HTTP/2 Request Smuggling
For anyone who lacks experience in information security or IT, getting into security testing may seem nearly impossible. But my own experience proves that successful lateral entry is possible.
Here I detail a number of options and tips for a successful entry into the field.
The field of security testing involves working from the “attack” perspective of the IT security industry. For security testers, this means carrying out penetration tests, social engineering campaigns and many other types of tests. How these tests are actually carried out can vary enormously. Because there are many different fields, and because they’re constantly developing, it’s vital that you keep acquiring new knowledge.
The first thing you need to do is find out if this field is right for you, because you’ll find the path far too difficult unless you’re sure and unless you have the drive to reach the goal of working in IT security. Taking this long path only to discover the work isn’t what you’d hoped or imagined is certainly something to be avoided. Because it’s certainly not what you see in movies. And a lot of consideration often goes into an attack. It’s also worth noting that the work doesn’t end once the attack is neutralized. Afterwards, you will have to prepare a report for the customer outlining what was tested, where the vulnerabilities were found and how they were handled.
Having an open mind is a must, as is a willingness to continue learning new things. After all, in a rapidly changing environment, you can’t just rely on old knowledge. For instance, an option for exploiting a vulnerability that may have worked two years ago probably won’t work in the same way now. The basic considerations behind them may well be the same, but technology can develop enormously in that time.
In my view, entry into this field requires sound basic training in IT. You will need to possess basic knowledge of the following areas:
That doesn’t mean you need to be an expert in each of these areas, however. But it’s important to at least have a basic understanding of all of them, as well as a more thorough grounding in at least one of these fields. Next, I’ll look at some of the ways you can acquire this knowledge.
If it is still an option and if you have the time and energy, the best approach is to complete an IT training program that will provide you with much of the groundwork you will need in your day-to-day work.
If a training program is no longer feasible or desirable, another option is to study at a technical college or university of applied sciences, for instance. This is the path that I chose. Looking back, I can say that there were times during my studies and in my work when I wished I already had experience in IT. If I could choose again, I would complete an IT training program right off. Remember, of course, that an IT degree requires a lot of work.
If you have sufficient interest and time, it is entirely possible for you to teach yourself. This is because many of the best-known figures in IT security didn’t take the direct route to get there. Unfortunately, the general climate in the field increasingly indicates that having the right diploma is key. For this reason, I would not recommend this route.
It’s possible to prepare for an entry into security testing, even while you’re still training or studying.
Start contributing to the community from the outset. For example:
It’s a good idea to start building up your network early on. You might start by searching for people from the industry on Twitter. Twitter is particularly worth mentioning, as a lot of information in the IT security field is shared there and spreads quickly. So if you don’t have a Twitter account already, make sure to sign up for one so you don’t miss out on the latest, most exciting information in the field. Once you have your account, start by following users, ideally people you have met at conferences. If you don’t know anyone in the industry yet, you can start by following your local OWASP and keeping an eye out for IT security events on Twitter. This gives you an idea of who is active in the field so that you can start building up your network. Twitter can also be useful for finding jobs, because jobs are sometimes even posted on the platform.
To gain initial experience in exploiting vulnerabilities, you can use projects set up for the purpose. These include WebGoat and the Hacking Lab, both projects of the OWASP. There are also many other projects set up in similar ways.
A basic knowledge of IT is vital for entry into the IT security field. There are various pathways that can take you to this goal. Whatever approach you take, IT security is constantly evolving, so a passion and willingness to learn are essential.
Our experts will get in contact with you!
Our experts will get in contact with you!
Further articles available here