Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 97 guests and 1 member online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow General Certificationarrow need advice: which cert to go for
EH-Net
May 23, 2013, 10:39:58 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: need advice: which cert to go for  (Read 2960 times)
0 Members and 1 Guest are viewing this topic.
kriss332
Newbie
*
Offline Offline

Posts: 5


View Profile
« on: June 12, 2012, 04:44:05 AM »

Hello to  all,
     
     Well, this is my first post and a question about what to do. Presently I want to get OSCP or any equivalent cert madly. So that i could get into ifosec field.  Further plans laterz.  About my present condition:-
   
     I have started to learn everything that could help me get Certs. I already learnt C,C++, CCNA. Presently learning RH linux, Python and MS Servers (all through Cbt Nuggets). And I started all this 1 year back. I have once prepared for CEH but later I dropped the idea about CEH cert.
      I have a good grasping power, provided I get good study material. The wholesole resource of my study material is Torrents only. . 
 
     I want to get advice from all of u on what all things i should opt. OSCP is is quite hard for newbies. So before opting for it i want to get a deep
understading of everything.
     e-learning security course material is also not available on torrents. I have seen SANS security stuff on torrents. Any stuff anybody would suggest worth studying? Plz keep in mind that in my country $ has a high price. I cant signup a course just for learning.I can spend on certs only. Moreover i have got 7 yrs remaining in my job. By that time i want to get to an expert level. So plz suggest the needed path. Welcome to all advices. Thanks...Kriss332
Logged
jason
Hero Member
*****
Offline Offline

Posts: 1012



View Profile WWW
« Reply #1 on: June 12, 2012, 08:52:32 AM »

Quote
The wholesole resource of my study material is Torrents only

*Sigh* My first suggestion would be to stop stealing the results of other folks hard work. This is the Ethical Hacker Network and these sorts of things are frowned upon around here. As an author, this particularly makes my blood boil.

Secondly, sitting around and watching security videos so you can accumulate more certs (I'll assume there are some braindumps involved here as well) isn't going to get you anywhere. The first time you have to sit for an actual technical interview you'll go to pieces. You need to jump in and get some real hands-on time with the tools and technologies and apply the concepts.
Logged
kriss332
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #2 on: June 12, 2012, 09:22:53 AM »

It is not about stealing others hardwork. I dont have good financial background, so that i could spend on gathering basic knowledge, sorry if it hurts u.well, today sombody can act like shouting on me, becoz i am seeking for guidance. But tomorrow if I master these things, I am going to welcome everybody open heartedly when someone asks for any help. Here i just wanted to ask for guidance about what to do,not for any help from anyone. I am capable of helping myself, thanx alot.
« Last Edit: June 12, 2012, 09:35:22 AM by kriss332 » Logged
Dark_Knight
Sr. Member
****
Offline Offline

Posts: 292


View Profile WWW
« Reply #3 on: June 12, 2012, 09:43:24 AM »

It is not about stealing others hardwork. I dont have good financial background, so that i could spend on gathering basic knowledge, sorry if it hurts u.well, today sombody can act like shouting on me, becoz i am seeking for guidance. But tomorrow if I master these things, I am going to welcome everybody open heartedly when someone asks for any help. Here i just wanted to ask for guidance about what to do,not for any help from anyone. I am capable of helping myself, thanx alot.

There really is no need for you to go on the defensive. The fact is that it is stealing. Even if you are not on sound financial footing there are several other options outside of torrents that can get you started.

Jason also offered you solid advice. Maybe its not what you wanted to hear.
Logged

CEH, OSCP, GPEN, GWAPT, GCIA
http://sector876.blogspot.com
kriss332
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #4 on: June 12, 2012, 10:27:09 AM »

Jason, dark_knight ! Thanks for posting. I understand i have to get into doing it all. I am absolutely ready for that. I have my own VM Ware lab for that. But i should know atleast what to choose. There are plenty of courses out there. But which one will suit me at this situation. Offcourse i will sign up for a security course. And seriously i have money saved for just that only. One bitter truth is that:-  torrent is stealing only. I accept it.
    Ok apart from this can someone suggest me the path? I'll be very grateful.
Logged
Dark_Knight
Sr. Member
****
Offline Offline

Posts: 292


View Profile WWW
« Reply #5 on: June 12, 2012, 11:25:51 AM »

Jason, dark_knight ! Thanks for posting. I understand i have to get into doing it all. I am absolutely ready for that. I have my own VM Ware lab for that. But i should know atleast what to choose. There are plenty of courses out there. But which one will suit me at this situation. Offcourse i will sign up for a security course. And seriously i have money saved for just that only. One bitter truth is that:-  torrent is stealing only. I accept it.
    Ok apart from this can someone suggest me the path? I'll be very grateful.

This should get you started:
http://infiltrated.net/TechnicalSecurityRoadmap.html#

Sil:
Quote
I think you need to pick your own poison and go from there. Think of security in terms of a baseball team. Here you are saying: "I want to play which position should I aim for?" What are your strengths and weaknesses. Focus on your weaknesses to bring them up to par with your strengths while in parallel upping your strengths.

In security, there are a lot of avenues to choose from. Forensics, pentesting, application security, cryptography, networking, etc. Each have their unique methodologies, technologies, protocols, pros and cons.

Examples:

++++++++++

Forensics. Where would you want to fit in? Working as an incident responder researching malware, researching e-Discovery, researching the cause of a compromise? What field? Pros: Banking, insurance, defense industries, huge Fortune 100s are always in demand for these types of individuals.

Cons: Job can be linear, stressful, repetitive.

Certifications: (real world relevant) GCFE, GCFA, EnCe, GCIH, ACE, CCE, GREM, WCNA (Wireshark), GCIA

++++++++++

Pentesting: Where would you want to fit in? Define pentesting. Too many companies have turned this field into a tool (Core Impact, Metasploit, Nessus, etc) however there is more to pentesting than running tools. In order to fit into a well rounded position, the document I linked you too will give you excellent foundations needed. You then need to progress into a more linear stage (focus on applications (which web application, business applications (SAP, etc)).

Pros: Can be fun, creative, non-linear (no two pentests are ever the same)

Cons: Industry has created too many retards that rely far too much on tools. Many industries are now mandated to have penetration testing (PCI requirement). With that stated, many companies are relying on point and click drop boxes (QualysGuard) and calling it a "pentesting day."

Certifications: (the ones that count) GPEN, CEPT, OSCP, OSCE, CPT, RWSP

++++++++++

Network security: Where would you want to fit in? Managing firewalls, IPS, IDS, DLP, acronym hell? Performing network analysis' with tools and hardware such as nGenius, Netwitness, Wireshark, etc., this can criss-cross the forensics realm.

Pros: ALL COMPANIES need network security period.

Cons: Can be as linear as in point A to point B

Certifications: (ones that count) WCNA, CC{N,D,S}P, GCIH, GSEC

++++++++++

Take note, all the certifications I listed are TECHNICAL, for those wondering why CISM, CISA, CGEIT, CISSP, etc isn't listed. And NO, the SSCP to me is not a technical cert. When I state "ones that count / relevant" I mean the ones you *truly* want to aim for as you WILL LEARN while getting them. Not to take anything away from say the C|EH, CHFI but it is what it is. I felt the certifications I listed would help you LEARN something as opposed to dumping a billion tools on your lap and telling you "hey this is a security tool, learn this tool's syntax and we will give you a shiny certificate!"

Your best bet regardless of any advice you see from me or anyone else is to determine something that you can enjoy while making money. I would hate to focus on Forensics only to have a job I hated doing e-Discovery 24x7x365. I know people that dread getting into the field. They work to dissect/analyze info, go to court, are stressed out as all hell. The money they make doesn't cover sanity, happiness.

Go over to Dice.com and check the markets for certs also. Search for the certification itself to see its demand and WHO is asking for that particular cert. That is a good baseline as is e.g:

http://www.payscale.com/research/US/Certification=Certified_Ethical_Hacker_%28CEH%29/Salary
http://www.payscale.com/research/US/Certification=SANS%2fGIAC_Security_Essentials_Certification_%28GSEC%29/Salary
http://www.payscale.com/research/US/Certification=SANS%2fGIAC_Certified_Intrusion_Analyst_%28GCIA%29/Salary
http://www.payscale.com/research/US/Certification=SANS%2fGIAC_Certified_Forensic_Analyst_%28GCFA%29/Salary
http://www.indeed.com/salary/q-Forensic-Consultant-Ence-l-New-York,-NY.html
http://www.indeed.com/salary?q1=GREM&l1=New+York%2C+NY

« Last Edit: June 12, 2012, 11:30:19 AM by Dark_Knight » Logged

CEH, OSCP, GPEN, GWAPT, GCIA
http://sector876.blogspot.com
kriss332
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #6 on: June 12, 2012, 12:37:36 PM »

Thanks a tonns DARK_KNIGT. U gave a heavenly direction. Thanks alot. One more question, if u have time.
    Is pentesting or hacking skill mandatory for gorensics and if yes, then upto what level? I love to learn pentesting skills but  I have a dream to go for forensics only. What would u suggest? Is forensics considered next step of pentesting/hacking or is it parallel on knowledge grounds?
   Thanks...
Logged
Dark_Knight
Sr. Member
****
Offline Offline

Posts: 292


View Profile WWW
« Reply #7 on: June 12, 2012, 01:42:24 PM »

Thanks a tonns DARK_KNIGT. U gave a heavenly direction. Thanks alot. One more question, if u have time.
    Is pentesting or hacking skill mandatory for gorensics and if yes, then upto what level? I love to learn pentesting skills but  I have a dream to go for forensics only. What would u suggest? Is forensics considered next step of pentesting/hacking or is it parallel on knowledge grounds?
   Thanks...
I wouldn't say pentesting is mandatory to get into forensics. The two are separate disciplines. What I will say though is that as a penester with forensics skills with no doubt set himself apart from the rest.
Logged

CEH, OSCP, GPEN, GWAPT, GCIA
http://sector876.blogspot.com
kriss332
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #8 on: June 12, 2012, 09:40:49 PM »

thanks a tonns DARK_KNIGHT. thanks alot. U really gave a very helpful advice. Thanks again.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.059 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.