6 ms·
Ask HN: How did you get started in Network Security/Penetration Testing?
- igolden 9y agoI’ve been a professional software developer for the last 4-5 years, but never took security serious until iot took off. Get some raspberry pis, install kali Linux on a VM or spare computer, and go to work! It’s just so easy and cheap to setup a pen test lab. I’d recommend every dev have a few attack machines for fun. That’s how I got started. It’s also a huge field. Try checking out security in your current discipline. I was a web developer in 2013, so it was natural that I was inclined to look at SQL injections, XSS, packet sniffing, Etc. I already understood the domain. That is easier than jumping into reverse engineering firm ware if you have no xp. Now after a couple years of practice, I’m recommitted to security. Huge issue in our current tech ecosystem. I was just approved to take CEH and will be taking it next month. To make it official. If you need some structure to your learning and want to make a career move, check out getting an industry base cert like the CEH or offensive arc cert. most security jobs prefer candidates to have at least one, and they’re not incredibly difficult. Happy pwning!
- nickthemagicman 9y agoHey man this is really inspiring. I've been thinking about switching from web dev to security. How do you like it in comparison?
- igolden 9y agoRight now I am happy as a freelance software engineer. I wasn't looking for a new job (I wanted the KNOW), but I _was_ looking for validation among business-types. I also have a few certs from AWS, and attaining those created the validation I needed in Devops/cloud (so it can be worth it for career growth). Honestly, I just got tired of being THAT developer who willingly shirked his security duties. I always let someone else 'handle it'. In comparison now, I'm much more confident because I know (more) about securing the network and underlying ecosystem that my applications live in. I think most people hiring want to see a developer who is excited and puts out lots of work. I've always been pursuing this in my free time, which goes a long way to show that I am truly interested in the subject. But at the end of the day, your cert can't secure a network if you can't. Get the KNOW and you'll find an opp w/ or w/out the semantics. Hope that helps.
- nickthemagicman 9y agoThat helps thanks for the reply!
- sasas 9y agoSkip the CEH and go straight for the OSCP. It's much more valued. Many in the industry seentu CEH as a joke. Good luck!
- PeeryTwo 9y agoI wouldn't skip the CEH, at least not the material, but I wouldn't use it as a badge of honor on a resume either. It's a decent study guide as it exploses you to the nomenclature fairly well but it's far too easy to pass the certification without actually being proficient in anything.
- freehunter 9y agoThere is a massive difference between the CEH and OSCP. If he's ready to take CEH, I'd say do it and use that experience to begin studying for OSCP. OSCP is no fucking joke. It's hard.
- igolden 9y agoI don't disagree that CEH is inflated, and this coming from me, the guy who paid $1000 for the chance to test. What the CEH does give people is a curriculum that they can adhere to. Not everyone can wrap their head around a complex subject like infosec alone. It's not a badge of honor, especially in a niche like infosec. But it does show you're serious about the field and willing to make a financial commitment. That's why i'd say it's worth considering if you're looking to make a career move. Of course, look at every other option and choose the best fit for you.
- Txmm 9y ago"It’s also a huge field. Try checking out security in your current discipline." I'm actually 15 at the moment with basically no experience besides messing around with kali tools like a script kiddie. Got any tips for programming languages to learn/where to learn? I appreciate the post!
- graystevens 9y agoTake a look at either Ruby or Python - both have huge userbases in general, but are also used regularly within the business. A lot of quick scripts are written in Python - you may have noticed this in Kali. Ruby is what metaspoilt in built upon, meaning a lot of the modules are also ruby. Both are great languages. In regards to where to start with learning them, take a look at https://www.codecademy.com https://www.codecademy.com, both are featured there and give you a nice gentle introduction to their syntax and ways of workings. Also for Python there's https://learnpythonthehardway.org https://learnpythonthehardway.org which is awesome, and https://automatetheboringstuff.com https://automatetheboringstuff.com which is a little more practical to begin with. Once you feel comfortable with the language(s), go read the source code for those scripts or modules in Kali and see what else you can pick up.
- Txmm 9y agoThank You!
- raesene9 9y agoIn terms of languages I'd echo the sibling comment, Ruby or python are likely to be good choices. If you're looking for things to start getting into security type learning, you could do a lot worse than start with CTFs (https://ctftime.org/ctf-wtf/ https://ctftime.org/ctf-wtf/) Whilst they're not identical to what you'll face as a security tester, they cover a lot of similar skills. Also you'll likely meet people in the industry by doing them. There's also sites like https://pentesterlab.com/ https://pentesterlab.com/ which have free examples of pentesting challenges.
- Txmm 9y ago
- brer 9y agoWas minding my own business building malware, playing with crypto, researching ATM skimmers and anonymoizing networks when out of the blue I received an email from a local company offering a high paying job with benefits. It helps fast track you to get on their radar if you act super shady most of the time. Also start wearing a hoodie basically always (even when sleeping) and frequenting all night cyber cafes most nights of the week. Make sure to stare fixated at scrolling terminals continuously while you are there, at least 3 hours minimum per visit.
- freehunter 9y agoTo be clear to everyone, this guy is trolling. Poorly. In fact being involved in creating malware in any way will often destroy any chances you have of getting into any serious technical security role.
- dguido 9y agoI had an oppressive computer teacher in high school and I liked to pull pranks. It started out with simple password guessing, then phishing, then trojaned USB autoruns, SAM hash dumping, and password cracking, then some wifi sniffing... I never thought of what I was doing as hacking at the time (2001-2002). I just wanted to use the computer lab to play video games, and show up my jerk of a teacher. In my senior year of high school, I was handed a brochure for a scholarship program offered by an engineering school that paid your entire tuition if you studied cybersecurity. I didn't know much then, but I knew loans were a bad thing, so I went with it and attended that university. The final hook was a Capture the Flag (CTF) game hosted by the school. I had not pursued obtaining the scholarship until that point but playing in the CTF got me exposed to the other students and convinced me to go through it. You can read more about the NSF Scholarship for Service (SFS) program here: https://www.sfs.opm.gov/StudFAQ.aspx https://www.sfs.opm.gov/StudFAQ.aspx I like to characterize myself as one of the first class of graduates with specialized degrees in cybersecurity (at least in the US). Anyone older than me is usually entirely self taught, anyone younger generally had exposure in an academic setting. I was about half and half. For reference, I am 32. I think the NSA Center of Academic Excellence program had a lot to do with that shift. Many US universities were first getting certified with new coursework to meet that standard through the mid to late 2000s, right as I was attending college. https://www.iad.gov/nietp/reports/current_cae_designated_institutions.cfm https://www.iad.gov/nietp/reports/current_cae_designated_ins... FWIW I wrote a short career guide to help others trying to make sense of the field and how to get started. https://trailofbits.github.io/ctf/intro/careers.html https://trailofbits.github.io/ctf/intro/careers.html In fact, this year's Flare-On challenge just started today! It's an online game composed of 10-20 reverse engineering and forensics challenges that takes place over the next few weeks. There will be solution writeups after the challenge is over so you can learn how to solve whatever got you stuck. Give it a shot! Flare-On always gets great reviews for being fun to play, and online games (CTFs, wargames, etc) are a great way to get yourself started and add something to your resume. https://2017.flare-on.com/ https://2017.flare-on.com/ I am now the CEO and co-founder of Trail of Bits, a high-end software security research firm. I will probably never quit the field. You can read more about what we do here: https://www.trailofbits.com https://www.trailofbits.com AMAA?
- dfc 9y ago
- anon_dev_123456 9y agoI can tell you how not to do it. I'll never forget the funniest interview I ever had. I interviewed with this company called Deja vu Security. http://www.dejavusecurity.com/ http://www.dejavusecurity.com/ I explicitly told them, via email, I have ZERO experience pen testing, or anything related to hacking. I'm a terrific software engineer looking to pivot into this market, would take a salary cut to get my feet wet and be mentored. Would this be possible? Are you guys remotely interested in an arrangement like this? They say great, when can we sync up? That's definitely something we can do. So we set a call up and the call takes literally 39 seconds, I'll never forget it. He asked me what experience I had, and I reply: None whatsoever, like I mentioned in my email I'm interested in jumping into this line of work though. "Thanks but we're not going to move forward." Before I can even say thank you for your time, goodbye, the dude just hangs up the phone on me lol.
- throwaway74748 9y agoNot involved in the company, but fyi the reason for that is because this is the pentest equivalent of not having any github repo as a dev. There's virtually no barrier to playing/attempting a ctf or testing a vulnerable VM, so it's sensible to expect that of all candidates and shows a genuine interest.
- bitexploder 9y agoWe have a hiring process for folks with no infosec experience. It isn't easy, but it works. The guys at Deja are solid and consulting makes for busy folks, so don't hold a low opinion of them. Probably did not pay close enough attention to the initial email. If you are interested shoot careers at carvesystems dot com an email.
- brightball 9y agoCommunications breakdowns like that are funny. I remember communicating with a recruiter one time years ago that I'd be happy to do a part time contract to fill a need that I had a lot of experience with. He calls me up and immediately starts talking salary and full time so I had to re-explain everything that was in the email conversation as if he'd never seen it.
- 9y ago
- sillysaurus3 9y agoJust to clarify for everyone: Be careful switching your career to netsec/pentesting. If that's your thing, great. But you're likely to be a "lifer" because no one will want to hire you anymore for webdev. It's not quite as clear-cut as that, but if you're out of the game for N years, it's really hard to get back into it. Especially when you're not younger than 30. Ageism is a real thing.
- dguido 9y agoI don't think I agree with this, at all. It depends on what you do in security. If you work as a pentester or network security staff, then you might be trading a career in software development for a career in operations. In that career, it's more likely that you will be challenged _use_ tools, build processes, or fight political battles for consensus, rather than build software. On the other hand, there are many firms that hire primarily for security engineering and focus on building software. Any skills you have in software development will stay current, and your work in security would make you a better, and more desirable, software engineer. Anecdotally, I can name many people who have made the jump from security engineering to positions like VP of Engineering, CTO, or simply software engineering.
- sillysaurus3 9y agoSee the sibling comment. Both stories are common, but I think my story is far more common. We don't have data so it's impossible to know, but of course you'd see a lot of people go from security engineering to VP or CTO -- those are the winners. Survivorship bias is a nasty beast.
- dguido 9y agoI've only seen people make poor choices and limit their own careers. It's nothing inherent in the field of security that forces people to let their dev skills atrophy while turning into script kiddies or non-technical managers. You should be aware of what you are doing when entering ANY new field. Obviously, if you enter a job where you have to "fight for dev time" as the sibling comment you refer to mentions, then your skills as a dev will suffer. That's not a good career path if you think you might want to return to software development one day. Find a job in security engineering, of which there are many, where you have to fight to take breaks from coding instead. I think people have a confirmation bias that the security industry is made entirely of "netsec/pentesting" jobs since the news cycle is driven by hype from bug hunters, consultants, and vendor FUD. There are enormous numbers of people working on designing and building new security tools, capabilities, and research. Do that. Finally, I'd like to say that if my own company wound down tomorrow, I am confident that every single one of my ~30 engineers could find a job in software engineering in an instant.
- deleted 9y ago[deleted]
- Kikawala 9y agoI dabble in netsec, but not in it. My job requires me to work with our netsec team so I prefer to be familiar about the subject matter. I usually lurk on /r/netsec and they have a good resource on their wiki[1] on getting started in netsec. [1] https://www.reddit.com/r/netsec/wiki/start https://www.reddit.com/r/netsec/wiki/start
- dguido 9y agoThanks! I'm glad you found that useful (I'm one of the mods there). /r/netsec is no longer the smaller, more personal community it was when I started as a mod (7 years ago now?). If you're just starting out, one of the things I recommend most is finding a meetup in whatever city you live. It's hard to underestimate how useful an in-person conversation over a beer or two can be when you're early on. I guess my advice for you would be: take your netsec team out to lunch once in a while! :-)
- Eridrus 9y agoBy hacking the planet, duh. But seriously, I got started by writing exploits for long tail web apps.
- dguido 9y ago> But seriously, I got started by writing exploits for long tail web apps. I lovingly refer to this as "clubbing baby seals" and it is overwhelmingly common among younger hackers looking to polish their skills. :-x
- jnbiche 9y agoI understand the meaning of "long tail", but not sure what it means in this context. Is this an infosec term? I work in webdev and have never heard it used. Are you referring to less-commonly used web app frameworks?
- Eridrus 9y agoLess commonly used web apps; they tend to have poor security because no-one has cared/known enough to make them not horribly insecure.
- rhexs 9y agoI decided I wanted to get verbally assaulted by engineering teams I was reporting findings to day in and day out. Who would have thought, I managed to make a career out of it! (ps, if you do go down this route, try to find a job at a company with a good security culture. starting one from scratch is walking a road of broken glass)
- libpcap 9y agoBy typing a URL and clicking the "start" button on a pentest tool. :D
- mkhpalm 9y agoI got started for personal entertainment in darker corners of the internet. That ultimately evolved into me writing some of the tools people used in the industry. Eventually that developed into some SaaS products and 2 companies that we ended up selling. My advice to you if you are just getting started in the infosec world is... don't do it! Short of the increased attention to encryption and various better authz/authn standards... the newer crowd doesn't want to hear anything about the vulnerabilities in their code. 9 times out of 10 the only reason they'll resort to testing anything is to cross off a corp checkbox somewhere. Keep in mind that nobody likes policy and you'll be associated with their hatred for it.
- sebcat 9y ago> 9 times out of 10 the only reason they'll resort to testing anything is to cross off a corp checkbox somewhere Can confirm. The way it usually works is that Company X has N dollars allocated for security. Company X (or rather, a person or a team at Company X, with his/her/their own internal and external priorities and motivations) buys a service - recurring automated tests/assessments/pentests &c. This is where the usual corporate bullsh*t kicks in. If they want to show that they've done a good job in securing something, they buy a pentest over a short duration for a minor thing and then they claim "<trusted security vendor Y> said we were secure". If they want more money, they obtain data to show that. The infosec companies has a "customer is always right" mind-set. It's business. You can probably get good cash just for telling people to use TLS. Green padlocks and all that. EDIT: also, to differentiate infosec from regular security, don't forget to prepend "cyber" to everything.
- kgc 9y agoIn school, they taught us of the existence of Wireshark. It lets you see network traffic.
- vmarquet 9y agoA way to validate that you're genuinely interested in penetration testing and to learn is to do challenges on sites like https://www.root-me.org/ https://www.root-me.org/ for example. It's not necessarily realistic challenges, meaning there can be challenges on vulnerabilities you're very unlikely to see in real life, but you'll always learn something If the challenge does not teach you on some kind of vulnerability, at least it will teach you about how to think and do research, which is the most valuable. I've seen companies filter candidates based on their score on such platforms. For example, for a junior position in penetration testing, they asked for at least 3000 points on root-me (but it was a few years ago, the number of challenges on the site has increased so it would make sense if they had increased their minimum points requirement). Compared to certifications, it has two enormous advantages: it's fun, and it's free. I've started that way and never regretted it. I've not needed a certification to land a penetration testing job in a serious company (this was in France though, I don't know much about practices in other countries).
- unixhero 9y agoI never went in, but the baseline skills are there.* Let's just say I was forced to show up at the principal's office at several educational institutions during my youth :). I now sometimes make money doing white hat stuff.
- throwaway8367 9y agoA bunch of comments here warn that you may become unemployable in software engineering as a result. A so-called "security lifer". I think that's a little silly. I work for one of the top security consulting firms and it's just not my or anyone else I know's reality. In fact, the total opposite seems to be true. We have talented code reviewers and tool writers move on to work at tech companies all the time. These people are still interested in security and from what I've heard, they end up working on or even leading some really cool software engineering projects. I suppose if you woke up one day and decided that you're no longer interested in security at all, it may be difficult to pivot back if you stopped writing code. But that does not sound like the typical person who was originally interested in both security and code. Most security consultants I know who came from writing code really excel in security doing code review, architecture review, tool dev, etc. and those are all things that can translate back into software engineering experience on a resume. Of course some people's experiences will differ. There are plenty of employers out there who are biased or looking for a very specific background. But these cases are far from the norm. Perpetuating the whole "security is a dead-end, life-long job" narrative is spreading needless FUD and prevents the industry from maturing.