TCP/IP skills

From: Don Parker (dparker_at_rigelksecurity.com)
Date: 07/07/04

  • Next message: H Carvey: "Re: PWDUMP Parser"
    Date: Tue, 6 Jul 2004 21:20:46 -0400 (EDT)
    To: pen-test@securityfocus.com, vuln-dev@securityfocus.com
    
    

    Hello all, I just wanted to comment on what I see as a rather alarming trend in the
    security industry today. More and more many are becoming reliant upon tools to do their
    job whilst they ignore core components of their skillset. Specifically in this case an
    in-depth knowledge of TCP/IP.

    Knowing TCP/IP at a granular level in my opinion is very much a core skill that must be
    attained by anyone who wishes to have a successful career in the network security
    industry today. One cannot become adept by simply using tools, and never knowing how to
    interpret the output by verifying the packets themselves.

    It constantly amazes me when I teach a TCP/IP Analysis course that people who are
    presently in the industy do not know of such basic TCP/IP concepts as the 3 way
    handshake and how ICMP works. That or being able to wholly dissect a packet and explain
    the relationships between various metrics.

    I would be curious to hear of your opinions on this?

    Cheers,

    Don

    -------------------------------------------
    Don Parker, GCIA
    Intrusion Detection Specialist
    Rigel Kent Security & Advisory Services Inc
    www.rigelksecurity.com
    ph :613.233.HACK
    fax:613.233.1788
    toll: 1-877-777-H8CK
    --------------------------------------------


  • Next message: H Carvey: "Re: PWDUMP Parser"

    Relevant Pages

    • sshd exploit & $1,000 whine
      ... between the security community and the underground community* ... You say it affects the "whole industry." ... vulnerability research and exploit coding. ... > * CUA find a problem in vendor ABC's product ...
      (Vuln-Dev)
    • Re: TCP/IP skills
      ... > security industry today. ... > Knowing TCP/IP at a granular level in my opinion is very much a core skill that must be ... > interpret the output by verifying the packets themselves. ...
      (Pen-Test)
    • Re: TCP/IP skills
      ... I have taken a few security courses, and have been using Unix for about ... knowledge of TCP/IP. ... >security industry today. ... That or being able to wholly dissect a packet and explain ...
      (Pen-Test)
    • 0-day exploit..do i hear $1000?
      ... industry. ... L33t Hacker writes to ABC ... Security firm 123 implement patches for brain dead clients. ... CUA codes the exploit ...
      (Pen-Test)
    • Re: TCP/IP skills
      ... Subject: TCP/IP skills ... > security industry today. ...
      (Pen-Test)