9 ms·
I’ve been a professional software developer for the last 4-5 years, but never took security serious until iot took off. Get some raspberry pis, install kali Lin
by igolden 9y ago
I’ve been a professional software developer for the last 4-5 years, but never took security serious until iot took off. Get some raspberry pis, install kali Linux on a VM or spare computer, and go to work! It’s just so easy and cheap to setup a pen test lab. I’d recommend every dev have a few attack machines for fun. That’s how I got started.
It’s also a huge field. Try checking out security in your current discipline. I was a web developer in 2013, so it was natural that I was inclined to look at SQL injections, XSS, packet sniffing, Etc. I already understood the domain. That is easier than jumping into reverse engineering firm ware if you have no xp.
Now after a couple years of practice, I’m recommitted to security. Huge issue in our current tech ecosystem. I was just approved to take CEH and will be taking it next month. To make it official. If you need some structure to your learning and want to make a career move, check out getting an industry base cert like the CEH or offensive arc cert. most security jobs prefer candidates to have at least one, and they’re not incredibly difficult.
Happy pwning!
- nickthemagicman 9y agoHey man this is really inspiring. I've been thinking about switching from web dev to security. How do you like it in comparison?
- igolden 9y agoRight now I am happy as a freelance software engineer. I wasn't looking for a new job (I wanted the KNOW), but I _was_ looking for validation among business-types. I also have a few certs from AWS, and attaining those created the validation I needed in Devops/cloud (so it can be worth it for career growth). Honestly, I just got tired of being THAT developer who willingly shirked his security duties. I always let someone else 'handle it'. In comparison now, I'm much more confident because I know (more) about securing the network and underlying ecosystem that my applications live in. I think most people hiring want to see a developer who is excited and puts out lots of work. I've always been pursuing this in my free time, which goes a long way to show that I am truly interested in the subject. But at the end of the day, your cert can't secure a network if you can't. Get the KNOW and you'll find an opp w/ or w/out the semantics. Hope that helps.
- nickthemagicman 9y agoThat helps thanks for the reply!
- sasas 9y agoSkip the CEH and go straight for the OSCP. It's much more valued. Many in the industry seentu CEH as a joke. Good luck!
- PeeryTwo 9y agoI wouldn't skip the CEH, at least not the material, but I wouldn't use it as a badge of honor on a resume either. It's a decent study guide as it exploses you to the nomenclature fairly well but it's far too easy to pass the certification without actually being proficient in anything.
- freehunter 9y agoThere is a massive difference between the CEH and OSCP. If he's ready to take CEH, I'd say do it and use that experience to begin studying for OSCP. OSCP is no fucking joke. It's hard.
- igolden 9y agoI don't disagree that CEH is inflated, and this coming from me, the guy who paid $1000 for the chance to test. What the CEH does give people is a curriculum that they can adhere to. Not everyone can wrap their head around a complex subject like infosec alone. It's not a badge of honor, especially in a niche like infosec. But it does show you're serious about the field and willing to make a financial commitment. That's why i'd say it's worth considering if you're looking to make a career move. Of course, look at every other option and choose the best fit for you.
- Txmm 9y ago"It’s also a huge field. Try checking out security in your current discipline." I'm actually 15 at the moment with basically no experience besides messing around with kali tools like a script kiddie. Got any tips for programming languages to learn/where to learn? I appreciate the post!
- graystevens 9y agoTake a look at either Ruby or Python - both have huge userbases in general, but are also used regularly within the business. A lot of quick scripts are written in Python - you may have noticed this in Kali. Ruby is what metaspoilt in built upon, meaning a lot of the modules are also ruby. Both are great languages. In regards to where to start with learning them, take a look at https://www.codecademy.com https://www.codecademy.com, both are featured there and give you a nice gentle introduction to their syntax and ways of workings. Also for Python there's https://learnpythonthehardway.org https://learnpythonthehardway.org which is awesome, and https://automatetheboringstuff.com https://automatetheboringstuff.com which is a little more practical to begin with. Once you feel comfortable with the language(s), go read the source code for those scripts or modules in Kali and see what else you can pick up.
- Txmm 9y agoThank You!
- raesene9 9y agoIn terms of languages I'd echo the sibling comment, Ruby or python are likely to be good choices. If you're looking for things to start getting into security type learning, you could do a lot worse than start with CTFs (https://ctftime.org/ctf-wtf/ https://ctftime.org/ctf-wtf/) Whilst they're not identical to what you'll face as a security tester, they cover a lot of similar skills. Also you'll likely meet people in the industry by doing them. There's also sites like https://pentesterlab.com/ https://pentesterlab.com/ which have free examples of pentesting challenges.
- Txmm 9y ago