<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Pentesting Skillset</title>
	<atom:link href="http://hexesec.wordpress.com/2008/07/05/pentesting-skillset/feed/" rel="self" type="application/rss+xml" />
	<link>http://hexesec.wordpress.com/2008/07/05/pentesting-skillset/</link>
	<description>sudo apt-get install ... security?</description>
	<lastBuildDate>Mon, 28 Dec 2009 10:12:56 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Building the pentest team skillset &#8212; spylogic.net</title>
		<link>http://hexesec.wordpress.com/2008/07/05/pentesting-skillset/#comment-86</link>
		<dc:creator>Building the pentest team skillset &#8212; spylogic.net</dc:creator>
		<pubDate>Wed, 15 Jul 2009 01:50:49 +0000</pubDate>
		<guid isPermaLink="false">http://hexesec.wordpress.com/?p=8#comment-86</guid>
		<description>[...] saw this post on Hexesec the other day that made me think about all the skill&#8217;s that when you put them together could [...]</description>
		<content:encoded><![CDATA[<p>[...] saw this post on Hexesec the other day that made me think about all the skill&#8217;s that when you put them together could [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Panarchy</title>
		<link>http://hexesec.wordpress.com/2008/07/05/pentesting-skillset/#comment-29</link>
		<dc:creator>Panarchy</dc:creator>
		<pubDate>Fri, 12 Sep 2008 06:01:12 +0000</pubDate>
		<guid isPermaLink="false">http://hexesec.wordpress.com/?p=8#comment-29</guid>
		<description>Thanks

I&#039;m going to print this out.

And learn as much as the things from the list as I can.

For pen-testing and white hat hacker, this&#039;ll be a good goal to set myself.</description>
		<content:encoded><![CDATA[<p>Thanks</p>
<p>I&#8217;m going to print this out.</p>
<p>And learn as much as the things from the list as I can.</p>
<p>For pen-testing and white hat hacker, this&#8217;ll be a good goal to set myself.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jcran</title>
		<link>http://hexesec.wordpress.com/2008/07/05/pentesting-skillset/#comment-28</link>
		<dc:creator>jcran</dc:creator>
		<pubDate>Wed, 03 Sep 2008 04:45:30 +0000</pubDate>
		<guid isPermaLink="false">http://hexesec.wordpress.com/?p=8#comment-28</guid>
		<description>Tom, 

definitely, this was aimed as more of a wish-list for a team.  

it would be interesting to put together a maturity model for a pentesting team. -- what skills are absolutely (day-one) necessary for a generic pentest. i guess it depends on the network / idea of a &quot;generic&quot; pentest. 

surely though, there should be some way to boil down to skills which are more essential:
 - networking
 - unix / linux
 - security mindset
 - scripting (debatable, but imo necessary...)

and those that are secondary (again, depending on a lot of factors):
 - scripting++
 - networking++
 - unix-foo
 - web-app skillz

etc.

again, all of this is debatable, and depends on the environment which needs testing. 

the goal is to make a list of where anyone interested should focus. the short answer seems to be any of these areas, though some are easier than others...</description>
		<content:encoded><![CDATA[<p>Tom, </p>
<p>definitely, this was aimed as more of a wish-list for a team.  </p>
<p>it would be interesting to put together a maturity model for a pentesting team. &#8212; what skills are absolutely (day-one) necessary for a generic pentest. i guess it depends on the network / idea of a &#8220;generic&#8221; pentest. </p>
<p>surely though, there should be some way to boil down to skills which are more essential:<br />
 &#8211; networking<br />
 &#8211; unix / linux<br />
 &#8211; security mindset<br />
 &#8211; scripting (debatable, but imo necessary&#8230;)</p>
<p>and those that are secondary (again, depending on a lot of factors):<br />
 &#8211; scripting++<br />
 &#8211; networking++<br />
 &#8211; unix-foo<br />
 &#8211; web-app skillz</p>
<p>etc.</p>
<p>again, all of this is debatable, and depends on the environment which needs testing. </p>
<p>the goal is to make a list of where anyone interested should focus. the short answer seems to be any of these areas, though some are easier than others&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Interesting Information Security Bits for July 29th, 2008 &#171; Infosec Ramblings</title>
		<link>http://hexesec.wordpress.com/2008/07/05/pentesting-skillset/#comment-4</link>
		<dc:creator>Interesting Information Security Bits for July 29th, 2008 &#171; Infosec Ramblings</dc:creator>
		<pubDate>Wed, 30 Jul 2008 14:22:38 +0000</pubDate>
		<guid isPermaLink="false">http://hexesec.wordpress.com/?p=8#comment-4</guid>
		<description>[...] points to 0&#215;0e&#8217;s post that puts forward a list of skills that a good pentesting team should have. It is a good list and [...]</description>
		<content:encoded><![CDATA[<p>[...] points to 0&#215;0e&#8217;s post that puts forward a list of skills that a good pentesting team should have. It is a good list and [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom</title>
		<link>http://hexesec.wordpress.com/2008/07/05/pentesting-skillset/#comment-2</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Wed, 23 Jul 2008 12:53:57 +0000</pubDate>
		<guid isPermaLink="false">http://hexesec.wordpress.com/?p=8#comment-2</guid>
		<description>Great list!  I would add that it is very difficult for a single pentester to be an expert in a all of these areas (at least I have yet to meet one!).  Hence, one of the things that bothers me is when I see a pentest company send one person out to do a two week penetration test!  How could one person be an expert in all of these areas?  This is why you should have a diverse pentesting team with experts in most of the &#039;major&#039; areas (Web app, OS-Specific, Networking, scripting/dev) you listed.  Other skill sets like vuln development can easily be learned by someone with skills in scripting/development.  In general, the more diverse and well rounded your team is the better. :-)</description>
		<content:encoded><![CDATA[<p>Great list!  I would add that it is very difficult for a single pentester to be an expert in a all of these areas (at least I have yet to meet one!).  Hence, one of the things that bothers me is when I see a pentest company send one person out to do a two week penetration test!  How could one person be an expert in all of these areas?  This is why you should have a diverse pentesting team with experts in most of the &#8216;major&#8217; areas (Web app, OS-Specific, Networking, scripting/dev) you listed.  Other skill sets like vuln development can easily be learned by someone with skills in scripting/development.  In general, the more diverse and well rounded your team is the better. <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>
