Application Security Jobs/Functions

gld998

High Supremacy Member
Joined
Feb 21, 2008
Messages
38,406
Reaction score
2,327
Bros out there, how to get into Software Security? Meaning evaluating software/programs and run security test? My current organisation is using HP Webscan but I believe this is insufficient. What certification required? Anyone here can advise?
 

seesiang

Member
Joined
Oct 17, 2011
Messages
415
Reaction score
5
Bros out there, how to get into Software Security? Meaning evaluating software/programs and run security test? My current organisation is using HP Webscan but I believe this is insufficient. What certification required? Anyone here can advise?

HP Webscan?

Do you mean HP Fortify (to test on source code / static code) or HP WebInspect (to test on Dynamic code)?

What do you mean by certification? Certification to a person, organisation or..?
 

gld998

High Supremacy Member
Joined
Feb 21, 2008
Messages
38,406
Reaction score
2,327
HP Webscan?

Do you mean HP Fortify (to test on source code / static code) or HP WebInspect (to test on Dynamic code)?

What do you mean by certification? Certification to a person, organisation or..?

Sorry, its Web Inspect.

IT Certification rah.. like https://www.isc2.org/csslp/default.aspx

Is there any other alternative?:) Trying to beef up my profile for better job opportunity. :D Any suggestion appreciated
 

seesiang

Member
Joined
Oct 17, 2011
Messages
415
Reaction score
5
Thanks! I think I will skip CISA.

ISC2 and ISACA are one of the few most popular one.

Go for SANS if you are feeling rich.

If you want technical, there are a couple, namely CSFA, OSCP, ISO 27001 LA.

Security is a wide scope, ask yourself what do you want to do then aim for the related certifications.

I came from a Service Desk background then slowly climb towards Security, it is a long way in the past. Now it has accelerated so you can save a couple of years.
 

gld998

High Supremacy Member
Joined
Feb 21, 2008
Messages
38,406
Reaction score
2,327
ISC2 and ISACA are one of the few most popular one.

Go for SANS if you are feeling rich.

If you want technical, there are a couple, namely CSFA, OSCP, ISO 27001 LA.

Security is a wide scope, ask yourself what do you want to do then aim for the related certifications.

I came from a Service Desk background then slowly climb towards Security, it is a long way in the past. Now it has accelerated so you can save a couple of years.

I m more on project/ dev ops sides.. trying to avoid network side as I m trying to avoid auditing track, more focus on developer/application/software security side. so far, I only see CISSP n (CSSLP) from (ISC)2 relevant. Any other suggestions?


In the place I work, Auditors dont really add value, as they only scan n provide report, but dunno how fix all the loop holes correctly.

Anyway thanks for the response.
 
Last edited:

seesiang

Member
Joined
Oct 17, 2011
Messages
415
Reaction score
5
I m more on project/ dev ops sides.. trying to avoid network side as I m trying to avoid auditing track, more focus on developer/application/software security side. so far, I only see CISSP n (CSSLP) from (ISC)2 relevant. Any other suggestions?


In the place I work, Auditors dont really add value, as they only scan n provide report, but dunno how fix all the loop holes correctly.

Anyway thanks for the response.

http://certification-learning.hpe.com/tr/datacard/certification/ASE-FortSecV1

Go for this only if you want to be product-trained.

Apple may be red at Company A but Apple may be green or black at Company B.
 

Lastexile

Arch-Supremacy Member
Joined
Mar 6, 2004
Messages
11,718
Reaction score
126
Not sure why I am seeing people propose certifications from ISC2/ISACA/ISO for software security. I think those certs are good for paper pushers or people doing policies/audits at banks or whatsoever. I don't see how memorising definitions and procedures can help improve software security especially if you are trying to get developers to rewrite their codes.

The best way to do software security is to understand software vulnerabilities and exploit them because developers won't give a **** if you can't show them what will happen if they write insecure codes, management won't push for it without seeing the business risk. The hope is by knowing how to exploit vulnerabilities, one has enough understanding to propose fix for them - you need to know more than running tools like script kiddies.

I would encourage you go through the trainings/materials on

1. http://opensecuritytraining.info/Training.html
2. https://www.coursera.org/learn/software-security
3. Any other materials that go back to basics - programming etc.

I don't think you really need certifications for software security unless you are in a service provider environment (going for tender etc), but if you insist, I would recommend

1. GWAPT - Web application Security
2. GMOB - Mobile application Security
3. OSCP - System & Network & App Security <-- Probably the best for devops environment
 
Last edited:

gld998

High Supremacy Member
Joined
Feb 21, 2008
Messages
38,406
Reaction score
2,327
Not sure why I am seeing people propose certifications from ISC2/ISACA/ISO for software security. I think those certs are good for paper pushers or people doing policies/audits at banks or whatsoever. I don't see how memorising definitions and procedures can help improve software security especially if you are trying to get developers to rewrite their codes.

The best way to do software security is to understand software vulnerabilities and exploit them because developers won't give a **** if you can't show them what will happen if they write insecure codes, management won't push for it without seeing the business risk. The hope is by knowing how to exploit vulnerabilities, one has enough understanding to propose fix for them - you need to know more than running tools like script kiddies.

I would encourage you go through the trainings/materials on

1. http://opensecuritytraining.info/Training.html
2. https://www.coursera.org/learn/software-security
3. Any other materials that go back to basics - programming etc.

I don't think you really need certifications for software security unless you are in a service provider environment (going for tender etc), but if you insist, I would recommend

1. GWAPT - Web application Security
2. GMOB - Mobile application Security
3. OSCP - System & Network & App Security <-- Probably the best for devops environment

wow.. thanks!! Looks like i cannot escape OSCP.. :o
 

gld998

High Supremacy Member
Joined
Feb 21, 2008
Messages
38,406
Reaction score
2,327
any tips given now will be generic and probably useless.

talk to me when you are doing the lab.

this month abit broke cause renew COE.

2 ~ 3 months the road then I register provided I m not overwhelm at work. :(

Any tips that are free or cheap that I can prepare. Pls do take note that I actual have a small lab at home that I start to practice. 2x ESXi that I can spin up RHEL or W12r2 VMs and start practicing.:)

Edit: Found this.


There are no serious prerequisites for such certification.However you need to have a solid understading of network protocols,Kali Linux commands and bash scripting.I would recommend you went for the 3 month course which is enough time to practice on their network and read their instructions (pdf and videos).So where to start?
First of all everything you need is in the course material.Before you sign up I would recommend you watch some videos about ethical hacking.The following ones are very helpful for the course
https://www.cybrary.it/course/advanced-penetration-testing/ !!!!!
Also there are some books which can also help you during the course which are: Hackers Playbook 2,Metasploit Unleashed,Penetration Testing:Hands on (by Georgia Weidman). When you believe you are ready to root some machines you can find and download many of them at http://www.vulnhub.com (you download a vulnerable machine and you run it on virtualbox simultaneously with your kali linux).This way you can prepare yourself for the final exam which is quite the same (involves vulnerable machines to be rooted).You can also connect to VPN networks like those which are totally for practice:
https://lab.pentestit.ru/how-to-connect
https://ctf365.com
For exploits try the Exploit Database from Offensive Security.If you don't have time for this be sure to watch the videos from Cybrary and practice on vulnhub with the vulnerable machines.You can also find additional help and guidance from Google by typing : OSCP reviews - You will find a lot of help from other students.
Also take a look at those websites about privilege escalations.They will help. http://www.fuzzysecurity.com/tutorials/16.html
https://blog.g0tmi1k.com/2011/08/basic-linux-privilege-escalation/
http://toshellandback.com/2015/11/24/ms-priv-esc/
And sometimes you may have difficulties finding the correct exploit so download and try those small tools written in python.
https://github.com/GDSSecurity/Windows-Exploit-Suggester https://github.com/PenturaLabs/Linux_Exploit_Suggester
Python programming is not essential for the course,although there are some extra exercises in the course about it.However you should try writing some simple scripts.Try to use metasploit as little as possible because in the final exam it is prohibited and you may lose points using it.I suggest you go through the videos first and follow the instructor step by step.When you finish the exam you'll be required to write a report just a like you would do on a professional pen-test.You are given another 24 hours to write but it should not take more than 4-5.I read about someone writing a 400 page report :-X .There is no need to write a book :p .Your report must be around 50 pages.Don't be frightened by the exam time,it may be 24 hours,but it should take around 10 including a 2-3 hour sleep to refresh.I wish you luck with your exam.The OSCP is clearly the only cert that makes you technically and psychologically ready to perform a pen-test on a clients network.You will be able to get into unknown territories with complete confidence.At least that's how I felt :D
The are numerous certs out there about ethical hacking including CEH,LPT,GPEN,eLearn and also security-oriented certs like CISSP,CCNA Sec,Sec+,CISM all of them demanding renewal every 3-4 years (overpriced) and they don't even teach you how to break stuff,it's all about theory and multiple choice questions in the end.You can even go for a Msc degree in InfoSec neither that will teach you how to pen-test.It is totally fine if you want to become a security specialist/consultant/teacher but If you want to get into a pen-testing job especially without experience you go for OSCP.Even with the 3 month program it costs about 1100$ which is a very reasonable price for the skills you gain and the time (90 days) to educate yourself.


https://www.ethicalhacker.net/forums/viewtopic.php?f=58&t=12060

Anything u can share further inside?
 
Last edited:

Lastexile

Arch-Supremacy Member
Joined
Mar 6, 2004
Messages
11,718
Reaction score
126
I am not interested in talking about the prerequisite/material that you will do, i mean you can google all that by yourself and there are many many writes up about it. For PWK & OSCP, you will learn some tools, and how to break some stuff. However the most important thing is to develop your thinking process and problem solving methodology because more often than not you will be dealing with things you are not really familiar with. Also everyone has different style/approach, so there's no point for me to tell you to do from Step 1 to Step Z, you need to develop your style.

Therefore I am more interested in guiding your thinking process based on what you have done than going through like you need to know python programing or any XXX things. If you are facing something you don't know about and you think you need it, you go learn it, thats all there is to it.

If you want to practice, sure. You can download some virtual machines from vulnhub and go through them, they have a few vms that designed to be similar to the machines in PWK's lab.
 
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ Forums. Forum members and moderators are responsible for their own posts. Please refer to our Community Guidelines and Standards and Terms and Conditions for more information.
Top