Security Basics mailing list archives

Re: Tools to use for Penetration Testing?


From: phillip bailey <phillip () cryptolife org>
Date: Fri, 03 Oct 2008 22:28:14 +0200

Adam Pal wrote:
Hi

Trying to start as a pen tester means a lot of work, since pentester depends on skills like innovation, new tools have to be written, new ways to be tried. If you expect to have all tools somewhere then you maybe are on the wrong way. You should get familiar with reading and searching on the web, a small search will lead you to tons of tools and material to start with. I am sorry that i wont name here any tools, but i dont want to destroy your way, since you will have to do a lot by yourself in this area. Nmap and wireshark is fine, but that is only the start (footprinting/sniffing). What will you do with the obtained information then? This is how you start and move forward.

but that is just my oppinion.

Seeing that you are up to spend a lot of money for CCNA and MCSE i also would like to suggest you to think carefully where you want to go - a certification is no magic wand anymore, CCNA is each penny worth if you plan to work on CISCO, MCSE is great if you plan to work with Microsoft or sysadmin on MS-Platforms, but it is definetly NOT a tool which can be used for each purpose.

best regards

Adam Pal

-------- Original-Nachricht --------
Datum: Wed, 10 Sep 2008 14:54:05 +1000
Von: "Chip Panarchy" <forumanarchy () gmail com>
An: Betreff: Tools to use for Penetration Testing?

Hello

I am interested in getting started as a white hat hacker/pen tester.

I would like to know what tools I should get familiar with, and be
able to use to be a pen-tester.

I only know of a few at the moment, and of them, I only use 2 (NMap
and Wireshark).

Can I please receive recommendations on tools to use?

Thanks in advance,

Chip Panarchy

PS: I am currently in training towards my CCNA and (maybe) MCSE.


Just to have a lot of tools in the same place I'll recommend you to use http://www.remote-exploit.org/backtrack.html , it' s a linux live distribution focused on penetration testing .

Regards,

phillip

--
Blog: wwww.cryptolife.org


Current thread: