what their requirements might be for App pen testers.
Good luck!
Logged
Certs: GCWN
(@)Dewser
cd1zz
Hero Member
Offline
Posts: 561
Re: From Web Developer to Penetration Tester
«
Reply #4 on:
March 15, 2012, 08:48:36 PM »
Your background will suit you nicely for that piece of pen testing. Don't be discouraged by failing CISSP, work on your technical skills first. Try to contribute to the community in some way so you have a leg to stand on when you're interviewing. Since web dev is your forte, you might want to consider knocking out the GWAPT.
Logged
OSCE | OSCP | GXPN | OSWP | CISSP
http://www.pwnag3.com
http://www.networkadminsecrets.com
moosa
Newbie
Offline
Posts: 5
Re: From Web Developer to Penetration Tester
«
Reply #5 on:
March 16, 2012, 12:55:21 PM »
I really appreciate all your suggestions. I agree with u guys that Web Pentesting is what i should pursue and OWASP is what which can get me into community scene. But can i make the best use of Backtrack as in my region backtrack is recognized widely. So will it be possible to go for OSCP with the knowledge i have or can i get that kind of knowledge with self study which is needed to get OSCP. Currently i am working with html, css, jquery, wordpress, apache, mysql, ftp server and mercury. I know about vmware and stuff currently m having bt5 win2000 win 2003 metasploitable and other vuln machines on my vm. Other than that SQL injection is something i am very comfortable with.
Cheers
Logged
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: From Web Developer to Penetration Tester
«
Reply #6 on:
March 16, 2012, 01:19:43 PM »
Have you reviewed the syllabus?
http://www.offensive-security.com/documentation/penetration-testing-with-backtrack.pdf
It sounds like you'll probably be short on the systems and networking side of things. You could either identify your weak areas in advance or research unfamiliar items as you go through the course. The only downside of the later approach is that you'll be doing that instead of making use of the lab time you're paying for.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
BillV
Hero Member
Offline
Posts: 1892
Re: From Web Developer to Penetration Tester
«
Reply #7 on:
March 16, 2012, 01:57:37 PM »
Not sure when, or if (though probably after BlackHat), Offensive Security will be releasing this in online form but this sounds like something that would interesting you:
OffSec Advanced Web Attacks
Logged
vp75
Jr. Member
Offline
Posts: 78
Re: From Web Developer to Penetration Tester
«
Reply #8 on:
March 17, 2012, 07:09:40 AM »
Hi
Don't take me wrong, I have been in IT working as Dev for 8+yrs and Testing another 6+years, On looking at OSCP syllabus, I personally felt it might be too much for me (Again Its ME) so preferred to look at eCPPT and from there slowly understand myself on more by reading (blogs) and practicing in my own lab. By this I will reach a comfortable level to go for OSCP.
There are EH members who has taken OSCP directly, I believe its all to do with passion on the subject and commitment to work on OSCP lab.
So it depends on your commitment to the subject and learning capacity as every individual is different.
Goodluck
V
Quote from: moosa on March 16, 2012, 12:55:21 PM
I really appreciate all your suggestions. I agree with u guys that Web Pentesting is what i should pursue and OWASP is what which can get me into community scene. But can i make the best use of Backtrack as in my region backtrack is recognized widely. So will it be possible to go for OSCP with the knowledge i have or can i get that kind of knowledge with self study which is needed to get OSCP. Currently i am working with html, css, jquery, wordpress, apache, mysql, ftp server and mercury. I know about vmware and stuff currently m having bt5 win2000 win 2003 metasploitable and other vuln machines on my vm. Other than that SQL injection is something i am very comfortable with.
Cheers
Logged
eCPPT
MaXe
Hero Member
Offline
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: From Web Developer to Penetration Tester
«
Reply #9 on:
March 20, 2012, 02:13:59 PM »
Don't forget to do some preliminary study and perhaps research, and if you haven't already checked out some of my blogs, check this out:
http://www.exploit-db.com/category/maxe/
There's also tons of information here, but also on the InterN0T forums:
http://forum.intern0t.org/forum.php
and many others as well. Just be aware that not all guides are high quality guides, some are even incorrect and many, teaches you only the basics (of the basics sometimes), but InterN0T is a free and good place to start.
There's even threads about coding securely, how to identify the vulnerabilities in the code, e.g., in this thread:
http://forum.intern0t.org/offensive-guides-information/1382-finding-vulnerabilities-php-sirgod.html
(which was originally posted there, before it was distributed to all the other websites. Please keep in mind that it was SirGod who wrote this.)
You can also find really good proof of concept's and possibly guides by RGod aka RetroGod, and well, this is not one of the resources I have shared often, but this one will help you (and hopefully many others too) quite a lot:
http://www.blackhatacademy.org/security101/Web_Exploitation
There's plenty of web labs, both open source and commercial. I haven't tried many web app labs, but MDSec Labs are very heavy, and you may want to study the "Web Application Hacker's Handbook Second Edition" first (I'd say it's almost a requirement, but also to get the best experience), and the first edition of this book may be good as well.
What is important to keep in mind, that the MDSec Labs has a lot of content, and extreme amounts of variations of the same attack (haven't seen this in other labs), but there aren't cool things like:
http://www.exploit-db.com/vbseo-from-xss-to-reverse-php-shell/
, but there's a lot of nice things you can learn in there, including how to use Burp for a lot more tasks.
I did 4˝ Labs, and it was a nice experience. The first 2 labs were piece of cake, but fun to do. I am planning on doing the rest of the labs, before making a complete review with good "details" (not actual solutions of course, just how I think the labs are), and the price is not bad. I used 5 credits for those 4˝ labs, but I spent my time well and knew web app sec before playing in there.
So, with that being said, I hope you'll enjoy becoming a Penetration Tester, this is just the web app sec side, if you want to learn exploit development (for binary programs, etc.) then Corelan.be is one of the best places to go to.
If you want a nice overall, broad and deep certification, it's OSCP. I know you may think you'll save money on just doing OSCE, but that's very close to actual exploit development (such as 0days), and very targeted, so it is within pentesting, but it's not very broad compared to OSCP which is good for anyone
SANS courses, if you don't pay yourself, go for them. If you do, start with Offensive Security, or eLearnSecurity (Even though they're heavily web app sec focused, at least their exam is).
That's some of my best recommendations I can give for now
Logged
I'm an InterN0T'er
moosa
Newbie
Offline
Posts: 5
Re: From Web Developer to Penetration Tester
«
Reply #10 on:
March 21, 2012, 06:06:00 AM »
I really understand the fact that i will be short on systems and networking side. And yea i can not just go study for 30 days and yea i am done with OSCP. I believe if i will prepare myself properly with self reading stuff for which i have no deadlines as i am right now working on a development side which is not related to security so i am not practicing security on my job that is the only thing which keeps me away from security. Because after working 13 hours daily i am not able to get hold on sec side. So my final thought is i should study all the material recommend by you guys, and slowly i will make my way to sec first. My major subject would be Web Pentest but i will also study overall pen-testing tools. Once i will be able to exploit/hack all the major vuln vmware machines i should think that i am now aware of all the tools. I will try to use BT5 for all type of attacks instead of My Host OS Win 7. As i have to pay for my certs. I will invest on OSCP once i am sure. And this forum is going to help me for my assessment
. n yea i always appreciate EH Suggestions
Please Correct me if i am wrong some where. I guess there is no such restriction or need to have any cert before OSCP.
Cheers
Logged
MaXe
Hero Member
Offline
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: From Web Developer to Penetration Tester
«
Reply #11 on:
March 21, 2012, 02:57:37 PM »
Almost anyone can sign up for OSCP, but they don't accept free e-mail providers, and some countries may be blocked from buying the courseware due to copyright laws in those countries, or because of previously leaked courseware from those countries.
OSCE has a challenge you have to pass, it's quite fun, but also a bit hard, especially if you're a beginner, then I wouldn't recommend spending too much time on it in case you get stuck.
But if you want to try it out one day:
http://fc4.me/
(Just keep in mind it's for OSCE, not OSCP and it's meant to make sure you know enough before doing the course.) Doing the challenge doesn't force you to sign up for the course, so feel free.
I'm sure that you can sign up for OSCP without much trouble, keep in mind they have "slots" due to they don't put too many students in their labs at the same time, so plan ahead as you may have to wait a month before you can enter their labs.
Logged
I'm an InterN0T'er
Agoonie
Full Member
Offline
Posts: 176
Re: From Web Developer to Penetration Tester
«
Reply #12 on:
March 22, 2012, 10:51:50 AM »
As you are researching and learning more, maybe you can try incorporating it at your current position if you have not already. There are others here who did that same thing to move into the security field. Maybe do research on the web applications you are currently developing and do vulnerability assessments on them. You can make reports on what you find and try to explain it to others.
As far as certifications go, at some point, I would still continue to study for the CISSP. It helps with learning laws for security issues and other non-technical issues. It also seems to please HR for some reason.
In addition, I would go for the OSCP asap. It gives enormous amounts of technical knowledge for pentests. It will also expand your knowledge as far as the process of a pentest. You can work on the soft skills also. The course helps with making pentest reports.
I remember Mike Murray talking a lot about that: (
http://www.thehackeracademy.com/blog/
). The OSCP pentest report is a good process to go through since a lot of other security courses do not talk about it. It is very time consuming and requires you to know, not only about the vulnerability, but also, its solution or workaround. My 2cents.
Logged
OSCE, OSCP, OSWP, CISSP, GPEN
www.agoonie.com
moosa
Newbie
Offline
Posts: 5
Re: From Web Developer to Penetration Tester
«
Reply #13 on:
April 09, 2012, 02:07:42 AM »
I tried
http://fc4.me/
and after spending few mins I was only able to find the JS files embedded with the page, Whats inside the page makes me confuse i got an idea that the password is encrypted but i was unable to decrypt it. So yea it means i am still a newbie
..
Agoonie, yes now i am doing the same i am researching about it from my work. When i get free time i am planning to go for a pen-test as my company don't want me to do that i will just go for it and once I will find something very vulnerable will show them the report to make them aware how important it is. Other than that the book which I think will be very helpful if i will buy one is
http://www.amazon.com/BackTrack-Assuring-Security-Penetration-Testing/dp/1849513945
What do u guys think about this Book? is it ok for a newbie to jump into it. I will appreciate all the Ehackers suggestions...
Logged
Agoonie
Full Member
Offline
Posts: 176
Re: From Web Developer to Penetration Tester
«
Reply #14 on:
April 09, 2012, 07:54:24 AM »
Quote from: moosa on April 09, 2012, 02:07:42 AM
I tried
http://fc4.me/
and after spending few mins I was only able to find the JS files embedded with the page, Whats inside the page makes me confuse i got an idea that the password is encrypted but i was unable to decrypt it. So yea it means i am still a newbie
..
Agoonie, yes now i am doing the same i am researching about it from my work. When i get free time i am planning to go for a pen-test as my company don't want me to do that i will just go for it and once I will find something very vulnerable will show them the report to make them aware how important it is. Other than that the book which I think will be very helpful if i will buy one is
http://www.amazon.com/BackTrack-Assuring-Security-Penetration-Testing/dp/1849513945
What do u guys think about this Book? is it ok for a newbie to jump into it. I will appreciate all the Ehackers suggestions...
I would not do a pentest on your company without their (written) consent. You want to make sure you are covered in case something goes wrong. You could be liable and no one likes fines or prison. Can you just convince your company that they need a vulnerability assessment first, which would not be very intrusive or disrupt your environment? If that goes well, maybe they would be open to have you do the penetration test (legally).
I think it is a good book to start with but just make sure you do not stop there. You will find that you will be looking at many books from now on. I just keep a fund every year since I know I will be spending about $250-500 on books. Also, search online, most of the knowledge you will need is already online for free. Just to name a few:
http://www.ethicalhacker.net
(Try skillz challenges too)
http://infiltrated.net/TechnicalSecurityRoadmap.html
http://www.securitytube.net/
http://forum.intern0t.org/forum.php
http://www.crackmes.de/
http://www.irongeek.com/
http://www.hackthissite.org/
https://www.corelan.be/
http://www.offensive-security.com/metasploit-unleashed/Main_Page
http://www.backtrack-linux.org/forums/forumdisplay.php?f=143
http://code.google.com/p/pentest-bookmarks/wiki/BookmarksList
http://www.secmaniac.com/
http://www.pwnag3.com/
http://insidetrust.blogspot.com/
http://www.madirish.net/
http://blog.zeltser.com/
http://krebsonsecurity.com/
Logged
OSCE, OSCP, OSWP, CISSP, GPEN
www.agoonie.com
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: Ruby on Rails Vulnerabilities/Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
Network Pen Testing
: AIX Vulnerability Assessments
(1) by
3xban
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.