Ask a Penetration Tester Anything

What advice could you give to someone who is a junior software tester and would like to get into penetration testing? What's the best way to break into the industry?
 
What advice could you give to someone who is a junior software tester and would like to get into penetration testing? What's the best way to break into the industry?

Hey there Ioc

The best way is to start researching penetration testing and information security, try to get a couple of vulnerable virtual machines and practise various exploits.

You could check out the following links if you are interested:

https://www.owasp.org/index.php/OWASP_Broken_Web_Applications_Project
https://www.vulnhub.com/

Companies like mine also offer an internship program where you will learn web application and infrastructure hacking. You're welcome to send me a PM if you want more information.
 
What advice could you give to someone who is a junior software tester and would like to get into penetration testing? What's the best way to break into the industry?

Hack the managers exchange account and schedule yourself an interview.
 
What does it take to become certified as a CEH and what are the salary ranges and the job market like?

Can you send me a pm about the internship?
 
What does it take to become certified as a CEH and what are the salary ranges and the job market like?

Can you send me a pm about the internship?

PM Sent

I would actually recommend you check out the OSCP. It is more highly regarded among penetration testers.
 
Hey ghoti

It is actually possible :)

Many companies will use something like the following for best practice configuration of machines within their environments:

https://benchmarks.cisecurity.org/t...t_Windows_Server_2008_R2_Benchmark_v2.1.0.pdf

Often the point is not to achieve total security, but make it secure enough that it deters the attacker and gives you time to detect and react to an attack.

Okay, Google dont seem to agree with you. Though I was talking more about the real weak points in security. IE, the receptionists desktop.

My next question. Do you ever come across government spyware, and if so how do you identify it?
 
Hey ghoti

It is actually possible :)

Many companies will use something like the following for best practice configuration of machines within their environments:

https://benchmarks.cisecurity.org/t...t_Windows_Server_2008_R2_Benchmark_v2.1.0.pdf

Often the point is not to achieve total security, but make it secure enough that it deters the attacker and gives you time to detect and react to an attack.

Just don't connect your windows box to the network/internet. Ever. Problem solved.
 
A dedicated attacker will be able to get into any system regardless of whether it is Windows, Linux or OSX. There are some very advanced groups out there such as the NSA, equation group, china etc. You should watch a talk by Jacob Applebaum on the capabilities of the NSA:

https://www.youtube.com/watch?v=vILAlhwUgIU

I think the message is that trying to completely prevent a breach is almost impossible and is the wrong approach. Many security professionals will tell you "assume that you've been breached, how good is your incident response?".

You rather want to secure your systems to a point that you force an attacker down specific paths and cause them to set off certain alarm bells. This then allows you to react before they can get to the crown jewels and get out.

On the government malware question, yes and it involves looking for specific behaviours.

Okay, Google dont seem to agree with you. Though I was talking more about the real weak points in security. IE, the receptionists desktop.

My next question. Do you ever come across government spyware, and if so how do you identify it?
 
Top
Sign up to the MyBroadband newsletter
X