Careers in security, ethical hacking and advice on where to get started
troyhunt.com
troyhunt.com
- https://www.corelan.be/index.php/2015/10/13/how-to-become-a-...
- https://tisiphone.net/2015/10/12/starting-an-infosec-career-...
- https://danielmiessler.com/blog/build-successful-infosec-car...
"Owasp Testing Guide V4" is a must read for web hackers, at least for starters: https://www.owasp.org/index.php/OWASP_Testing_Guide_v4_Table...
OWASP has vulnerable application projects for you to play with, such as WebGoat "https://www.owasp.org/index.php/Category:OWASP_WebGoat_Proje..., but there are many applications like these such as "DVWA - Damn Vulnerable Web Application" and variants in Node JS (https://n0where.net/damn-vulnerable-node-application-dvna/)
I also developed two free courses on "WordPress Security" and "Docker Security" https://dadario.com.br/courses/
The point is to learn development / infrastructure first, then study attacks and defense to develop a security mindset. Get involved in bug bounties, but learn how to fix, don't let your code skills rust. Then learn more security concepts, how to build a corporate security program and keep moving :)
There's also a very famous book in the area: "The Web Application Hacker's Handbook" http://mdsec.net/wahh/
How do you get started breaking shit? Github has tons of shit. Go break it. More interested in hardware? Go buy some crappy iot gear and break it. Vulns are not rare and they do not require a damn piece of paper to find. Find them, and you will have no problem finding jobs.
If you are reading this and still don't know where to start, I am happy to help you find things to break and suggest approaches that might help. But seriously,don't waste your time and money getting certified. I don't care at all.
My best colleagues, the people I most deeply respect and the people who inspired me to work in this industry all neglect bug bounties. They mostly don't participate in them at all. Bug bounties are usually pursued by people who have the free time and bandwidth for them. For the most part, most security consultants and engineers do not actually engage in them because they are already highly paid. This is why you most frequently see bug bounty participants from countries other than the United States and Western Europe.
Those that do have a full-time position and also engage in bug bounties certainly have a commendable passion for the work (or sometimes more accurately a workable formula for getting to low hanging fruit in new programs first), but please don't expect all or even most skilled security talent to adhere to this rule. Many people enjoy being skilled without sacrificing work-life balance. Just as not every software engineer needs to contribute to open source or have a GitHub profile, not every security engineer needs to have badgers for every company they've hacked.
The folks at Attrition tend to cover it a bit more when it comes to "security rockstars":
There are no employers in security that I know that anyone wants to work for that take certification seriously. The best people working in security --- not just in application security but in network security, red-teaming, exploit development, and cryptography --- don't have certificates.
If you want to work in startups, a hiring process that even asks if you have a certification is a big red flag. This is less true in the broader tech industry, but while it's probably not a good idea to discard a prospective Fortune 500 employer just because they ask if you have any certifications, it is certainly reasonable to pull the ejection lever hard if an employer cares about them.
Every minute you'd spend pursuing certification is better spent building programming skills.
For whatever it's worth, I still stand behind everything in here:
https://krebsonsecurity.com/2012/06/how-to-break-into-securi...
I've seen this sort of outlook (usually without the textbook) across the board. Either a company will train people from scratch, or they want to see applicants with actual records of working security, finding and reporting vulnerabilities, or patching holes in OSS.
"Have a certificate" is nowhere on that list. It probably can't hurt for a candidate, but I certainly don't think it will bridge the gap from inexperienced to experienced the way an actual work record would.
Having a certificate actually can hurt you, for elite jobs (it's not really going to hurt you if you're just breaking into the field).
I'm not saying it should be. If you're hiring exploit developers, your process should begin and end at having candidates build model exploits. But almost nobody hires like this; most organizations have tea-leaf-reading hiring processes, and proudly advertising that you have a CISSP or CEH is one of the tea leaves they read.
The timing never worked out, but applying to Matasano was tied to the start of my interest in security. It was one of the most welcoming and positive interview processes I've ever seen.
Using systems administration as an analog, there exists a class of sysadmins who can't write even basic scripts. Their ability to troubleshoot or problem solve are limited to using predefined tools. Whole categories of tasks will be infeasible for them to accomplish (mostly because of the amount of time it would take to do them manually, not necessarily because they are technically impossible).
Lacking the ability to do any programming limits their job prospects to the bottom of the sysadmin barrel. That being said, programming isn't necessarily a prerequisite for their job, it's just a ceiling.
Going back to security, most tasks benefit from the ability to automate some part of them. I come from application security, where that frequently manifests in having to quickly piece together tools for interfacing with a specific protocol or API. Application consulting exacerbates that even more, because you'll usually have to do all of this in a very short amount of time, so that you can spend the allotted assessment time actually doing the assessment, and not trying to get your tools to work with the environment.
My experience is that the Australian tech scene (I don't live there anymore) is in many ways similar to the 1990s in the U.S. Customers and recruiters ask about certificates. Hell, you typically have to go through a professional recruiter in order to get a job; it is often not possible to apply directly to companies.
I am generalizing and also talking about my experience in Australia about 8 years ago. Maybe everything has changed.
Blog posts like that are designed to steer traffic towards course views and "time watching the content", without which PluralSight authors don't get paid.
But: thank you!
I'm pretty confident in my answer here.
If you want to know whether someone understands disassemblers, debuggers, exploit code writing, and assembly, have them do tasks that involve disassemblers, debuggers, exploit code writing, and assembly. We had that problem, and we built Microcorruption to address it. But you don't need anything that elaborate.
I get that most firms don't hire this way yet (all of them will within the next 10 years). But so far as I know, none of the reputable firms rely on certifications. Of the top, say, 20 "offensive security" people I know, not one of them has any of these certifications.
If there's a major firm that outsources this stuff to certification programs, that would be surprising news for me.
I am slowly working towards moving us into a position where we have more practical methods of finding out if candidates understand the above, but it takes time for me to develop testing methods etc. while simultaneously completing everything that needs to be completed.
If you have any recommendations, I'm more than open!
The most common mandate I currently see is "CCNP Security", which shows up as a hard requirement regularly, even in non-Cisco shops. I could never bring myself to invest time for such a thing - feeling it largely conflates "security" with "buy firewalls".
While I'm talking to you, thank you for the cryptopal challenges. They were a very good departure from the compliance based security I usually have to deal with.
[1] http://www.itnews.com.au/news/should-aussie-cyber-security-p...
Some have even suggestion "cyber conscription" to force people to do government work if they're capable. This, and the recent articles indicating that the government wants people to "volunteer" their time goes to show that they want people for the lowest possible price.
The problem in Australia here is no different to overseas: the focus is on useless certifications and compliance, cheap resources, and security theatre. CEH and CISSP are alive and kicking because of this.
All of the above is beside the point. Troy made CEH PluralSight content because PluralSight's people wanted it. It's really that simple. The blog post is just marketing for that content.
Yes but the majority of enterprises are not in the industry. These stupid certifications are being pushed by our largest accounting firms (where Arno Brok is connected), and these are influential to business leaders.
> Troy made CEH PluralSight content because PluralSight's people wanted it
I hadn't considered that. Good point.
>the focus is on useless certifications and compliance
It's hard to explain to people in "real" security just how hopeless the current "compliance security" situation really is. Consider this situation. A user goes on holidays for two weeks. Before leaving, they turn off their laptop and lock it in a cupboard.
I've just described a critical incident. I can expect to be writing up incident reports, and reporting to management on "root cause" and how we can avoid this incident recurring. Can anyone in "real security" even see the problem?
Why, after two weeks, their desktop antivirus is out of date.
I feel your pain in those latter points.
0. Do not pursue certifications at all.
1. Learn to code. C + Python is a great choice, to start with (or C + Ruby).
2. Start with application security, because it's the easiest place to get your feet wet.
3. Work through The Web Application Hacker's Handbook (don't just read it).
4. Find bug bounties in as many programs on BugCrowd or HackerOne as you can. Extra resume points (and money!) for bug bounties in Google, Facebook etc.
5. Join a reputable security consultancy (NCC Group, Optiv, Bishop Fox, etc.) and mature your skills.
6. Decide how you'd like to specialize.
This is true because of the availability of targets, however, the easiest place to get your feet wet is not the same thing as the easiest discipline and people must keep that in mind. Application security is the toughest of the discipline's in my book; far tougher than netsec, oppsec, and many others because it's a world of vast diversity of solutions. It's also a world of vast diversity in attacks from SQLi to XSS, to remote unauthenticated remote code execution, to the identification of logic errors which result in the exposure of sensitive information.
What do you mean by that(application security) ? Can you explain me? (Sorry for bad english)
Why not?
I somewhat disagree with this statement. While I agree completely that certifications do not equate to ability, education is never a bad thing.
For example, many of the SANS GIAC courses are run by industry experts that have a lot of real world experience. For example, I took the GCIH taught by John Strand (BHS) and the GCIA taught by Mike Poor (InGuardians) with material joinly developed with Judy Novak.
This may be unique for SANS courses, but I personally found combining quality education material with well vetted instructors that have real world experience to be quite useful.
It's certainly not a substitute for having real world experience, but quality education can be worthwhile.
1. Graduate from any school with a degree in CS/CE/Math/Physics.
2. Solve one crackme in your free time.
3. Apply for all entry level jobs at GENERIC DEFENSE CONTRACTOR that involve keyword "ida pro." Prepare to move to a deserted town in Florida or the DC megalopolis.
4. Die on the inside when you spend years working on unbelievably complicated problems that do nothing else except get a government employee promoted. Have everyone else in the news/online tell you you're evil.
5. Spend several months working for a government employee that is amazing at what he or she does. (part of the 20% of employees doing 80% of the work)
6. Watch as that employee is immediately promoted and replaced by someone else who doesn't care.
7. Try to transition to non-defense and discover that for all the talk about "cyber!!!!" and infosec in the news, all anyone actually wants is an IT professional that took a one week course at Blackhat on exploitation/has meaningless certificates/knows how to buy and install Nessus products and Palo Alto products. That has to be 90% of the job postings out there.
In all seriousness, if you do think you want to go down the government route, stick to a dedicated research institution or try to get a federal job. There are a very, very small few defense contractors that truly do good work, but they burn too bright and are eventually snuffed out by corporate greed or insane management.
Raytheon SI, Mantech, and Booz Allen Hamilton have some decent contracts; yes they are in Melbourne and Annapolis Junction (where else would they be in the U.S?).
It's hard to get involved in the smaller firms, because DoD wants to keep the best employees from going to these contractors to do their current job for 2x the pay.
I'm biased, but I think the better way is to start federal, get into a cool 3-year rotational program for poverty wages, and then go contractor once you've paid your dues for a couple of years.
This is, of course, pretty damn niche for infosec. Most infosec folks I've met in the industry have no exposure to this.
Federal jobs are pretty awesome everywhere except extraordinarily expensive cities. Unfortunately, a good percentage of them are based exactly there. :) (Also, a bit easier to admire the benefits and stability they offer when you're older. Early 20s me would laugh and then apply to whatever popular corporate grinder was hiring for prestige and 6000 hour weeks.)
Grass is always greener.
In general though, the prevailing sentiment has been that demonstrated experience is the #1 factor. Infosec isn't a career path that begins as a totally oblivious hire after floating around in college. It begins in your bedroom in the evenings poking around bug bounties or playing on hackthissite.org and its forums and that sort of thing. A professional setting isn't required to gain some good real-world experience, so there's no reason you should be inexperienced by the time you're sitting for your first professional interview.
If you consider HR as a first firewall to get past, that may make CISSP certification not such a terrible option. If you can get past the outermost protection layers, you can start poking at the inner layers that may be more soft and squishy.
Check out a few sample questions: http://www.gocertify.com/quizzes/ceh/ceh1.html
Also review their attrition.org page that exposes how they just copypaste their material from other authors. http://attrition.org/errata/charlatan/ec-council/
Especially this part: http://attrition.org/errata/charlatan/ec-council/history_and...
Oh yeah, EC-council keeps your passport scans and other PII unencrypted in their gmail inbox. I would know, I hacked them once. https://cdn.arstechnica.net/wp-content/uploads/2014/02/EC-ha...
Stay away from CEH and EC-Council, don't support these scumbags. They're just a bunch of charlatans that managed to grow their paper mill by spamming and stealing material from others.
EDIT: Oh! But there's more! Apparently they like to serve ransomware on their website http://arstechnica.co.uk/security/2016/03/ethical-hacker-web...
tl;dr: stay the fuck away from CEH and EC-Council.
It was an analogy to get your to understand that what you are saying is silly.
(I'm 22+ years in the industry, for whatever that's worth.)
What it should tell employers however is that the person is capable of critical thought and has a light familiarity with a wide range of security concepts.
>That’s bad for employers but good news for cybersecurity workers, who can command an average salary premium of nearly $6,500 per year, or 9% more than other IT workers.
Why are the technical skills (in this article specifically) so demanding, but yet the salary is only 9% higher?
Same for the other career-starting directions given here -- most of which seem like multi-year time investments. Many of them ask even more of your technical ability than the article before entering the field with a salaried position, and yet that's only worth 9% extra salary?
$6,500 / year? Am I misunderstanding the term "salary premium"?
Also the bar graph confuses me. Shouldn't cybersecurity positions be included in "all IT positions"?
The average IT worker makes $72000, while cybersecurity workers are making $78500, a 9% premium
[1] https://www.defcon.org/images/defcon-16/dc16.../defcon-16-ob...
I think $6,500 per year is very low...
Of course, it's still a bit of a silly comparison, because the distribution on "IT" is so wide that you don't learn much without bucketing further.