Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 38 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
General Certification
Certifications you need to have in order to be a Pen Tester.
EH-Net
May 21, 2013, 06:25:18 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
General Certification
(Moderator:
don
) >
Certifications you need to have in order to be a Pen Tester.
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Certifications you need to have in order to be a Pen Tester. (Read 7301 times)
0 Members and 1 Guest are viewing this topic.
Root
Newbie
Offline
Posts: 3
Certifications you need to have in order to be a Pen Tester.
«
on:
November 02, 2012, 07:24:14 PM »
I want to be a Penetration tester, but I don't know much about all the certifications that you can get.
If anyone could make a "list" of the certifications that you need in order to become a Penetration tester, I would be very glad.
Like what certifications to take first and so on. 1,2,3 etc.
My experience:
I started my hacking "hobbies" on Hackforums.net back in 2009. There I learned all the basic App injections. There's not much to come for on that site.
I've been trough the CEHv7 material. It was kinda basic in my option.
Well, I hope that someone can help me a little, just to get started.
Regards,
-Root.
Logged
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: Certifications you need to have in order to be a Pen Tester.
«
Reply #1 on:
November 02, 2012, 09:40:06 PM »
You don't
need
certs to be a pen tester, but they do help you differentiate yourself from other applicants when looking for a job.
Offensive Security and SANS both have reputable certifications. OSCP and GPEN would be good starting places from Offensive Security and SANS, respectively. They both have more niche and advanced certifications related to pen testing, but those are the staples. eLearn's eCPPT is a nice bridge between CEH and OSCP if you feel that the OSCP material might be too advanced for you.
CEH is a bit fluffy, but it is nice to have since it one of the more well-known ethical hacking/pen testing certs.
The CISSP is another one that's more of a personal marketing certification and not related to pen testing, but it is often expected/required for more advanced infosec roles.
Sil's put together a fairly comprehensive list of infosec certs here:
http://infiltrated.net/TechnicalSecurityRoadmap.html
That may be a bit overwhelming if you're not familiar with many of them, but it will at least give you a starting point for research.
eCPPT or OSCP will probably be the next best step for you, unless you have a budget large enough for a SANS course/cert.
Welcome to the forums, and let us know if you have any other questions.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
Root
Newbie
Offline
Posts: 3
Re: Certifications you need to have in order to be a Pen Tester.
«
Reply #2 on:
November 03, 2012, 01:44:13 PM »
Thank you very much.
The information that you gave me was very helpful.
And the link, it's a great help.
Regards
-Root.
Logged
MaXe
Hero Member
Offline
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: Certifications you need to have in order to be a Pen Tester.
«
Reply #3 on:
November 03, 2012, 11:21:33 PM »
In the Asian region of the world, you will often need to be CEH certified. In the UK (England), you will need to be CREST and/or CHECK certified (sometimes both), and in Australia, you will need CREST in the near future if the current situation here evolves.
In all countries, depending on the security level of your work, you may be required to be cleared for e.g. "SECRET" or "TOP SECRET", such as when you are working for the police, the military and federal agencies.
If you go to another country, there will most likely be certain jobs you cannot do which requires certain security clearances, as they often require you to be a citizen of that country and thus, hold a citizenship in that country.
Note: Some job offers, requires or asks for CISSP, but it is not a "requirement" for the actual job being performed, as CISSP won't prove whether you are a penetration tester or not. (Some CISSP and CEH certified professionals, actually remove these certifications from their CV's as the reputation can easily taint your image.)
«
Last Edit: November 03, 2012, 11:23:18 PM by MaXe
»
Logged
I'm an InterN0T'er
ambient
Newbie
Offline
Posts: 20
Re: Certifications you need to have in order to be a Pen Tester.
«
Reply #4 on:
November 05, 2012, 08:28:38 PM »
Quote from: MaXe on November 03, 2012, 11:21:33 PM
In the Asian region of the world, you will often need to be CEH certified. In the UK (England), you will need to be CREST and/or CHECK certified (sometimes both), and in Australia, you will need CREST in the near future if the current situation here evolves.
In the Asian region, the qualification which is often referred to is C|EH, but it's not mandatory. SANS or OSCP is not well known for HR. In several countries, you need to be their citizens as a prerequisite.
Logged
We secure the nation.
GPEN,eCPPT,C|EH,CCNA
http://incognitolab.com/
https://www.facebook.com/secure.thailand
MaXe
Hero Member
Offline
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: Certifications you need to have in order to be a Pen Tester.
«
Reply #5 on:
November 06, 2012, 08:46:28 PM »
Quote from: ambient on November 05, 2012, 08:28:38 PM
Quote from: MaXe on November 03, 2012, 11:21:33 PM
In the Asian region of the world, you will often need to be CEH certified. In the UK (England), you will need to be CREST and/or CHECK certified (sometimes both), and in Australia, you will need CREST in the near future if the current situation here evolves.
In the Asian region, the qualification which is often referred to is C|EH, but it's not mandatory. SANS or OSCP is not well known for HR. In several countries, you need to be their citizens as a prerequisite.
CEH in common tongue however, is often removed from resumes by most serious penetration testers in developed Information Security countries such as Australia, England and USA, as it is frowned upon in the more serious infosec community. Some of my colleagues are "CEH" because they needed it to get the jobs they had, in e.g. India and other countries nearby. As they don't need to display it, they removed it from their LinkedIn profiles, as it is still seen as a joke (no offence intended) to many people.
So it may not be mandatory where you are currently located and working, but from what I heard from my colleagues that travelled and worked in most of the countries in the Asian region, they needed the certification, even though they didn't want it. (They would rather obtain Offensive Security certifications, which are less recognized in especially undeveloped information security countries, but also "SANS certifications" as well. (Actually it's GIAC providing certifications, as SANS only provides) courses.)
Logged
I'm an InterN0T'er
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Certifications you need to have in order to be a Pen Tester.
«
Reply #6 on:
November 07, 2012, 05:08:07 AM »
Not wanting to hi-jack the thread but I'm not sure I understand the logic behind removing certifications from CV's or LinedIn. I've achieved more respected and advanced certifications since gaining C|EH, but C|EH still holds a mention on my resume.
Regardless of opinions of particular certs, surely having a questionable (in some people's eyes, discussion for another thread) cert like C|EH is still better than an empty space in it's place?
Admittedly I sat C|EH with it's reputation in mind as a way to bypass HR filters rather than 'prove' technical capabilities, but I still sat the cert for a purpose. If you're not going to display a cert, why take in the first place?
To answer Root's original question: you don't necessarily
need
certs to to be a pentester, but if you want to find work you will likely need to be able to by-pass HR filters and pass minimum requirements in particular industries. Using the UK as an example, C|EH can often achieve the first, with CREST/CHECK providing the second (as MaXe has already stated). YMWV depending on location/business sector though.
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
Root
Newbie
Offline
Posts: 3
Re: Certifications you need to have in order to be a Pen Tester.
«
Reply #7 on:
November 07, 2012, 02:47:17 PM »
Thank you for all the great comments.
Well, my plan is to make a company myself, penetration testing company.
I live in the Faroe Islands. It's right between Iceland and England.
Only 50.000 people live there.
So, I don't really need a certification, right?
Logged
MaXe
Hero Member
Offline
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: Certifications you need to have in order to be a Pen Tester.
«
Reply #8 on:
November 07, 2012, 05:30:45 PM »
Quote from: Root on November 07, 2012, 02:47:17 PM
Thank you for all the great comments.
Well, my plan is to make a company myself, penetration testing company.
I live in the Faroe Islands. It's right between Iceland and England.
Only 50.000 people live there.
So, I don't really need a certification, right?
You don't need any information security certifications there, you just need to make sure you don't get into any legal trouble. For (some or all) PCI assessments you need insurance though. But that's not really penetration testing though.
I know where it is as one of my best friends is from there, plus I am from Denmark as well
As the Faroe Islands and the rest of Scandinavia is not _that_ evolved in information security, you may find it hard to find clients in those countries as the big companies are already selling to those that actually wants to buy information security services. A lot of the companies in Denmark doesn't get external penetration tests done, as they haven't been hacked yet, so why should they? Insanity at high level
Anyway, you can still create a penetration testing company and get clients in almost any country if you just meet their legal requirements if there is any, and if you are good at selling your services.
Keep in mind, that if you are going to do this alone, you will have to spend a lot of time on sales, management, etc., over penetration testing and the most important but also less interesting, reporting.
Quote from: Andrew Waite on November 07, 2012, 05:08:07 AM
Not wanting to hi-jack the thread but I'm not sure I understand the logic behind removing certifications from CV's or LinedIn. I've achieved more respected and advanced certifications since gaining C|EH, but C|EH still holds a mention on my resume.
Regardless of opinions of particular certs, surely having a questionable (in some people's eyes, discussion for another thread) cert like C|EH is still better than an empty space in it's place?
I would say it depends on the company you are applying at, if you only got CEH, and it's a highly technical and very serious company, they might think you're joking. No offence intended.
Logged
I'm an InterN0T'er
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Certifications you need to have in order to be a Pen Tester.
«
Reply #9 on:
November 08, 2012, 03:07:44 AM »
Quote from: MaXe on November 07, 2012, 05:30:45 PM
Quote from: Andrew Waite on November 07, 2012, 05:08:07 AM
Regardless of opinions of particular certs, surely having a questionable (in some people's eyes, discussion for another thread) cert like C|EH is still better than an empty space in it's place?
I would say it depends on the company you are applying at, if you only got CEH, and it's a highly technical and very serious company, they might think you're joking. No offence intended.
If you've not got the certs/experience/skills for any position, your application won't be successful, that's true of any industry. What I don't understand is people that have C|EH
and
higher/more advanced certifications dropping C|EH.
At a minimum it shows your development path to get to where you are now. All else being equal I'd hire a CHECK/CREST
and
C|EH applicant over 'just' a CHECK/CREST applicant.
Root, as Maxe states be aware of non-technical workload if working alone. A general truism for consultancy type roles seems to be 1/3 of your time chasing new work, 1/3 doing admin/paperwork and a 1/3 actual billable work. Just make sure you work the excess into your billable prices
Good luck
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
GAWN - GIAC Assessing Wireless Networks
: Karen Millen Dresses Things did improve as the decade gone on
(0) by
dtree70fx
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Programming
: Finished Python Course in Codecademy now what?
(11) by
securitian
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
Tutorials
: Need guidance
(8) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.