|
don
|
 |
« on: April 29, 2010, 01:53:50 AM » |
|
Welcome to the Official First Article of our newest columnist, Jason Haddix. Glad to add you to the family. Thanks and I look forward to a bright future. Permanent: [Article]-Review: eLearnSecurity’s Penetration Testing Pro (PTP)eLearnSecurity’s Penetration Testing Pro - What CEH Should Have Been 
Recently the web has been abuzz with pentest training options. The CEH received new life as it was added to DoD Directive 8570 as well as revamped its courseware in version 6.0, Offensive Security rolled out their version 3.0 of “Pentesting With BackTrack,” and it seems like new training options are coming out almost every day in the field. That being said, I have been lucky enough to receive an advanced copy of the flagship course by eLearnSecurity, Penetration Testing Pro (PTP). PTP is a three section presentation and video course authored by Armando Romeo (admin of hackerscenter.com), Brett D. Arion, Nitin Kumar, and Vipin Kumar. It has an optional certification component called the Certified Professional Penetration Tester or eCPPT for short. The target audience for the course is security engineers or penetration testers in the 0-3 year experience range. The course divides penetration testing into three categories: System Security, Network Security, and Web Application Security. Let’s take a look at each. As with any other article or column, please send us your feedback by replying to this thread. Also feel free to suggest any other reviews you'd like Jason to do. Don
|
|
|
|
|
Logged
|
CISSP, MCSE, CSTA, Security+ SME
|
|
|
|
Equix3n-
|
 |
« Reply #1 on: April 29, 2010, 02:16:27 AM » |
|
Excellent! I'm currently going through their demo SQL Injection module and have been greatly impressed by it. Also, how does it compare to PWB and SANS Sec 504 ( I guess Jason has done both of them)? Did you take the certification exam?
Additionally, I've the 20% discount code for eLearnsecurity's Penetration Testing Pro. I won't be using and it's valid until 30th April. I am willing to give it to some EH member. Contact me if you want. With the coupon the training cost is just $388.
|
|
|
|
|
Logged
|
|
|
|
|
What90
|
 |
« Reply #2 on: April 29, 2010, 05:02:14 AM » |
|
Great review Jason, it really helps understand who this is focused towards and what they can get out of it!
I'd love to hear about the web application stand alone course, once it's ready for the general public of course;-)
|
|
|
|
|
Logged
|
|
|
|
|
BillV
|
 |
« Reply #3 on: April 29, 2010, 05:23:07 AM » |
|
Great review, Jason  I personally haven't had time to get much beyond the Systems Security section yet but it's nice to know what is coming up. As mentioned in the article, Armando and his team is quick to update material and make any corrections as needed. I know there were a couple things I brought to his attention and he replied nearly immediately saying they'd be fixed. I definitely agree with the points made by Jason in his article and the eLearnSecurity group has created an excellent course. BillV
|
|
|
|
|
Logged
|
|
|
|
|
Armando
|
 |
« Reply #4 on: April 29, 2010, 07:25:13 AM » |
|
Thank you all.
When you have a budget of approximately 0$ for marketing and promotion, the only way to be successful is to build something great. It seems we managed to do it.
Your words will be our proof for the skeptics. So please, spread the word and be an eLS evangelist.
Thank you very much
|
|
|
|
« Last Edit: April 29, 2010, 07:27:14 AM by Armando »
|
Logged
|
|
|
|
|
Ketchup
|
 |
« Reply #5 on: April 29, 2010, 08:33:55 AM » |
|
Jason, that's a great review! All of my questions were answered and then some. Fantastic work.
It seems like eLS is a great bargain and offers some great training. It will definitely go on my list.
|
|
|
|
|
Logged
|
~~~~~~~~~~~~~~ Ketchup
|
|
|
|
hayabusa
|
 |
« Reply #6 on: April 29, 2010, 10:08:44 AM » |
|
Hey Jason.
Great review! I'm pumped to look at this one now, too! Question for you. Dunno if you've done PWB yet, from Offensive... If you HAVE, how does this compare to what muts and company have there?
Obviously, PWB is pretty intensive (I'm preparing to start taking v3, in a couple of weeks), and I know from reading, the eLearnSecurity stuff is all online (no downloadable courseware, etc - assumably to keep it from being distributed, etc) But wondering, as a comparison, how the two stack up.
Like I said, this looks promising, so I'll likely go for this, when I am done with PWB. Just looking for a feel on it, so I can guage my time AFTER PWB, for what and how I want to be doing.
Thanks.
Tim
|
|
|
|
|
Logged
|
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
|
|
|
|
ethicalhack3r
|
 |
« Reply #7 on: April 29, 2010, 10:17:35 AM » |
|
Congrats Jason. Great article! 
|
|
|
|
|
Logged
|
|
|
|
|
Armando
|
 |
« Reply #8 on: April 29, 2010, 10:37:12 AM » |
|
@hayabusa You can sign up for a demo of our course, that is an (almost) full module on SQL Injection including 20 minutes of video training. Just enter your email on our home page and you will get a user and pass within 1 hour.
Wanted to say that the introductory price ($485) will expire tomorrow April 30th at 12pm GMT. Regular price will be 449€ ($599)
We really gifted this course that is worth at least three times the current price, but yeah! We will respect our first goal to make great training affordable! Even after the great reviews we are getting
|
|
|
|
« Last Edit: April 29, 2010, 10:42:17 AM by Armando »
|
Logged
|
|
|
|
|
pizza1337
|
 |
« Reply #9 on: April 29, 2010, 10:42:18 AM » |
|
good article, i am interested in "Web Application Security" part, because i am weak when it comes to web app, i only know little about xss. also interested in “Anonymity” part. also need to learn how to write shellcode, and exploits. i am script kiddie(but i understand the basics  ) *thinks about summer job*
|
|
|
|
|
Logged
|
Knowledge Resource is Power.
|
|
|
|
hayabusa
|
 |
« Reply #10 on: April 29, 2010, 10:52:27 AM » |
|
@hayabusa You can sign up for a demo of our course, that is an (almost) full module on SQL Injection including 20 minutes of video training. Just enter your email on our home page and you will get a user and pass within 1 hour.
Wanted to say that the introductory price ($485) will expire tomorrow April 30th at 12pm GMT. Regular price will be 449€ ($599)
We really gifted this course that is worth at least three times the current price, but yeah! We will respect our first goal to make great training affordable! Even after the great reviews we are getting
Thanks Armando. Will register for the demo. Appreciate the fact that your company is working to keep it real / affordable for everyone. I won't be able to register for the class at this time (budgetary issues), and won't, until I'm done with PWB, so I'll miss out on this discount, but I appreciate the concern and mention of expiration date. 
|
|
|
|
|
Logged
|
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
|
|
|
|
Armando
|
 |
« Reply #11 on: April 29, 2010, 10:54:27 AM » |
|
Not because I wrote it  . But I believe you won't find any better coverage of web app testing in other courses. Check out our demo, it's on web app testing or ask Jason 
|
|
|
|
|
Logged
|
|
|
|
|
Manu Zacharia (-M-)
|
 |
« Reply #12 on: April 29, 2010, 12:53:42 PM » |
|
Congrats to Jason for the wonderful review and Hats off to Armando and his team - the course looks really promising  All the best to eLS team
|
|
|
|
|
Logged
|
Manu Zacharia MVP (Enterprise Security), ISLA-2010 (ISC)˛, C|EH, C|HFI, CCNA, MCP, Certified ISO 27001:2005 Lead Auditor
There are 3 roads to spoil; women, gambling & hacking. The most pleasant with women, the quickest with gambling, but the surest is hacking - c0c0n
|
|
|
|
impelse
|
 |
« Reply #13 on: April 29, 2010, 02:09:35 PM » |
|
Great review
|
|
|
|
|
Logged
|
|
|
|
|
What90
|
 |
« Reply #14 on: April 29, 2010, 10:51:34 PM » |
|
Hello Armando,
Having taken the OSCP and GPEN, it's a strain to convince the powers that be to let me on another similar pentest course, but they seems happy to let me take a run at targeted training.
Do you have any time lines on the Web Application Security stand alone course being made available?
From Jason comments and review, I'd guess this would be well worth taking to strengthen those web app skills ;-)
|
|
|
|
|
Logged
|
|
|
|
|