Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 33 guests online
 
Advertisement

You are here: Home arrow Resourcesarrow Career Centralarrow Pen Test Interview Soon
EH-Net
May 21, 2013, 05:18:31 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Pen Test Interview Soon  (Read 5160 times)
0 Members and 1 Guest are viewing this topic.
variable
Newbie
*
Offline Offline

Posts: 2


View Profile
« on: April 25, 2012, 02:50:13 PM »

I have an interview lined up for a pen testing job next week.  I do have a computer security background but I am relatively new to pen testing.   I was told there will be a virtual box setup that i am suppose to compromise and then writeup a report when im done scanning/testing/hacking.   My question is what sort of tools/preparation would you take into an interview like this?   What sort of criteria would YOU want to see on a report.  Any advice is helpful. 
Logged
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1057


aka dynamik


View Profile WWW
« Reply #1 on: April 25, 2012, 02:57:54 PM »

Can you bring BackTrack in? That should provide more than you need to do the tasks at hand.

This is a great resource for a report template: http://www.offensive-security.com/offsec/sample-penetration-test-report/

Do you have any specific questions on the process? There's unfortunately no secret that will magically make you a pen tester in a matter of days.
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« Reply #2 on: April 25, 2012, 03:01:43 PM »

Were you told to bring your own system to attack from or will that be provided for you?

Certainly, in addition to the technical skills, they will want to see how well you can report on it. I would recommend reading this blog post:
http://pen-testing.sans.org/blog/2012/02/09/maximizing-value-in-pen-testing

I would want to see that you can summarize the findings in a non-technical summary and that you can present the risk appropriately. I would want to see what your thought process is on how you rate risks - in other words, for this purpose, I wouldn't care what you rated findings so long as you provided thoughtful support. I would also be looking at how you tell me to fix the problem.
Logged
variable
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #3 on: April 25, 2012, 03:21:08 PM »

As far as I know I cant bring in a system.  It will be a lab enviroment with a VM windows machine at a logon prompt and anything goes from there.  Its just a basic test to see if you can bypass authentication, gain root, find what services are running and wheter or not you can compromise them.  The more prepared the better off I am.  What interview questions would you ask someone for a entry level pen-test job?
Logged
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1057


aka dynamik


View Profile WWW
« Reply #4 on: April 25, 2012, 03:40:34 PM »

Start with this: http://resources.infosecinstitute.com/ideal-skill-set-for-the-penetration-testing/

And review an alternate perspective: http://www.thehackeracademy.com/the-key-skill-set-of-great-penetration-testers/

And as Bill alluded to, the most important thing is your thought process and cognitive capabilities. It's relatively easy to remedy technical gaps of knowledge, but it's much more difficult to improve someone's problem solving skills.

That test sounds odd. You're just sat in front of a single Windows system, and there's no attack system? Maybe they're testing you to see how prepared you are. Bring in a bootable Backtrack USB thumb drive and know how to add/change Windows accounts once booted to that (obviously make sure that's allowed).
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
Agoonie
Full Member
***
Offline Offline

Posts: 176



View Profile WWW
« Reply #5 on: May 11, 2012, 09:03:16 AM »

I have an interview lined up for a pen testing job next week.  I do have a computer security background but I am relatively new to pen testing.   I was told there will be a virtual box setup that i am suppose to compromise and then writeup a report when im done scanning/testing/hacking.   My question is what sort of tools/preparation would you take into an interview like this?   What sort of criteria would YOU want to see on a report.  Any advice is helpful. 

How did the interview go?  Was it everything you thought would happen or did they through surprises during the interview?
Logged

OSCE, OSCP, OSWP, CISSP, GPEN

www.agoonie.com
impelse
Hero Member
*****
Offline Offline

Posts: 565


View Profile WWW
« Reply #6 on: May 12, 2012, 06:34:00 PM »

When I was reading this post, I was expecting to see the result of the interview.lol

Logged

CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training

Website: http://blog.thehost1.com/
3xban
Hero Member
*****
Offline Offline

Posts: 607


View Profile WWW
« Reply #7 on: May 14, 2012, 09:57:17 AM »

I know, left us hanging and all.
Logged

Certs: GCWN
(@)Dewser
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.055 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.