Showing posts with label ethical hacking. Show all posts
Showing posts with label ethical hacking. Show all posts

Monday, 22 July 2019

CEH vs OSCP

It's been eons since I've been on here to update you guys. Thanks for those who faithfully follow this blog, I'm grateful for your attention.

Well, like you all know, I'm still pretty new in this industry. From programming in 2009 - 2011 to IT security from 2012 (as a student) and now as a professional. I've bagged just about 4 years of industry experience altogether. Its been a journey!!

UPDATE
So at work lately, I've been working on a lot of vulnerability findings and analysis aka Pen testing on web applications. It hasn't been great because half the time, I'm confused if I did the right thing and if my findings are indeed accurate but well, I eventually figured it all out.

Based on this, I'm looking to get certified. Previously, I'd been looking into CEH or OSCP. Some swear by the OSCP and others say it's best to start with the CEH. Some others say the CEH isn't practical like the OSCP.

MY OPINION
From my findings, CEH has lots of practical components, and there's a practical exam to it too. OSCP is practical, true and a little advanced in my opinion for someone starting out in this career. If you have 5 years + in Pen testing, then you should go for OSCP.

WHAT's NEXT
As for me, I'm taking the CEH course online and also planning on the exam at some point. The course gives me enough help with practice and everything I need to know. It has also been updated. This is my opinion, I'd like to hear from you too. Thanks

P.S.
Did you all know that Kali Linux Revealed training is free on kali.training website?

Saturday, 4 February 2017

How to know what needs to be known

I have a problem choosing what particular course to take online, or what experiment to do in relation to InfoSec because I studied Computing and Security and I just finished studying Information Systems security (I am not satisfied though because universities choose what to teach you)..

I decided to choose what I wish to learn but then the more vulnerabilities and threats I assess, the more I want to know indepth about that area of infosec, I can't!!

Thank you Information Security you are so broad!!!

How to decide what path to take
I asked me, "what excites you about Info Sec"? Managing vulnerabilities, watching threats, helping to block out threats and fix problems. That brought me to ---> Pen testing. (I have only a year of experience in vulnerability management and threat analysis).

Okay, great! there's so much to know in Pen testing where do I begin? ARM/x86, scripting in python, learning to use more tools like nmap?

I need help!!!!

Currently I am taking a course in py, (I know, this is my second attempt at scripting, first it was js and I got bored but python has got me captured).
I am also taking a course in Ethical hacking along side and I am interested in Comptia A+ to know more about networking and dodgy request coming through. Argh!!! too much at one time but I need to choose between eth hacking and comptia, please help if you are a pro in this or have overcome this decision making process.
Thank you kindly!

Sunday, 29 January 2017

How time flies

Its been a while I was on here to keep you up-to-date with my experiments in IS security. I can tell you there hasn't been much done since my last post, the reason being that I have been swarmed up with work and I can't seem to get a breather.

This weekend, I am back on my course. I'm learning ethical hacking and afterwards reverse engineering.
I am also learning python along side but that's taking too long as the course is going through the first phases of programming (boring and I already know it) but I have to do it anyway because I can't skip!
I'll certainly keep you updated if anything new comes up.

The only new thing so far is the BEEF tool. (you can use this to hack a windows pc, that's how much I know at the moment).

Have a fun filled week doing what you love doing, hopefully that's something in IS security.