Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 43 guests online
You are here:
Home
Resources
Career Central
Becoming a Pentester
EH-Net
May 18, 2013, 03:41:35 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Resources
>
Career Central
(Moderator:
don
) >
Becoming a Pentester
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Becoming a Pentester (Read 5376 times)
0 Members and 1 Guest are viewing this topic.
Sam Kennedy
Newbie
Offline
Posts: 5
Becoming a Pentester
«
on:
June 17, 2012, 02:19:41 PM »
I still have a couple of years to decide, but right now I'm thinking about a job as a pentester.
I live in the UK, so was hoping for advice specific to jobs in this country.
What path do I need to follow in order to get a job? Which qualifications will I need (The OSCP and OSCE courses look particularly interesting), which courses should I think of taking at University?
I've looked at the ethical hacking course at my local uni, but it seems more like a computer science course with a couple of security modules thrown in, I doubt it would teach anyone to actually hack, I'll do a bit more research but it looks pretty weak.
Is there any way to get experience now? Such as voluntary work etc.?
Thank You
-Sam Kennedy
Logged
UNIX
Hero Member
Offline
Posts: 1234
Re: Becoming a Pentester
«
Reply #1 on:
June 17, 2012, 02:51:53 PM »
If you are located in the UK, you should take a look at CREST, CHECK and Tiger Scheme.
To get your hands dirty, you could play around with some premade vulnerable images, such as
DVL
,
De-ICE
,
DVWA
,
WebGoat
,
Metasploitable
, etc.
To which university are you referring to?
Is there a specific field in IT security that you are interested in?
Logged
Sam Kennedy
Newbie
Offline
Posts: 5
Re: Becoming a Pentester
«
Reply #2 on:
June 17, 2012, 03:49:49 PM »
I've used Metasploitable and WebGoat, but I haven't used any of the others, looks like I will be very busy, thank you
I was referring to Northumbria University, however I will partly retract my previous statement, it looks like it will build a good foundation, but it doesn't look like it would prepare someone for hacking a real network.
I'm not sure on a specific field, I've lately enjoyed playing around with buffer overflows, and written a generic return address brute force tool. I found it really interesting, however I don't know which field this would be included in.
I also enjoy the whole process of penetration testing, from gathering information through to exploitation and covering tracks.
How does the metasploitable server compare to real world targets? It seemed way too easy, which do you think would give the best feel for testing the security of a real company?
Thank You
-Sam
Logged
UNIX
Hero Member
Offline
Posts: 1234
Re: Becoming a Pentester
«
Reply #3 on:
June 18, 2012, 03:04:00 AM »
Quote from: Sam Kennedy on June 17, 2012, 03:49:49 PM
I was referring to Northumbria University, however I will partly retract my previous statement, it looks like it will build a good foundation, but it doesn't look like it would prepare someone for hacking a real network.
I'd just concentrate on the basics and concepts - attacking a target will be much easier then and feels more natural. If one understands the very basics, understanding attack vectors on top of it shouldn't be much of a problem.
Quote from: Sam Kennedy on June 17, 2012, 03:49:49 PM
How does the metasploitable server compare to real world targets? It seemed way too easy, which do you think would give the best feel for testing the security of a real company?
I haven't played around with Metasploitable 2, but personally I don't think that any premade vulnerable image can mimic a real target/network/infrastructure 100%. As you said, they are usually rather easy to root and aim to demonstrate specific attack vectors. Of course you will find in real pentests low-hanging fruits as well or can use a single exploit to do a mass pwnage, but often it's much more complicated or needs multiple stages of exploitation in order to get to your desired data.
If you meet the
requirements
you will most probably enjoy the labs from Offensive Security.
Logged
Sam Kennedy
Newbie
Offline
Posts: 5
Re: Becoming a Pentester
«
Reply #4 on:
June 18, 2012, 12:25:05 PM »
I didn't see a list of requirements on the website (I have seen them posted somewhere though)
Looking at the syllabus, I'm comfortable with the majority of the content, I don't think I would have any problems with the course (other than paying for it haha)
My exams will be over shortly, I will see if I could get any IT/network related jobs over the summer just to get experience.
Logged
UNIX
Hero Member
Offline
Posts: 1234
Re: Becoming a Pentester
«
Reply #5 on:
June 18, 2012, 12:38:49 PM »
I was just referring to this:
Quote
Penetration Testing with BackTrack is an entry-level course but still requires students to have certain knowledge prior to attending the class. A solid understanding of TCP/IP, networking, and reasonable Linux skills are required. This course is not for the faint of heart; it requires practice, testing, and the ability to want to learn in a manner that will grow your career in the information security field and defeat any learning plateau.
Logged
Sam Kennedy
Newbie
Offline
Posts: 5
Re: Becoming a Pentester
«
Reply #6 on:
June 18, 2012, 02:52:33 PM »
Oh Yeah, I guess I meet those requirements. I'm definitely going to give this a go even if I don't end up with an information security related job, from what I've read it sounds really fun!
Logged
smokey
Newbie
Offline
Posts: 1
Re: Becoming a Pentester
«
Reply #7 on:
July 29, 2012, 01:23:15 PM »
I also am hoping to get a job as a pen tester one day. I'm majoring in computer science at the local university. I'm still taking my core requirements, not into the actual cs stuff just yet, although I will be taking 1 class this fall on sql programming. I'm just reading books at home and I have set up an old computer and am running it as a server and trying out things on it that I'm learning from my books. Right now I'm reading "The Basics of Hacking and Pen Testing" by Pat Engebretson. I also have Ninja Hacking which I haven't gotten started in yet. I hope to teach myself a bit of the security stuff as I go through college since they don't offer a security major here. Then after I finish my bachelors I may enroll somewhere and work on getting my masters in security. I'm just working with what's available to me, so hopefully, I'll be able to make it all work out for me. Good luck to you Sam Kennedy in your journey to becoming a pen tester! I hope you are successful!
Logged
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Becoming a Pentester
«
Reply #8 on:
July 31, 2012, 03:27:12 AM »
Hi Sam,
I know a few that went through the Northumbria Uni course (unfortunately I graduated before this course was available), some mixed opinions, but it should provide a good foundation. If you're staying local to the NE, let me know and I can make some introductions/suggestions to the local IT scene if of interest.
Degree aside, I'd definitely take a look at the OSCP course as it provides a good technical foundation across most common tools and attack vectors. After that, the TigerScheme QSTM can build on the basics, whilst providing an accreditation which is valued by employers/clients within the UK market.
Good look going forwards.
Andrew
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
Jamie.R
Sr. Member
Offline
Posts: 429
Re: Becoming a Pentester
«
Reply #9 on:
August 06, 2012, 10:09:27 AM »
Hi Sam,
I would say do a course in security if you can there are a lot of places that offer good security course in the UK.
I would also try get involved and make contact by attending events in the UK if you can afford it go to 44con.
CREST adn TIGER are the main cert you want to get in the UK but they come in at pretty price I think to get team member for Tiger its about 2k.
There are lots cool website that contain free information and lots of security groups. If you dont have one already build your own lab to pratice any skills you gain.
Hope this helps......
Logged
OSWP | Hackingdojo Nidan | eCPPT
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Web Applications
: Nessus and Nikto
(4) by
Seen
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(4) by
impelse
Tutorials
: Need guidance
(7) by
impelse
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.