Live data from Hacker News

Ask HN: How did you get started in Network Security/Penetration Testing?

news.ycombinator.com

1–10 of 69 posts

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#2
I’ve been a professional software developer for the last 4-5 years, but never took security serious until iot took off. Get some raspberry pis, install kali Linux on a VM or spare computer, and go to work! It’s just so easy and cheap to setup a pen test lab. I’d recommend every dev have a few attack machines for fun. That’s how I got started.

It’s also a huge field. Try checking out security in your current discipline. I was a web developer in 2013, so it was natural that I was inclined to look at SQL injections, XSS, packet sniffing, Etc. I already understood the domain. That is easier than jumping into reverse engineering firm ware if you have no xp.

Now after a couple years of practice, I’m recommitted to security. Huge issue in our current tech ecosystem. I was just approved to take CEH and will be taking it next month. To make it official. If you need some structure to your learning and want to make a career move, check out getting an industry base cert like the CEH or offensive arc cert. most security jobs prefer candidates to have at least one, and they’re not incredibly difficult.

Happy pwning!

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#3
post #2

I’ve been a professional software developer for the last 4-5 years, but never took security serious until iot took off. Get some raspberry pis, install kali Linux on a VM or spare computer, and go to work! It’s just so easy and cheap to setup a pen test lab. I’d recommend every dev have a few attack machines for fun. That’s how I got started . It’s also a huge field. Try checking out security in your current discipli…

Hey man this is really inspiring. I've been thinking about switching from web dev to security. How do you like it in comparison?

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#4
post #2

I’ve been a professional software developer for the last 4-5 years, but never took security serious until iot took off. Get some raspberry pis, install kali Linux on a VM or spare computer, and go to work! It’s just so easy and cheap to setup a pen test lab. I’d recommend every dev have a few attack machines for fun. That’s how I got started . It’s also a huge field. Try checking out security in your current discipli…

Skip the CEH and go straight for the OSCP. It's much more valued. Many in the industry seentu CEH as a joke. Good luck!

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#5
Was minding my own business building malware, playing with crypto, researching ATM skimmers and anonymoizing networks when out of the blue I received an email from a local company offering a high paying job with benefits. It helps fast track you to get on their radar if you act super shady most of the time. Also start wearing a hoodie basically always (even when sleeping) and frequenting all night cyber cafes most nights of the week. Make sure to stare fixated at scrolling terminals continuously while you are there, at least 3 hours minimum per visit.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#6
post #4
post #2

I’ve been a professional software developer for the last 4-5 years, but never took security serious until iot took off. Get some raspberry pis, install kali Linux on a VM or spare computer, and go to work! It’s just so easy and cheap to setup a pen test lab. I’d recommend every dev have a few attack machines for fun. That’s how I got started . It’s also a huge field. Try checking out security in your current discipli…

Skip the CEH and go straight for the OSCP. It's much more valued. Many in the industry seentu CEH as a joke. Good luck!

I wouldn't skip the CEH, at least not the material, but I wouldn't use it as a badge of honor on a resume either. It's a decent study guide as it exploses you to the nomenclature fairly well but it's far too easy to pass the certification without actually being proficient in anything.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#7
post #4
post #2

I’ve been a professional software developer for the last 4-5 years, but never took security serious until iot took off. Get some raspberry pis, install kali Linux on a VM or spare computer, and go to work! It’s just so easy and cheap to setup a pen test lab. I’d recommend every dev have a few attack machines for fun. That’s how I got started . It’s also a huge field. Try checking out security in your current discipli…

Skip the CEH and go straight for the OSCP. It's much more valued. Many in the industry seentu CEH as a joke. Good luck!

There is a massive difference between the CEH and OSCP. If he's ready to take CEH, I'd say do it and use that experience to begin studying for OSCP.

OSCP is no fucking joke. It's hard.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#8
I had an oppressive computer teacher in high school and I liked to pull pranks. It started out with simple password guessing, then phishing, then trojaned USB autoruns, SAM hash dumping, and password cracking, then some wifi sniffing... I never thought of what I was doing as hacking at the time (2001-2002). I just wanted to use the computer lab to play video games, and show up my jerk of a teacher.

In my senior year of high school, I was handed a brochure for a scholarship program offered by an engineering school that paid your entire tuition if you studied cybersecurity. I didn't know much then, but I knew loans were a bad thing, so I went with it and attended that university. The final hook was a Capture the Flag (CTF) game hosted by the school. I had not pursued obtaining the scholarship until that point but playing in the CTF got me exposed to the other students and convinced me to go through it. You can read more about the NSF Scholarship for Service (SFS) program here: https://www.sfs.opm.gov/StudFAQ.aspx

I like to characterize myself as one of the first class of graduates with specialized degrees in cybersecurity (at least in the US). Anyone older than me is usually entirely self taught, anyone younger generally had exposure in an academic setting. I was about half and half. For reference, I am 32. I think the NSA Center of Academic Excellence program had a lot to do with that shift. Many US universities were first getting certified with new coursework to meet that standard through the mid to late 2000s, right as I was attending college. https://www.iad.gov/nietp/reports/current_cae_designated_ins...

FWIW I wrote a short career guide to help others trying to make sense of the field and how to get started. https://trailofbits.github.io/ctf/intro/careers.html

In fact, this year's Flare-On challenge just started today! It's an online game composed of 10-20 reverse engineering and forensics challenges that takes place over the next few weeks. There will be solution writeups after the challenge is over so you can learn how to solve whatever got you stuck. Give it a shot! Flare-On always gets great reviews for being fun to play, and online games (CTFs, wargames, etc) are a great way to get yourself started and add something to your resume. https://2017.flare-on.com/

I am now the CEO and co-founder of Trail of Bits, a high-end software security research firm. I will probably never quit the field. You can read more about what we do here: https://www.trailofbits.com AMAA?

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#9
post #5

Was minding my own business building malware, playing with crypto, researching ATM skimmers and anonymoizing networks when out of the blue I received an email from a local company offering a high paying job with benefits. It helps fast track you to get on their radar if you act super shady most of the time. Also start wearing a hoodie basically always (even when sleeping) and frequenting all night cyber cafes most ni…

To be clear to everyone, this guy is trolling. Poorly.

In fact being involved in creating malware in any way will often destroy any chances you have of getting into any serious technical security role.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#10
post #4
post #2

I’ve been a professional software developer for the last 4-5 years, but never took security serious until iot took off. Get some raspberry pis, install kali Linux on a VM or spare computer, and go to work! It’s just so easy and cheap to setup a pen test lab. I’d recommend every dev have a few attack machines for fun. That’s how I got started . It’s also a huge field. Try checking out security in your current discipli…

Skip the CEH and go straight for the OSCP. It's much more valued. Many in the industry seentu CEH as a joke. Good luck!

I don't disagree that CEH is inflated, and this coming from me, the guy who paid $1000 for the chance to test.

What the CEH does give people is a curriculum that they can adhere to. Not everyone can wrap their head around a complex subject like infosec alone. It's not a badge of honor, especially in a niche like infosec. But it does show you're serious about the field and willing to make a financial commitment. That's why i'd say it's worth considering if you're looking to make a career move. Of course, look at every other option and choose the best fit for you.

Post reply on HN