Live data from Hacker News

Shared thoughts after 6 years in Pentesting

0x00sec.org

71–80 of 97 posts

Re: Shared thoughts after 6 years in Pentesting

#71

I am always fascinated by pen testing and studied computer networking in security to fall into a software engineering job. I just never knew where to start with heading a leg up on the tools and practices to be able to go into pen testing professionally... I couldn't find any apprenticeships or junior roles for it so ended up shelving it as a 'maybe one day' 'dream'. Where would be the best place to start? Most of th…

I'm the same as you. I got this book:

https://www.amazon.ca/Hacking-Art-Exploitation-Jon-Erickson/...

Which I've dabbled in, and haven't gotten further than what I already know from my CS education, but the consensus seems to be it's a good book to learn from.

Re: Shared thoughts after 6 years in Pentesting

#72
post #52
post #40

Earlier quoted context omitted.

Certification in a field such as vulnerability research doesn't help with your abilities because the techniques you learn are rarely related to the techniques you need to be the best in your class. As for job prospects, generally certification won't get you into companies that are only looking for talent as opposed to a checklist of certifications (the former is usually where all of the really interesting work is don…

I think you guys are comparing apples to oranges > Certification in a field such as vulnerability research OSCP is basically tool-based network pen testing with a bit of outdated websec and buffer overflows thrown into the mix. It's not "vulnerability research" in any meaningful sense of the word. They have some other certs (OSCE) that might purport to target that domain, but idk much about them. > As for job prospec…

Name a pentesting firm that cares about the OSCP.

Re: Shared thoughts after 6 years in Pentesting

#73
post #68
post #66

Earlier quoted context omitted.

> HR wall? You're applying at the wrong places This elitism is not helpful. There are finite employers in the world, and many of them do screen based on keywords. That's reality. Applicants who are entering the job market might not always have the luxury of disregarding n% (where n most likely > 75) of their potential employers based on stuff like "oh well any real company wouldn't screen my resume..."

The security industry is remarkably small. If you're going to spray your CV and hope for the best, sure, having as many certs as possible will get you past the first interview. But chances are if someone is browsing HN they're at least genuinely engaged enough to do better than that. You're advocating for people to shoot for average, I'm suggesting to not settle.

> You're advocating for people to shoot for average, I'm suggesting to not settle.

From my perspective, I'm advocating that people don't inadvertently shoot themselves in the foot. They might not yet be qualified to work at Matasano or [insert top tier security shop here] : not everyone is.

Assuming someone isn't (yet) qualified to work with their dream employer, what do you suggest they do? "Don't settle" in that scenario sounds a lot like "be unemployed". I'm straight up saying it's better to build up skills at a job - even if that job isn't their endgame.

Re: Shared thoughts after 6 years in Pentesting

#74
post #72
post #52

Earlier quoted context omitted.

I think you guys are comparing apples to oranges > Certification in a field such as vulnerability research OSCP is basically tool-based network pen testing with a bit of outdated websec and buffer overflows thrown into the mix. It's not "vulnerability research" in any meaningful sense of the word. They have some other certs (OSCE) that might purport to target that domain, but idk much about them. > As for job prospec…

Name a pentesting firm that cares about the OSCP.

The pentesting team at SEI-CERT cares about it.

Re: Shared thoughts after 6 years in Pentesting

#75

I am always fascinated by pen testing and studied computer networking in security to fall into a software engineering job. I just never knew where to start with heading a leg up on the tools and practices to be able to go into pen testing professionally... I couldn't find any apprenticeships or junior roles for it so ended up shelving it as a 'maybe one day' 'dream'. Where would be the best place to start? Most of th…

I work as pen tester (ask me anything). In school I got the opportunity to pick digital security as my major, but I'm certain any computer science related study would have been fine.

When interviewing for my current company, my first full-time job, I was given a vulnerable web application which they used to assess whether I could do the job (next to a regular interview). I aced this hack test, but due to it being my first full-time job they still scaled me in as a junior.

Overall, if you know your thing, you can just go and interview with companies that do security. Specifics, such as a workflow when performing a security assessment, are specific to a company anyway. With some semi-related work experience (many colleagues have a programming background) you should be able to come in above junior too.

As for where to get the skills: hack something. My study gave me dedicated time to spend on it, but even in high school I was writing code, sharing it with others, and we had fun poking around each other's applications security-wise. That's how I truly learned: doing.

Re: Shared thoughts after 6 years in Pentesting

#76

Earlier quoted context omitted.

> The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. I googled, but I didn't manage to find out what "netpen" is. Network Penetration? I'd assume that virtually all relevant security stuff is network related these days so I'm still confused. Which are the other specialties and why are they more demanding?

Network Penetration Testing is a correct guess. Pentesting itself can be quite a broad field, and although you’re right about a lot of it being network-related, it typically gets split into categories depending on the exact type of pentest (e.g. application penetration testing, wireless pentesting, embedded devices, SCADA/OT systems). You could get into a debate on which areas are more demanding, but as you get deepe…

So is webapp pentesting a part of netpen? How about wireless? I still don't understand the definitions.

Re: Shared thoughts after 6 years in Pentesting

#77
post #10

We just had some consultants do pentesting on our medical device and its software components. I was pretty impressed by all the problems they found quickly. As developer I find it pretty hard to stay up-to-date with all the possible ways hackers can get into your systems. To me this was money well spent.

Check out Threatcare, it's a SaaS version of what most pentesters do.

Re: Shared thoughts after 6 years in Pentesting

#78
post #3

1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…

> The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security.

I think that's a fairly sweeping judgement to make, and not entirely accurate. I think it says more about your own experiences than those of network penetration testers.

You could equally cast the aspersion that red teamers are little more than Microsoft Office power users and occasional part-time domain admins and fall just as far outside of the mark.

The speciality is certainly demanding. The generalisation is not. The difference is that scan and scram artists and PCI scanners get lumped into the more general area associated with network penetration testing.

When done properly, network penetration testing is inherently valuable, not just from a security perspective but from a network discovery and debugging perspective.

I think your point on network testing (and indeed points 2 and 3), are shining examples of navel gazing within your own experience. Perhaps it's best not to belittle an entire subsection of the industry you spent so long in all at once, but to ask yourself why you believe this to be the case and wonder where you may have gone wrong in this assertion.

Re: Shared thoughts after 6 years in Pentesting

#79
post #72
post #52

Earlier quoted context omitted.

I think you guys are comparing apples to oranges > Certification in a field such as vulnerability research OSCP is basically tool-based network pen testing with a bit of outdated websec and buffer overflows thrown into the mix. It's not "vulnerability research" in any meaningful sense of the word. They have some other certs (OSCE) that might purport to target that domain, but idk much about them. > As for job prospec…

Name a pentesting firm that cares about the OSCP.

In the UK OSCP can be used for CRT equivalency and I know that many/most pentesting companies care about CRT/CCT qualifications in the UK, if only because they're a requirement for doing work for some government departments, and also some financial services companies will use CREST certification as a check for testers doing work for them.

So in that sense, they do care about OSCP.

Re: Shared thoughts after 6 years in Pentesting

#80
post #6

Earlier quoted context omitted.

I agree with you. Here are some of my thoughts at 15 years: 1. Get sleep and exercise. Stop drinking soda, just stop it. Drink water, coffee, tea, and scotch. 1a. During undergrad, I would get into a trap where I would think I was too busy with schoolwork some night to exercise. Later, I changed my thinking and realized I was too busy to NOT exercise. My grades improved. 2. Work 40 hours a week. Don't be a hero. You'…

> Learn some advanced mathematics and cryptography. There is too much of mathematics to learn all of them. To make maximize, I think I need to focus on some subjects that would be cost-effective. What woulds would this be?

Just learn what you need:

https://gist.github.com/tqbf/be58d2d39690c3b366ad

Post reply on HN