LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-07-2018, 09:25 PM   #16
linuxbawks
Member
 
Registered: Apr 2013
Distribution: Snuckware
Posts: 240

Rep: Reputation: 17

Quote:
Originally Posted by SteelCitySteve View Post
I wish I knew someone who does it so they could give me some tips getting my foot in the door.

There has to be a handful of skills that once you know them would allow you to do entry level penetration testing.

Have no clue what those are, though.
Rip out nm and play with your network. Set up a mini infrastructure at home.
 
Old 04-09-2018, 08:30 PM   #17
JJJCR
Senior Member
 
Registered: Apr 2010
Posts: 2,174

Rep: Reputation: 449Reputation: 449Reputation: 449Reputation: 449Reputation: 449
Cool

Quote:
Originally Posted by SteelCitySteve View Post
I wish I knew someone who does it so they could give me some tips getting my foot in the door.

There has to be a handful of skills that once you know them would allow you to do entry level penetration testing.

Have no clue what those are, though.
Believe in yourself you can do it, there's quite a lot of resources on the net; videos, pdf, powerpoint, text files the list is not exhaustive but of course it has to be ignited by You.
 
Old 04-10-2018, 08:52 AM   #18
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
If you know there is a difference between say a "console" and a "terminal" regardless of how "other people" use those terms.
then you should be ok.

16 videos in this playlist
https://docs.kali.org/category/introduction
https://github.com/Security-Onion-So...onion/wiki/FAQ
http://www.linuxhomenetworking.com
https://www.linuxquestions.org/quest...erences-45261/
https://kali.training/


Have Fun!
 
1 members found this post helpful.
Old 04-12-2018, 01:28 AM   #19
JJJCR
Senior Member
 
Registered: Apr 2010
Posts: 2,174

Rep: Reputation: 449Reputation: 449Reputation: 449Reputation: 449Reputation: 449
Question

Quote:
Originally Posted by Habitual View Post
If you know there is a difference between say a "console" and a "terminal" regardless of how "other people" use those terms.
then you should be ok.

16 videos in this playlist
https://docs.kali.org/category/introduction
https://github.com/Security-Onion-So...onion/wiki/FAQ
http://www.linuxhomenetworking.com
https://www.linuxquestions.org/quest...erences-45261/
https://kali.training/


Have Fun!
How about if you combine the two, "terminal console"?

Good references below:
https://mikrotik.com/testdocs/ros/2.9/guide/console.php
https://superuser.com/questions/1446...google_rich_qa
 
Old 04-13-2018, 09:08 AM   #20
snowman81
Member
 
Registered: Aug 2006
Location: Michigan
Distribution: Ubuntu
Posts: 282

Rep: Reputation: 30
I've worked in security for awhile and have done some pen testing. I would recommend trying to get a job in a SOC or a small MSSP. It's not glamorous but it's a good foot in the door to the better things.
 
Old 04-13-2018, 10:38 AM   #21
SteelCitySteve
Member
 
Registered: Sep 2017
Location: Western PA
Posts: 39

Original Poster
Rep: Reputation: 0
Quote:
Originally Posted by snowman81 View Post
I've worked in security for awhile and have done some pen testing. I would recommend trying to get a job in a SOC or a small MSSP. It's not glamorous but it's a good foot in the door to the better things.
Sorry, what is a SOC or MSSP?

What I wanted to know is if there are things I could do that would land me some side work in this area.

For instance, if I got a Certified Ethical Hacker or Security+ cert, would that give me enough skills to get an entry-level job or be able to do side work so I can then gain real-world experience?

(Most roles in IT have to have some entry point that is attainable. If you wanted to be a web developer, you'd need to know HTML, CSS and Javascript. And if you knew those, you could probably make some $$$ using those skills.)

So how can I do that with Security and Penetration Testing?
 
Old 04-13-2018, 01:29 PM   #22
snowman81
Member
 
Registered: Aug 2006
Location: Michigan
Distribution: Ubuntu
Posts: 282

Rep: Reputation: 30
It's a bit different with security. Not a lot of people want to hire someone just starting out to work with sensitive materials and processes. Not a lot of part time work doing this either. Especially if they can be fined if you screw up. SOC is a Security Operations Center and MSSP is a Managed Security Services Provider. If you're really serious I would recommend getting those certs and working for an MSSP. Certs don't matter as much as experience.
 
Old 04-13-2018, 01:34 PM   #23
SteelCitySteve
Member
 
Registered: Sep 2017
Location: Western PA
Posts: 39

Original Poster
Rep: Reputation: 0
Quote:
Originally Posted by snowman81 View Post
It's a bit different with security. Not a lot of people want to hire someone just starting out to work with sensitive materials and processes. Not a lot of part time work doing this either. Especially if they can be fined if you screw up. SOC is a Security Operations Center and MSSP is a Managed Security Services Provider. If you're really serious I would recommend getting those certs and working for an MSSP. Certs don't matter as much as experience.
Are those basically web hosting companies?

I get what you're saying, but what about for smaller businesses?

There must be some things I could learn to help small businesses and non-profits be more secure and maybe make some side income so it becomes "real" experience.

Maybe installing firewalls?

Basic network hardening?

Penetration testing on company websites (e.g. Bob's Plumbing, Mary's Cakes & Cookies)?

Installing encrypted drives?

Patching systems?
 
Old 04-13-2018, 01:51 PM   #24
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Quote:
Originally Posted by JJJCR View Post
How about if you combine the two, "terminal console"?
I hate every word you said.

Get some!
 
Old 04-13-2018, 01:52 PM   #25
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Hack Your Neighbor with a Post-It Note

Last edited by Habitual; 04-13-2018 at 01:53 PM. Reason: Learning Resources
 
Old 04-13-2018, 02:03 PM   #26
snowman81
Member
 
Registered: Aug 2006
Location: Michigan
Distribution: Ubuntu
Posts: 282

Rep: Reputation: 30
Quote:
Originally Posted by SteelCitySteve View Post
Are those basically web hosting companies?

I get what you're saying, but what about for smaller businesses?

There must be some things I could learn to help small businesses and non-profits be more secure and maybe make some side income so it becomes "real" experience.

Maybe installing firewalls?

Basic network hardening?

Penetration testing on company websites (e.g. Bob's Plumbing, Mary's Cakes & Cookies)?

Installing encrypted drives?

Patching systems?
Yeah you could probably get a few gigs doing freelance type work and put it on your resume. Don't mind me, I'm a pessimist so I can find a lot of ways where it wouldn't work but doesn't hurt to try.
 
Old 04-19-2018, 09:37 PM   #27
AwesomeMachine
LQ Guru
 
Registered: Jan 2005
Location: USA and Italy
Distribution: Debian testing/sid; OpenSuSE; Fedora; Mint
Posts: 5,524

Rep: Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015
Foot in the door.

Quote:
Originally Posted by SteelCitySteve View Post
I wish I knew someone who does it so they could give me some tips getting my foot in the door.

There has to be a handful of skills that once you know them would allow you to do entry level penetration testing.

Have no clue what those are, though.
No one is going to let you pen test until they know they can trust you. Download metasploit framework, john and openvas. Learn how to use those, netcat, nmap, dsploit, and spoof. That's a good start.

Small law enforcement agencies and private investigators that can't afford their own full-time data-forensics staff often hire freelancers, You must be good with smart phones though, and that requires financial investment, XRY by MSAB.

You can also pick up a cracker for locked hard drives from Vogon UK.

Last edited by AwesomeMachine; 04-19-2018 at 09:48 PM.
 
Old 04-22-2018, 08:29 PM   #28
JJJCR
Senior Member
 
Registered: Apr 2010
Posts: 2,174

Rep: Reputation: 449Reputation: 449Reputation: 449Reputation: 449Reputation: 449
Hi AwesomeMachine,

Sounds like you've been down the road.

Quote:
You can also pick up a cracker for locked hard drives from Vogon UK.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: How to use Zarp for penetration testing LXer Syndicated Linux News 0 01-31-2017 08:40 AM
what is the procedure of penetration testing? zerop Linux - Security 7 05-16-2016 11:33 AM
penetration testing on home network nightphreak Linux - Security 5 10-24-2009 01:01 PM
Is penetration testing part of the IT policy where you work? win32sux Linux - Security 14 01-15-2009 03:52 PM
Beginer Penetration Testing Live Cds penguinlinux Linux - Security 3 05-03-2007 09:09 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:19 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration