pen-test
[Top] [All Lists]

Ethical hacker/penetration tester skills and certifications

To: <pen-test@securityfocus.com>
Subject: Ethical hacker/penetration tester skills and certifications
From: "Steve Fletcher" <safletcher@insightbb.com>
Date: Fri, 29 Dec 2006 00:19:03 -0600
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
Resent-date: Fri, 29 Dec 2006 18:00:35 -0700 (MST)
Resent-from: pen-test-return-1078483342@securityfocus.com
Resent-message-id: <20061230010035.6F279341777@outgoing2.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
Thread-index: AccrETwaJ3d3Exp0QCu6DQr0eOB1NA==
I am working on a magazine article on the job roles of ethical hackers.  It
is supposed to include what an ethical hacker does, the skills and
certifications that might be required, and the typical career path.  I
wanted to see if anyone on the list could provide some useful information. 
Here is what I have so far.

Skills:
Knowledge of a number of programming languages, such as C, C++, Perl, and
Python

Intimate knowledge of networking protocols, especially the TCP/IP suite

The ability to think ?out of the box?

Certifications:

CEH, ECSA, and LPT from EC-Council - I also mention that the validity of
these certifications has been questioned recently

Certified Pen Testing Specialist (CPTS) from mile2

OSSTMM Professional Security Tester Accredited Certification (OPST) from
ISECOM

Background:
I wasn?t really sure here.  I?m sure that ethical hackers/penetration
testers come from a variety of backgrounds in the IT field.  I specifically
mention programmers and network administrators.

Career Opportunities:
This is another area I am not real sure on.  I mention penetration tests as
the primary job role with a penetration test defined as trying to gain
illicit access to a network for purposes of finding and resolving problems
before the bad guys.  (I?m trying to keep it simple.)  Of course, most often
a penetration tester would either be an independent contractor or work for a
security service provider.

I am extremely concerned with making sure that I provide accurate
information in this article, so any corrections or additions to what I have
here would be greatly appreciated.  Depending on the response I get, I might
quote the reply in the article, with the permission of the author.

Thanks,

Steve Fletcher
MCSE (NT4/Win2k), MCSE: Security (Win2k), HP Master ASE, CCNA, Security+
Email:  safletcher@insightbb.com
Web:  http://safletcher.home.insightbb.com
 


<Prev in Thread] Current Thread [Next in Thread>
  • Ethical hacker/penetration tester skills and certifications, Steve Fletcher <=