Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 42 guests online
Free Business and Tech Magazines and eBooks
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Programming
SANS Python for Pentesters in beta
EH-Net
May 18, 2013, 11:25:04 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Programming
(Moderator:
don
) >
SANS Python for Pentesters in beta
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: SANS Python for Pentesters in beta (Read 5508 times)
0 Members and 1 Guest are viewing this topic.
tturner
Sr. Member
Offline
Posts: 432
SANS Python for Pentesters in beta
«
on:
November 09, 2012, 04:57:43 PM »
Check it out, it's a 5 day course and includes a copy of
http://www.amazon.com/Violent-Python-Cookbook-Penetration-Engineers/dp/1597499579
-
http://www.sans.org/course/python-for-pen-testers
Logged
Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP
WIP: OSWP, GSSP-JAVA, GXPN
Udacity on hold, again. I suck.
http://sentinel24.com/blog
@tonylturner
http://bsidesorlando.org
azmatt
Jr. Member
Offline
Posts: 76
Re: SANS Python for Pentesters in beta
«
Reply #1 on:
November 09, 2012, 10:46:45 PM »
The real loser here is my savings account.
Logged
GCFA, GCIH, GSEC, GCFE, CHFI
lorddicranius
Sr. Member
Offline
Posts: 447
Re: SANS Python for Pentesters in beta
«
Reply #2 on:
November 09, 2012, 11:21:07 PM »
I wonder how the class will compare to SecurityTube's Python class (
http://securitytube-training.com/online-courses/securitytube-python-scripting-expert/
), because I'm sure it won't be cheaper haha
Logged
GSEC, eCPPT, Sec+
ajohnson
Recruiters
Hero Member
Offline
Posts: 1056
aka dynamik
Re: SANS Python for Pentesters in beta
«
Reply #3 on:
November 10, 2012, 01:03:39 AM »
Man, that's kind of underwhelming. Two days are spent on Python basics, and the last day is exercises? Most of the foundation items are covered for free in Google's two-day Python course:
http://code.google.com/edu/languages/google-python-class/
The SPSE covers the vast majority of these topics, and additional items, such as RE and scripting Immunity. The book appears to fill in the gaps, and includes additional content as well.
That's a huge expense to have someone teach you a subset of a $30 book.
The value I see in other SANS courses is the relatively large amount or original/unique content. There's no way I could personally justify this.
«
Last Edit: November 10, 2012, 01:05:33 AM by ajohnson
»
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
hayabusa
Hero Member
Offline
Posts: 1630
Re: SANS Python for Pentesters in beta
«
Reply #4 on:
November 10, 2012, 09:08:01 AM »
I'd have to agree with ajohnson...
While there are some SANS courses I see value in, I can't personally see or justify the cost associated with SANS courses, for this python course.
SPSE has been good (as far as I've had time to go through it), and is far cheaper, and I still plan to buy a copy of Violent Python, anyway.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
tturner
Sr. Member
Offline
Posts: 432
Re: SANS Python for Pentesters in beta
«
Reply #5 on:
November 10, 2012, 02:28:19 PM »
Keep in mind 2 things.
One, SANS markets courses at the lowest common denominator to maximize attendance, which in security means non-coders. They have to cover basics here and will probably never have a 500 level course that requires substantial knowledge coming into the course. If this course does well for them I'd expect to see a more challenging 600 level or perhaps 1 or 2 day advanced courses in the future.
Second, this course is beta, and they very frequently make changes from beta to live and often even a year or two after going live sometimes make sweeping changes. If they see that people are not buying the course because of this they will shift gears. If however a bunch of people without experience sign up then we will just have to wait for the more advanced course.
Personally I think SPSE is the better value by far but with Mark Baggett at the helm I'm expecting some pretty great stuff from this course as well. I plan on doing both but I probably won't do the SANS course until they work the kinks out. That usually happens by the time they have the cert. GPYP maybe?
Did anyone here take Joe McCray's Python course earlier this year?
http://strategicsec.com/services/training-services/classroom/python-for-security-professionals/
Anyone know if he's doing another run of it?
Logged
Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP
WIP: OSWP, GSSP-JAVA, GXPN
Udacity on hold, again. I suck.
http://sentinel24.com/blog
@tonylturner
http://bsidesorlando.org
hayabusa
Hero Member
Offline
Posts: 1630
Re: SANS Python for Pentesters in beta
«
Reply #6 on:
November 10, 2012, 03:36:03 PM »
Missed Joe's, and like you, perhaps IF they get a more advanced course, down the road, and the pricing is decent, MAYBE I'll take a look. (But you're right, in that SPSE is considerably more affordable, even for beginners, and the beginning sections are pretty good primers, for folks who have done 'no' major python coding)
I agree, with Baggett at the helm, it should at LEAST be a good course.
«
Last Edit: November 11, 2012, 03:30:11 PM by hayabusa
»
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
ajohnson
Recruiters
Hero Member
Offline
Posts: 1056
aka dynamik
Re: SANS Python for Pentesters in beta
«
Reply #7 on:
November 11, 2012, 01:03:30 PM »
Just to be clear, I wasn't implying the course would be poor quality. It just seems like a waste to spend two days on such basic material. I realize the courses are designed for broad appeal, but other 5xx courses have some teeth to them.
If you look at the SPSE, you'll see there are a ton of interesting directions you can take that aren't ridiculously hardcore or intimidating. More often than not, it's just introducing the student to a new library and providing some background on how to use it.
They already have a two-day Scapy course. I wish they would have dropped the intro fluff and brought that material in instead. That would have freed up the networking portion for an intro to RE and exploit development, or a myriad of other topics.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
tturner
Sr. Member
Offline
Posts: 432
Re: SANS Python for Pentesters in beta
«
Reply #8 on:
November 11, 2012, 08:17:00 PM »
Unfortunately Scapy didn't sell well so they appear to have abandoned that content.
Logged
Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP
WIP: OSWP, GSSP-JAVA, GXPN
Udacity on hold, again. I suck.
http://sentinel24.com/blog
@tonylturner
http://bsidesorlando.org
markbaggett
Newbie
Offline
Posts: 2
Re: SANS Python for Pentesters in beta
«
Reply #9 on:
November 13, 2012, 09:07:55 AM »
Hey. This is awesome. I appreciate that people are talking about the course already. Thanks for your kind words and vote of confidence about 'Baggett at the helm'. It means a lot to me. Here is a little background on the course.
I started teaching this course at on-site engagements for military customers almost two years ago. It was originally a 3 day course and I listed several online courses (Google Python Class, Kahn Academy, SPSE didn't exist at that time) as prerequisites. We jumped straight into the 4 hands on projects where we build a AV/IDS Evading backdoor, sql injection tool, password guesser and a network recon tool. As you can imagine prerequisites are difficult to enforce and I had a portion of the student that were lost. I decided I had to cover the essentials, but I didn't want to bore people who know how to code.
I put a lot of thought into how to cover the essentials for someone who is new to programming/Python and keep it engaging for people who can already code. What I came up with is pyWars. It is a CTF Challenge that runs the first 4 days and is deeply integrated into the course. Skilled programmers will likely disengage from the course material and play pyWars until the material catches up to their skill. New programmers will stay engaged early but turn to pyWars as they build their skills.
Thanks for the interest an "buzz generation."
Logged
lorddicranius
Sr. Member
Offline
Posts: 447
Re: SANS Python for Pentesters in beta
«
Reply #10 on:
November 13, 2012, 09:44:36 AM »
Quote from: tturner on November 10, 2012, 02:28:19 PM
Did anyone here take Joe McCray's Python course earlier this year?
http://strategicsec.com/services/training-services/classroom/python-for-security-professionals/
Anyone know if he's doing another run of it?
I missed Joe's too. I heard if it went well he was gonna give it another go, but I didn't hear anything afterward.
Quote from: tturner on November 11, 2012, 08:17:00 PM
Unfortunately Scapy didn't sell well so they appear to have abandoned that content.
I didn't know they had a scapy course
Thanks for hopping in and giving some extra info, Mark. pyWars sounds pretty cool and a neat idea for those with experience already.
Maybe we can get the course in on a EHnet giveaway so we can get a course review here
Logged
GSEC, eCPPT, Sec+
tturner
Sr. Member
Offline
Posts: 432
Re: SANS Python for Pentesters in beta
«
Reply #11 on:
November 13, 2012, 10:29:52 AM »
Quote from: lorddicranius on November 13, 2012, 09:44:36 AM
Quote from: tturner on November 10, 2012, 02:28:19 PM
Did anyone here take Joe McCray's Python course earlier this year?
http://strategicsec.com/services/training-services/classroom/python-for-security-professionals/
Anyone know if he's doing another run of it?
I missed Joe's too. I heard if it went well he was gonna give it another go, but I didn't hear anything afterward.
Quote from: tturner on November 11, 2012, 08:17:00 PM
Unfortunately Scapy didn't sell well so they appear to have abandoned that content.
I didn't know they had a scapy course
Looks like Joe's Python course is being offered again in a week or 2.
http://www.trainace.com/courses/python/
I'm not sure if he's the instructor or not.
Also, the Scapy course was a Judy Novak original. SEC567, here's a cheat sheet for the course
http://www.sans.org/security-training/course_sums/1382.pdf
I was very sad to see it go.
Logged
Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP
WIP: OSWP, GSSP-JAVA, GXPN
Udacity on hold, again. I suck.
http://sentinel24.com/blog
@tonylturner
http://bsidesorlando.org
ajohnson
Recruiters
Hero Member
Offline
Posts: 1056
aka dynamik
Re: SANS Python for Pentesters in beta
«
Reply #12 on:
November 13, 2012, 10:33:04 AM »
Yes, thanks for the feedback Mark. You should play up the PyWars piece a bit more on the course page. That sounds like a key aspect of the course that deserves more than a single bullet point under Lab Details.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
lorddicranius
Sr. Member
Offline
Posts: 447
Re: SANS Python for Pentesters in beta
«
Reply #13 on:
November 13, 2012, 10:49:07 AM »
Quote from: tturner on November 13, 2012, 10:29:52 AM
Also, the Scapy course was a Judy Novak original. SEC567, here's a cheat sheet for the course
http://www.sans.org/security-training/course_sums/1382.pdf
I was very sad to see it go.
Awesome, thanks for the link
Logged
GSEC, eCPPT, Sec+
markbaggett
Newbie
Offline
Posts: 2
Re: SANS Python for Pentesters in beta
«
Reply #14 on:
November 13, 2012, 12:25:55 PM »
ajohnson - Good point. I'll take another look at the course description.
lorddicranius - Let me run the BETAs and make sure the product lineup is finalized before we talk about a course review.
All - Thanks for the feedback. I appreciate it.
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
General Certification
: CPT Practical Submission
(0) by
z28power4u
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(5) by
MrTuxracer
Career Central
: Starter cert?
(0) by
Alert
Web Applications
: Nessus and Nikto
(4) by
Seen
Tutorials
: Need guidance
(7) by
impelse
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.