Live data from Hacker News

Shared thoughts after 6 years in Pentesting

0x00sec.org

61–70 of 97 posts

Re: Shared thoughts after 6 years in Pentesting

#61
post #3

1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…

> The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. I googled, but I didn't manage to find out what "netpen" is. Network Penetration? I'd assume that virtually all relevant security stuff is network related these days so I'm still confused. Which are the other specialties and why are they more demanding?

Network Penetration Testing is a correct guess.

Pentesting itself can be quite a broad field, and although you’re right about a lot of it being network-related, it typically gets split into categories depending on the exact type of pentest (e.g. application penetration testing, wireless pentesting, embedded devices, SCADA/OT systems).

You could get into a debate on which areas are more demanding, but as you get deeper, they do require different skill sets/specialities/ways of thinking. Someone who’s great at web app pentesting may not necessarily be fantastic at RE or social engineering.

Re: Shared thoughts after 6 years in Pentesting

#62
post #3

1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…

> The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. I googled, but I didn't manage to find out what "netpen" is. Network Penetration? I'd assume that virtually all relevant security stuff is network related these days so I'm still confused. Which are the other specialties and why are they more demanding?

[deleted]

Re: Shared thoughts after 6 years in Pentesting

#63
post #8

Earlier quoted context omitted.

If I'm honest, and I feel like I should be when it comes to talking about my profession even though I'm going to be a little impolitic here and it could cost me elsewhere: yeah, I definitely do discount people a little bit if they volunteer to me that they have OSCP certification. Avoid certification.

>> Avoid certification. Why? Is that something that can hurt your abilities, or your employment prospects?

If you are a black hat, would that help if you have a certificate and half the world knows about it? Transitioning from a (anonymous) black hat to a white hat is relatively painless. However the opposite could be quite painful, because the probability of you ending up on the suspects list will be much higher. Also consider how blurred the line between white/black hat really is.

Re: Shared thoughts after 6 years in Pentesting

#64
post #59
post #8

Earlier quoted context omitted.

If I'm honest, and I feel like I should be when it comes to talking about my profession even though I'm going to be a little impolitic here and it could cost me elsewhere: yeah, I definitely do discount people a little bit if they volunteer to me that they have OSCP certification. Avoid certification.

"Avoid certification." So how do you get through HR wall? Padding CV with keywords is a common way to get an interview. I'm an embedded system engineer looking to move closer to IT security, so how do I get there without experience and certifications as virtually all jobs require one, another or both (except junior positions, but I'm too old to start from the very bottom)? I do learn a lot on my spare time, but you s…

HR wall? You're applying at the wrong places. If a company needs to see letters on your CV, it's because they have no idea what/who they want.

A decent company will have your future colleagues heavily involved in the hiring process, and they'll know how to chat to you about security.

Re: Shared thoughts after 6 years in Pentesting

#65
post #26

Earlier quoted context omitted.

Possibly the former, certainly the latter.

Please explain how is that so?

pentesting requires fast thinking, an ability to learn quickly, and solve unusual challenges on the go. It could be considered dangerous to become comfortable having lessons to teach you new skills, and fairly arbitrary exams that are a poor replica of the real world to assess your own skill set.

A lot of good employers know this, and put zero weight on certa. Or as tptacek mentioned, possibly even consider it a bad thing. If I see a CV with CEH, I go in with an open mind but aware it's probably going to go poorly. I'd rather see someone who bought a stack of books, wrote some vulnerable code to attack, asked for advice from people; demonstrated they could throw themselves in and make it up as they go along.

Re: Shared thoughts after 6 years in Pentesting

#66
post #64
post #59

Earlier quoted context omitted.

"Avoid certification." So how do you get through HR wall? Padding CV with keywords is a common way to get an interview. I'm an embedded system engineer looking to move closer to IT security, so how do I get there without experience and certifications as virtually all jobs require one, another or both (except junior positions, but I'm too old to start from the very bottom)? I do learn a lot on my spare time, but you s…

HR wall? You're applying at the wrong places. If a company needs to see letters on your CV, it's because they have no idea what/who they want. A decent company will have your future colleagues heavily involved in the hiring process, and they'll know how to chat to you about security.

> HR wall? You're applying at the wrong places

This elitism is not helpful. There are finite employers in the world, and many of them do screen based on keywords. That's reality. Applicants who are entering the job market might not always have the luxury of disregarding n% (where n most likely > 75) of their potential employers based on stuff like "oh well any real company wouldn't screen my resume..."

Re: Shared thoughts after 6 years in Pentesting

#67
post #3

1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…

> The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. I googled, but I didn't manage to find out what "netpen" is. Network Penetration? I'd assume that virtually all relevant security stuff is network related these days so I'm still confused. Which are the other specialties and why are they more demanding?

I personally agree NetPen is the least demanding. Not because there aren't incredible netpen testers nor that it can be challenging, but generally you have a lot of attack vectors across a very complex piece of infrastructure, and you just need to find the weakest link to win.

Compare that to say, cryptography or code review, which typically require fairly deep specific knowledge and a lot of intense focus, as opposed to broader knowledge and a willingness to try a lot of different things.

Most findings in netpen reports I see are basically that something wasn't configured correctly, or that one of the 10k employees had a weak password, or someone got phished. I often chuckle but rarely am surprised or learn too many new things.

Re: Shared thoughts after 6 years in Pentesting

#68
post #66
post #64

Earlier quoted context omitted.

HR wall? You're applying at the wrong places. If a company needs to see letters on your CV, it's because they have no idea what/who they want. A decent company will have your future colleagues heavily involved in the hiring process, and they'll know how to chat to you about security.

> HR wall? You're applying at the wrong places This elitism is not helpful. There are finite employers in the world, and many of them do screen based on keywords. That's reality. Applicants who are entering the job market might not always have the luxury of disregarding n% (where n most likely > 75) of their potential employers based on stuff like "oh well any real company wouldn't screen my resume..."

The security industry is remarkably small. If you're going to spray your CV and hope for the best, sure, having as many certs as possible will get you past the first interview.

But chances are if someone is browsing HN they're at least genuinely engaged enough to do better than that. You're advocating for people to shoot for average, I'm suggesting to not settle.

Re: Shared thoughts after 6 years in Pentesting

#69
post #64
post #59

Earlier quoted context omitted.

"Avoid certification." So how do you get through HR wall? Padding CV with keywords is a common way to get an interview. I'm an embedded system engineer looking to move closer to IT security, so how do I get there without experience and certifications as virtually all jobs require one, another or both (except junior positions, but I'm too old to start from the very bottom)? I do learn a lot on my spare time, but you s…

HR wall? You're applying at the wrong places. If a company needs to see letters on your CV, it's because they have no idea what/who they want. A decent company will have your future colleagues heavily involved in the hiring process, and they'll know how to chat to you about security.

"A decent company will have your future colleagues heavily involved in the hiring process"

Of course, but you still have to get to them first as no sane company makes their engineers to do 1st round CV screening (especially for publicly announced positions where tens or hundreds of CVs are applied). From my personal experience, technical interview with an engineer is usually only on 2nd/3rd round, so we are back to square 1. Yes, I know the best positions are filled through networking and recommendations, but that's not an option when you live outside of tech bubbles.

Re: Shared thoughts after 6 years in Pentesting

#70
I am always fascinated by pen testing and studied computer networking in security to fall into a software engineering job. I just never knew where to start with heading a leg up on the tools and practices to be able to go into pen testing professionally... I couldn't find any apprenticeships or junior roles for it so ended up shelving it as a 'maybe one day' 'dream'. Where would be the best place to start? Most of the books I have are pretty dated now.

Also the article was a great read. Pinning it to go over again on the weekend as my lunch is now over.

Post reply on HN