Ask a Penetration Tester Anything

InfoSec

Member
Joined
Mar 20, 2015
Messages
17
Reaction score
0
Hey Everyone

I work for a local information security company performing penetration testing (ethical hacking). We do a wide range of information security projects on different technologies ranging from mobile phones and point of sale devices to large enterprise windows networks.

We've started this thread for you to ask us anything about information security!

Looking forward to your questions :)

InfoSec
 
Has the penetrator ever been penetrated?
 
Thought the title meant something sexual but it is just a networking thing, so disappointed.
 
why cant EC Council allow me to take CeHv8 without a recommendation from a company I work for.
I'm a freelancer and would like to add these skills and offer them, and capable of self-study, yet I am not allowed to sit the exam unless a referral letter from my employers (who dont exist) who have a need for these skills, is received

I also think it is a bit of a joke that "we" have been doing pen testing since Adam made love to Eve, and a 3rd party who arrived on the scene after the fact is now in charge of deciding who can and cant sit the course (made up of materials, facts and findings that people prior to them "discovered", which they now utilise for profit), and other clueless bimbos wont contract you until you have sat their course.

Nicely stitched up *claps hands*

There, I've said my bit
 
why cant EC Council allow me to take CeHv8 without a recommendation from a company I work for.
I'm a freelancer and would like to add these skills and offer them, and capable of self-study, yet I am not allowed to sit the exam unless a referral letter from my employers (who dont exist) who have a need for these skills, is received

I also think it is a bit of a joke that "we" have been doing pen testing since Adam made love to Eve, and a 3rd party who arrived on the scene after the fact is now in charge of deciding who can and cant sit the course (made up of materials, facts and findings that people prior to them "discovered", which they now utilise for profit), and other clueless bimbos wont contract you until you have sat their course.

Nicely stitched up *claps hands*

There, I've said my bit

Why don't you just authorize yourself as you require it for your business?
 
Do you do any R&D or just use well known tools?

Yes, we frequently develop our own custom tools and hardware for projects. We have a lot of electronic engineers who put together some really cool stuff for us
 
why cant EC Council allow me to take CeHv8 without a recommendation from a company I work for.
I'm a freelancer and would like to add these skills and offer them, and capable of self-study, yet I am not allowed to sit the exam unless a referral letter from my employers (who dont exist) who have a need for these skills, is received

I also think it is a bit of a joke that "we" have been doing pen testing since Adam made love to Eve, and a 3rd party who arrived on the scene after the fact is now in charge of deciding who can and cant sit the course (made up of materials, facts and findings that people prior to them "discovered", which they now utilise for profit), and other clueless bimbos wont contract you until you have sat their course.

Nicely stitched up *claps hands*

There, I've said my bit

Hi Werner

An alternative to consider would be OSCP, this does not require any recommendation and is actually a more in depth course. It's also offered by the same guys who make Kali Linux.

https://www.offensive-security.com/...cp-offensive-security-certified-professional/
 
I did the CEH many years back - was a really fun exam. I mean what other cert will give you a tcpdump and ask you what exploit is being targeted :)
 
Yes, we frequently develop our own custom tools and hardware for projects. We have a lot of electronic engineers who put together some really cool stuff for us

How about tracing machine code?

Which debuggers do you use on Windows?
 
Top
Sign up to the MyBroadband newsletter
X