Live data from Hacker News

Ask HN: How did you get started in Network Security/Penetration Testing?

news.ycombinator.com

31–40 of 69 posts

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#31
post #29

By hacking the planet, duh. But seriously, I got started by writing exploits for long tail web apps.

> But seriously, I got started by writing exploits for long tail web apps.

I lovingly refer to this as "clubbing baby seals" and it is overwhelmingly common among younger hackers looking to polish their skills. :-x

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#32
post #30

Just to clarify for everyone: Be careful switching your career to netsec/pentesting. If that's your thing, great. But you're likely to be a "lifer" because no one will want to hire you anymore for webdev. It's not quite as clear-cut as that, but if you're out of the game for N years, it's really hard to get back into it. Especially when you're not younger than 30. Ageism is a real thing.

I've heard a lot of managers complaining that it was hard to find security people who could code well, so while getting a generic web dev job may be hard due to bias, it should be relatively easy to get a security engineering position where you write security-related code, as long as you're good at the writing code part.

Sure, but that still makes you a security lifer.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#33
post #29

By hacking the planet, duh. But seriously, I got started by writing exploits for long tail web apps.

I understand the meaning of "long tail", but not sure what it means in this context. Is this an infosec term? I work in webdev and have never heard it used. Are you referring to less-commonly used web app frameworks?

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#34
post #30

Earlier quoted context omitted.

I've heard a lot of managers complaining that it was hard to find security people who could code well, so while getting a generic web dev job may be hard due to bias, it should be relatively easy to get a security engineering position where you write security-related code, as long as you're good at the writing code part.

Sure, but that still makes you a security lifer.

I didn't really find it that difficult to move from security consulting/research/code audits => dev/researcher at security vendors => machine learning engineer.

So I don't know how we decide whose anecdote wins here :p

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#35
post #33
post #29

By hacking the planet, duh. But seriously, I got started by writing exploits for long tail web apps.

I understand the meaning of "long tail", but not sure what it means in this context. Is this an infosec term? I work in webdev and have never heard it used. Are you referring to less-commonly used web app frameworks?

Less commonly used web apps; they tend to have poor security because no-one has cared/known enough to make them not horribly insecure.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#36

I can tell you how not to do it. I'll never forget the funniest interview I ever had. I interviewed with this company called Deja vu Security. http://www.dejavusecurity.com/ I explicitly told them, via email, I have ZERO experience pen testing, or anything related to hacking. I'm a terrific software engineer looking to pivot into this market, would take a salary cut to get my feet wet and be mentored. Would this be p…

We have a hiring process for folks with no infosec experience. It isn't easy, but it works. The guys at Deja are solid and consulting makes for busy folks, so don't hold a low opinion of them. Probably did not pay close enough attention to the initial email.

If you are interested shoot careers at carvesystems dot com an email.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#37
I decided I wanted to get verbally assaulted by engineering teams I was reporting findings to day in and day out. Who would have thought, I managed to make a career out of it!

(ps, if you do go down this route, try to find a job at a company with a good security culture. starting one from scratch is walking a road of broken glass)

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#39
post #34

Earlier quoted context omitted.

Sure, but that still makes you a security lifer.

I didn't really find it that difficult to move from security consulting/research/code audits => dev/researcher at security vendors => machine learning engineer. So I don't know how we decide whose anecdote wins here :p

Simple. If you value your career as a dev, you won't become a pentester. :) There's no upside except intellectually. Being a dev pays more and gives you more options going forward.

That's a harsh way to frame it, but it's also accurate. (I'm speaking from experience FWIW.)

In other words, you could have become an ML engineer anyway. No reason to risk it by becoming a pentester.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#40
post #2

I’ve been a professional software developer for the last 4-5 years, but never took security serious until iot took off. Get some raspberry pis, install kali Linux on a VM or spare computer, and go to work! It’s just so easy and cheap to setup a pen test lab. I’d recommend every dev have a few attack machines for fun. That’s how I got started . It’s also a huge field. Try checking out security in your current discipli…

"It’s also a huge field. Try checking out security in your current discipline."

I'm actually 15 at the moment with basically no experience besides messing around with kali tools like a script kiddie.

Got any tips for programming languages to learn/where to learn?

I appreciate the post!

Post reply on HN