Penetration Testing mailing list archives

Re: Is there a scam in Security Certifications


From: "Rick Van Luvender" <rvanluve () comcast net>
Date: Thu, 1 Jun 2006 08:28:03 -0400

I did take your advice and query Mr. Bavisi directly regarding your research. Below is his response.

As for Mr. Bavisi's statement that the language regarding "EC-Councuil Universty is licensed by the State of Wyoming under Wyo. Stat. 21-2-401 through 21-2-407 and neither the Department of Education nor the Wyoming State Board of Education has accredited or endorsed any course of study offered by EC-Council University" being a statutory requirement, with a single google search I found the following information:

http://legisweb.state.wy.us/statutes/titles/title21/c02a04.htm

ARTICLE 4

PRIVATE SCHOOL LICENSING

21-2-401. License required; state board of education to administer and set minimum standards; in-state office required; on‑site inspections by state department.

(v) A copy of the enrollment agreement, contract or other document which acknowledges the enrollment of each student which is executed by each student at the time of enrollment or paying tuition fees other than applications fees. The agreement, contract or other document shall be made available at the time of the on-site inspection required under W.S. 21‑2‑401(d) and shall contain the following statement: "I understand that (name of institution) is licensed by the Wyoming department of education in accordance with W.S. 21‑2‑401 through 21‑2‑407 and that neither the department of education nor the Wyoming state board of education has accredited or endorsed any course of study being offered by (name of institution)."

From: Jay Bavisi
Sent: Thursday, June 01, 2006 1:20 AM
To:
Cc:
Subject: EC-Council

The post amazes me.

Anyway, I am of the opinion that anyone can hide behind the internet and fiere salvo and anyone else. I can claim that you are a martian too – that does not make it true :)

If there is a legitimate organization, then we have a legitimate answer for ALL of the non facts I see below.

EC-Council is called International Council , not American council.The whole world knows that we operate mainly from outside the US.The team in the US is based out of Laramie, Wyoming (where ECU licensed was granted).NY is a mere call answering service as a lot of people internationally do not know where Laramie is .

We ARE licensed by the state of Wyoming , and yes they are very hard on applicants, which is why we tool 2 years to form it! So obviously , this person has no idea what is a degree mill, an accredited University or a Licensed University!

The statement “From their university website "EC-Council University is licensed by the


State of Wyoming under Wyo. Stat. 21-2-401 through 21-2-407 and neither the Department of Education nor the Wyoming State Board of Education has accredited or endorsed any course of study offered by EC-Council University" is a STATUTORY requirement for us to comply with :)



The CNDA AND CEH are the same for now as we are told that the government hates the word HACKER. As such, we are testing this and if it is true, we intend to structure it’s future along the needs of government agencies. This is an open fact told to all ATC’s.

As for the members being fictitious – well , just check out the Hacker Halted pictures and news clippings and form your own opinion.

If you like, you may post this back but I think it will be a pure time waster. Just type hate Microsoft on Google and see what you get :)

The fact is , the more successful you get, the more negative attention you attract.

Jay Bavisi
EC-Council

----- Original Message ----- From: "xelerated" <xelerated () gmail com>
To: <adich71 () yahoo com>
Cc: <pen-test () securityfocus com>
Sent: Wednesday, May 31, 2006 2:24 PM
Subject: Re: Is there a scam in Security Certifications


Good research.... alarming to say the least.

I have a CEH cert. now im bummed.

But I also took the class. I did like the class, and it did have some
value for me.
I dont regret taking it at all. It filled in a few gaps that I had.

Makes me wonder about going after any others though.



On 28 May 2006 05:56:45 -0000, adich71 () yahoo com <adich71 () yahoo com> wrote:
I came across these posts recently at a forum


There is more hype than substance in EC-Council.


Check this link https://esos.state.nv.us/SOSServices/AnonymousAccess/CorpSearch/CorpDetails.aspx?CorpID=429981


EC-Council or International Council of ECommerce Consultants is a Nevada incorporated company and has NO office in New York as they claim. Pay them a visit and there is absolutely NOTHING there. Any enquiry called is always met with one response - please email. Try checking their claims before you invest in their products


EC-Council had announced an university earlier this year at Wyoming. They claim the certifications would get credits for their masters program. Its a diploma paper mill at best that will have its license revoked sooner or later as per the legislature revoking all unaccredited programs. Check this link http://legisweb.state.wy.us/2006/Digest/SF0069.htm


From their university website "EC-Council University is licensed by the State of Wyoming under Wyo. Stat. 21-2-401 through 21-2-407 and neither the Department of Education nor the Wyoming State Board of Education has accredited or endorsed any course of study offered by EC-Council University"


If you check their members list as well, you will realize that most of them are ficticious or hardly involved. Renaming the only program they sell is not going to fool the government for long I guess.


Check this link http://www.eccouncil.org/cnda.htm and compare it with http://www.eccouncil.org/CEH.htm - Its the same thing. What is the value for existing CEH if they are going to certify some of the candidates as CNDA?


Everything is the same. There is no alteration. Its not just money here... If some of us are going to be CEH and some CNDA, wont one destroy the value of the other? They are out to squeeze every last drop of money they can - think about it... To do LPT, you must have attended training. Check their website http://eccouncil.org/lpt/LPT-Course-Outline.htm


Look at the cost - 2500 USD and see what you get in return


Plaque with your name on it

LPT License card

Resource CD-ROMS

LPT T-shirts

LPT caps

LPT Certificate

LPT Lapel Pin

Membership ID


The million dollar question - license for what???



Why dont we go to archive.org to the wayback machine (as shown in CEH course) and look at EC-Council's site. ECSA / ECSP/ ECAD / LPT / etc have been announced more than a year ago. Why are there no certifications coming out yet?


The funniest part is that nobody else claims LPT is prestigious - nor is there an industry demand or recognition. LPT will grant you the license (to do what???). Please mail them and ask what the license stands for?





------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to win the Analyst's Choice Award from eWeek. As attacks through web applications continue to rise, you need to proactively protect your applications from hackers. Cenzic has the most comprehensive solutions to meet your application security penetration testing and vulnerability management needs. You have an option to go with a
managed service (Cenzic ClickToSecure) or an enterprise software
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service can
help you: http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit for you to confirm your
results from other product. Contact us at request () cenzic com for details.
------------------------------------------------------------------------------



------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security? Why not go with the #1 solution - Cenzic, the only one to win the Analyst's Choice Award from eWeek. As attacks through web applications continue to rise, you need to proactively protect your applications from hackers. Cenzic has the most comprehensive solutions to meet your application security penetration testing and vulnerability management needs. You have an option to go with a managed service (Cenzic ClickToSecure) or an enterprise software (Cenzic Hailstorm). Download FREE whitepaper on how a managed service can help you: http://www.cenzic.com/news_events/wpappsec.php And, now for a limited time we can do a FREE audit for you to confirm your results from other product. Contact us at request () cenzic com for details.
------------------------------------------------------------------------------



------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security? Why not go with the #1 solution - Cenzic, the only one to win the Analyst's Choice Award from eWeek. As attacks through web applications continue to rise, you need to proactively protect your applications from hackers. Cenzic has the most comprehensive solutions to meet your application security penetration testing and vulnerability management needs. You have an option to go with a managed service (Cenzic ClickToSecure) or an enterprise software (Cenzic Hailstorm). Download FREE whitepaper on how a managed service can help you: http://www.cenzic.com/news_events/wpappsec.php And, now for a limited time we can do a FREE audit for you to confirm your results from other product. Contact us at request () cenzic com for details.
------------------------------------------------------------------------------


Current thread: