Skip to main content

Before Learning Vulnerability Assessment and Pentration Testing


What one should learn before practicing Vulnerability Assessment and Penetration Testing.
  • One should have thorough understanding of at least one of the operating system out there in the market. I prefer Linux based operating system but there are others also. Basic understanding includes knowing about, how does an operating system starts, when does kernel gets loaded, what is boot loader, what is 'init' process, when does network services start etc. 
  • Knowledge of computer networks is also indispensable. You should know what is a network, network protocol, TCP/IP suite, what exactly happens when a network interface card is turned up etc. I mean you should be able to know how things work.  
  • Learn about the database systems and get your hands dirty with query languages like  SQL and others. Having a functional knowledge of databases system, will make it easy for you to practice against web applications.
One last point that i want to make is that if you have zeal and curiosity to learn these stuff, you are ready to go !


Some Links worth sharing:-

Comments

Popular posts from this blog

M.S in Cyber Law and Information Security(MS-CLIS) at IIIT Allahabad

The course provide an exhaustive blend of Technology and Legal requirement that are often sought after by the concerned industry. MS-CLIS students receives grounding in programming, security auditing, logic and cryptography, in addition to policy and legislative procedures. The education is at par with certifications like CISA, CISM and CISSP. “The knowledge that MS-CLIS students have at the end of the course is the same, as expected of a person holding all these certifications, and more,” says Dr. Abhishek Vaish , the faculty coordinator for placement at IIITA . Well, above is an objective view of the institute and the course, but this is my blog, and i possess the right to write my views and experiences with this course. I joined the course in july 2013 and within a fortnight after joining the course, I found out that i was quite naive before, my  understanding of information security was not holistic. It was a big surprise as i could never have had imagined the enormous d...

Did i miss to assetize Virtual Machines !

Auditee : Hi There ! Welcome, What would you like to have? Tea or Coffee? Auditor: Asset Register ! A comprehensive Asset Register is something which is quintessential for any risk management program. Everything that has to do with risk, follows from here. Information Security Risks are no different that any other type of risks. Having a few people (rarely security pro) building asset register will probably mess up any risk management at the very first stage. It has been seen that people generally miss to address technologically advanced assets (The ones they did not understand a few years ago)  to register in their asset inventory. The most obvious are the virtual machines.  Every day ,Virtual Machines (VM) are being created on the fly as per business requirement, many of them persist for years and many not so much. There are many questions  like: if that particular VM is of some value? Do I need to consider it as valuable at this point of time, whe...

Before "Security" becomes a cliché in your organization

With the proliferation of automated hacking toolkits and amusement that news channels create when some popular website gets hacked or defaced, every IT guy have heard of "security" at least as many times as it is sufficient to  make it sound boring.  Many researches held at universities across the globe shows good correlation between poor employee engagement with poor interest in efficiently fulfilling their jobs. Similarly there are some researches that emphasize on the phenomenon that effective security depends on employee engagement rather than hard compliance. With all of this taken into consideration it is not that difficult to say that talking about security more than required number of times can make situation worse. The problem that organizations are facing today can become daunting with more and more noise about  security. It is high time for CXOs to maintain a balance and keep providing filtered information about security at right time and amount. No o...