Career Advise For Penetration Tester/White Hat Hacker
September 20th, 2008Last week, a common question was posted on the seclist.org website where Chip Panarchy ask which tools and certifications would be beneficial in learning to help to become a “white hat hacker/pen tester”. (Which a great in itself to see the interest of this field continue to grow.) This post received several great replies that ranges from a very specific tool listings to check out the Top 100 Network Security Tools Listing. Each post gave a valuable amount resources that not only helped Mr. Panarchy, but also other Penetration Testers alike.

The most interesting (and could be argued the most valuable) post was by a member named J. Oquendo, who did not follow the suit of list any tools at all, instead raised some very significant points of value in regards to becoming distinguished Penetration Tester.
I have highlighted some of the most valid points and added some commentary below:
Take the time to learn the protocols, how things work, learn how intercommunications work before attempting to just download every tool you can find.
In the “hacker” world, this is what differentiates a “5(R1P7 |<1DD13″ from the “L337″ or “UB3R” H4X0R5.
Understand how processes communicate with each other, how and why things happen. Its easier down
the road to understand what is going on in terms of security. One doesn’t need uber tools if one knows what they’re doing from the protocol level on up.
It has been in my experience that this is one the most crucial items, without understanding how each device communicates can you fully understand how the exploit works? Could you advise a remediation act?
Suggestion: Learn networking, learn systems, learn protocols otherwise you end up devaluing the works Understanding the entire range of the what you are doing is better in the long run, think about it, if I hired you to perform a pentest on my network and you couldn’t explain to me what it is you intend on looking for, how it works in my network, what functions my vulnerabilities perform, why I should remove these functions, I’d sit back in my desk and think the script kiddiot in you.
This comment can be looked at in two ways, first if you are hired for a pen test, your understanding of the technology is a direct representation of yourself. Secondly, what if you are the first penetration tester that a company has hired, and you have not taken the time to learn the essentials. The image that you represent is not only the your reputation, but it can represent the entire field of penetration testers.
Too many (quote) professional pentesters have been taking this attitude: “I use Cenzic!@$” that it makes me wonder where this industry is headed. It also makes me think about how many vulnerabilities unclued pentesters can bring into an environment.
Lastly, there is not one school or certification that can be taken that will turn you into a penetration tester/white hat hacker within a week and a test. They can only be used a stepping stones toward a long and laborious journey.
In closing… Becoming a distinguished Penetration Tester/White Hat Hacker is laborious journey and hours and hours of learning and sacrifice, that is both challenging and rewarding. This is the reason why some of the biggest and brightest minds are among the Penetration Testing/White Hat Hacker “Society”.
Matthew S. Becker

