Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 50 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow Introduction & a couple questions about becoming a pen tester
EH-Net
May 21, 2013, 07:06:05 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Introduction & a couple questions about becoming a pen tester  (Read 3835 times)
0 Members and 1 Guest are viewing this topic.
adroc
Newbie
*
Offline Offline

Posts: 4



View Profile
« on: October 11, 2012, 11:50:42 PM »

Hello EH.net,
I’m a long time lurker, first time poster. I have been reading EH.net for some time now and the folks here seem extremely knowledgeable, talented and friendly (which is hard to find now a day with the anonymity that the internet provides).

A little about me

I have been working as a linux admin for the past 6 years. I have a bachelor’s degree in CompSci(2003) and a masters in NetSec(2008) which I have not really been able to use at my current position, excluding the hardening of infrastructure, catching, cleaning up and stopping of attacks etc.. I have a decent understanding of networking and linux. I can understand and program a little in C, C++, Perl and BASH. I am also currently working my way through udacity.com CS101 and cs262 in order to gain some python knowledge.

Questions

In 2013, I have made it a goal of mine to find a job as a pen tester (net/web) and would love some advice from everyone here on how to make the move from linux admin into security. So my questions to the community are:

1)Which certs are a must have for someone with my background in order to break into this field?

I’m definitely going for the OSCP, since it just seems like it would be a blast.

2)How should I prepare for the OSCP? I would like to be as ready as possible for the class so I can spend 90% of my time in the labs instead of taking 1 month to go over all the material and then only having 1 month for the labs.

3)Which books are a must read for anyone in this field and to prepare for the certs you suggest in question 1?

So far I have bought and am reading through the following:
Advanced Penetration Testing for Highly-Secured Environments
BackTrack 4
Hacking The Art of Exploitation, 2nd Edition
Metasploit - The Penetration Testers Guide
Professional Penetration Testing
The Web Application Hacker's Handbook

4)What skills are a must have in pen testing/netsec?

5)Which websites/blogs are a must read for any pen tester?

I’m already subscribed to a ton but would like to know what everyone’s favorites are.

6)What free and good training material is out there?

Sorry about all the questions  Smiley I’m just a noob.
Logged
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1057


aka dynamik


View Profile WWW
« Reply #1 on: October 12, 2012, 01:02:36 AM »

Welcome to the forums.

I'm going to be brief with my responses because these types of questions have already been answered dozens of times elsewhere, and I encourage you to review those other threads because there's a wealth of information in them.

Job: It will probably be more realistic to land a full-time security position in 2013 than a pen testing position. You may get lucky, but your best course of action will probably be to ease into it a bit more. Landing a position that has the possibility of some internal pen testing activities will greatly help you get into a full-time pen testing position as well.

Certs: You don't need any. If you have demonstrable skills, you can get by without them. The OSCP is great, and the OSCE beyond that. OffSec also has a new web app course/cert that will hopefully be available sometime around the end of the year. SANS/GIAC GWAPT, GPEN, and GCIH are nice ones to have as well. Of course, the CISSP satisfies a check box for many places and helps you get past HR filtering.

OSCP: Most people are short on Linux experience, so you're probably in a better starting place than most. You'll learn the most by experimenting in the labs, so as long as you're comfortable with Linux, Windows, and networking, go for it. Reading through that book list of yours would certainly put you ahead of the curve though. Unless you have a lot of time to dedicate to the labs, you'll probably be best off registering for 90 days at the onset. 60 was a bit tight for me, and I compromised about 80-85% of the systems.

Books: Popular ones you're missing are Counterhack: Reloaded, the official NMap book, and the Wireshark book. The Coding for Penetration Tester's book is a nice one as well. That one helps you think outside the box and take control yourself, as opposed to just showing you how to use tools.

Skills: Besides the obvious, http://www.thehackeracademy.com/the-key-skill-set-of-great-penetration-testers/ and excellent writing skills. I spend about a third of my time writing reports. Internal QA and your clients do not want to suffer through poor grammar, usage, or spelling. Speaking skills to a lesser extent. I typically conduct a 30-60 minute exit interview at the conclusion of an engagement. As long as you can convey critical findings and corrective measures to a few people of varying technical levels, you'll be fine. Check out something like Toastmasters if you feel weak here.

Websites: A few of my favorites off the top of my head:
http://carnal0wnage.attackresearch.com/
http://www.irongeek.com/
http://g0tmi1k.blogspot.com/
http://www.securitytube.net/
https://www.corelan.be/
http://pentestmonkey.net/
http://www.room362.com/
http://www.pentestgeek.com/
http://www.darkoperator.com/
http://pauldotcom.com/

Paul from PDC publishes his list, if you want a quick way to jump-start your RSS collection: http://pauldotcom.com/PaulsFeeds.opml

Free Material: See above...

Get on Twitter as well, even if you don't participate. There's tons of interesting information getting tossed around regularly.

Well, I guess that wasn't so brief...
« Last Edit: October 12, 2012, 01:04:27 AM by ajohnson » Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
Cyber.spirit
Sr. Member
****
Offline Offline

Posts: 351


The World is sick, Save your mind...


View Profile
« Reply #2 on: October 12, 2012, 01:46:11 AM »

Hello and welcome Mr. Admin! And i hope u have great time here.

First of all i want to say something about linux i think its great for u to know because all of hackers needs it, so you'll have no problem with that. Also because of that linux becground and othe experiences which you've said you dont need to learn network basics too.

But another thing which i always recommend is virtualization i dont know if u know it or not but u will need to work with atleast virtual box however if u learn the concepts and vmware it will be better.

The next thing which i want to recommend u to learn is programming which is extremely required for exploitation. I suggest u to learn assembly and python and html (its so easy!).

About OSCP im planning to get it next year and all i know about it is so hard and much better than CEH.! You can find good info about it in offsec's website.

And i think one of great books to learn pentest is this:
www.amazon.com/gp/aw/d/1597494259/ref=redir_mdp_mobile

However u can find many books with a simple google search.

Good luck

Logged

ICS Academy Network Security Certified
adroc
Newbie
*
Offline Offline

Posts: 4



View Profile
« Reply #3 on: October 12, 2012, 02:08:15 AM »

Hello ajohnson,

Thanks for the great reply and all the info. You have eased some of my fears about the OSCP. In regards to the other classes OS offers, I do plan on taking the OSWE and then the OSCE once I feel I'm ready. From all the research I have done, they diffidently seem like they are the best classes out there ATM.

About one of the books that you mentioned. Is Counterhack: Reloaded still relevant since it was written in 2005 or would something like the new hacking exposed be a better read?
« Last Edit: October 12, 2012, 02:10:14 AM by adroc » Logged
MaXe
Hero Member
*****
Offline Offline

Posts: 669


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« Reply #4 on: October 12, 2012, 04:28:34 AM »

OSCE will force you to think (more) out of the box, than you may have previously thought was possible, it's a great certification, but it is also very hard  Smiley
Logged

I'm an InterN0T'er
adroc
Newbie
*
Offline Offline

Posts: 4



View Profile
« Reply #5 on: October 12, 2012, 04:33:53 AM »

OSCE will force you to think (more) out of the box, than you may have previously thought was possible, it's a great certification, but it is also very hard  Smiley

and that's why I want to take it  Wink
Logged
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1057


aka dynamik


View Profile WWW
« Reply #6 on: October 12, 2012, 09:21:46 AM »

Hello ajohnson,
About one of the books that you mentioned. Is Counterhack: Reloaded still relevant since it was written in 2005 or would something like the new hacking exposed be a better read?

It's still largely relevant.
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4165


Editor-In-Chief


View Profile WWW
« Reply #7 on: October 17, 2012, 10:05:24 AM »

Thanks for coming out of lurker status and for the kind words for our community.

Be sure to check the pinned topics at the top of this board. Should give you plenty to start you off.

Keep learning, keep sharing,
Don
Logged

CISSP, MCSE, CSTA, Security+ SME
Shock
Newbie
*
Offline Offline

Posts: 20


View Profile
« Reply #8 on: October 17, 2012, 02:48:26 PM »

Hello ajohnson,
About one of the books that you mentioned. Is Counterhack: Reloaded still relevant since it was written in 2005 or would something like the new hacking exposed be a better read?

It's still largely relevant.

To expand a bit for Adroc's benefit.

The difference between Counterhack: Reloaded and a book like Grey Hat hacking/The Hacking Exposed series is that Counterhack starts off giving you an in depth understanding of how the basics of most things IT work (operating system file structure, network protocols, etc) and then starts talking about the attacks that can be done.

The other two assume the reader already has a grasp of the basics and head straight into the security stuff.

This is the reason why most people here suggest Counterhack for complete newbies over title series such as hacking exposed until they have a grasp of the basics.   
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.587 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.