3 ms·
Wow, this looks great, thanks for sharing! You mention this book as targetting pentesters. Do you have any advice on tools or skills to know for a software eng
by miccah 7y ago
Wow, this looks great, thanks for sharing!
You mention this book as targetting pentesters. Do you have any advice on tools or skills to know for a software engineer to transition to a pentesting role?
I ask because there are many resources for pentesting, but not any that I have found to reflect what happens in industry.
Thank you again!
- opsdisk 7y agoIn my experience, if you're going into security, it's good to have a solid foundation in either networking (routers, firewalls, switches), system administration, or software development. In your case, being a software engineer allows you to tweak, improve, or write your own tools. For example, some security tools have a hard coded HTTP User-Agent string that is flagged by security devices as a "hacker" tool. If you know how to go in and change it, it makes you harder to detect (assuming you're doing an ethical pen test / red team engagement). Check out Hack The Box (hackthebox.eu) which are a bunch of vulnerable virtual machines that can be hacked. It's totally free. The Offensive Security Certified Professional (https://www.offensive-security.com/information-security-certifications/oscp-offensive-security-certified-professional/ https://www.offensive-security.com/information-security-cert...) is the gold standard in terms of getting a cert. You get 24 hours to exploit 5 boxes and elevate to admin/root.