White hack hackers do not infiltrate real systems unless performing penetration tests. However, since real world hacking is illegal and they don't participate in this, how do they know their skills are up to snuff if they aren't penetration testers? Have most of them even hacked anything? And how can they possibly, legally learn these skills when real world experience is illegal? How can they know if they are skilled? How can they become penetration testers?
Forum Thread: How Do You Know Your Skills
- Hot
- Active
-
Forum Thread: How to Track Who Is Sms Bombing Me . 4 Replies
2 mo ago -
Forum Thread: Removing Pay-as-You-Go Meter on Loan Phones. 1 Replies
2 mo ago -
Forum Thread: Hydra Syntax Issue Stops After 16 Attempts 3 Replies
2 mo ago -
Forum Thread: moab5.Sh Error While Running Metasploit 17 Replies
3 mo ago -
Forum Thread: Execute Reverse PHP Shell with Metasploit 1 Replies
4 mo ago -
Forum Thread: Install Metasploit Framework in Termux No Root Needed M-Wiz Tool 1 Replies
5 mo ago -
Forum Thread: Hack and Track People's Device Constantly Using TRAPE 35 Replies
6 mo ago -
Forum Thread: When My Kali Linux Finishes Installing (It Is Ready to Boot), and When I Try to Boot It All I Get Is a Black Screen. 8 Replies
7 mo ago -
Forum Thread: HACK ANDROID with KALI USING PORT FORWARDING(portmap.io) 12 Replies
7 mo ago -
Forum Thread: Hack Instagram Account Using BruteForce 208 Replies
7 mo ago -
Forum Thread: Metasploit reverse_tcp Handler Problem 47 Replies
9 mo ago -
Forum Thread: How to Train to Be an IT Security Professional (Ethical Hacker) 22 Replies
9 mo ago -
Metasploit Error: Handler Failed to Bind 41 Replies
10 mo ago -
Forum Thread: How to Hack Android Phone Using Same Wifi 21 Replies
10 mo ago -
How to: HACK Android Device with TermuX on Android | Part #1 - Over the Internet [Ultimate Guide] 177 Replies
10 mo ago -
How to: Crack Instagram Passwords Using Instainsane 36 Replies
10 mo ago -
Forum Thread: How to Hack an Android Device Remotely, to Gain Acces to Gmail, Facebook, Twitter and More 5 Replies
10 mo ago -
Forum Thread: How Many Hackers Have Played Watch_Dogs Game Before? 13 Replies
10 mo ago -
Forum Thread: How to Hack an Android Device with Only a Ip Adress 55 Replies
11 mo ago -
How to: Sign the APK File with Embedded Payload (The Ultimate Guide) 10 Replies
11 mo ago
-
How To: Use Burp & FoxyProxy to Easily Switch Between Proxy Settings
-
How to Hack Wi-Fi: Cracking WPA2 Passwords Using the New PMKID Hashcat Attack
-
How To: Find Vulnerable Webcams Across the Globe Using Shodan
-
How To: Make Your Own Bad USB
-
Tutorial: Create Wordlists with Crunch
-
How To: Scan for Vulnerabilities on Any Website Using Nikto
-
How To: Find Identifying Information from a Phone Number Using OSINT Tools
-
Hack Like a Pro: How to Find Directories in Websites Using DirBuster
-
How To: Use Kismet to Watch Wi-Fi User Activity Through Walls
-
How To: Extract Bitcoin Wallet Addresses & Balances from Websites with SpiderFoot CLI
-
How To: Set Up a Wi-Fi Spy Camera with an ESP32-CAM
-
How to Hack Wi-Fi: Cracking WPA2-PSK Passwords Using Aircrack-Ng
-
How To: Hunt Down Social Media Accounts by Usernames with Sherlock
-
Tutorial: DNS Spoofing
-
How To: Set Your Wi-Fi Card's TX Power Higher Than 30 dBm
-
How To: Use Hash-Identifier to Determine Hash Types for Password Cracking
-
How To: Automate Wi-Fi Hacking with Wifite2
-
How To: Hack WPA & WPA2 Wi-Fi Passwords with a Pixie-Dust Attack Using Airgeddon
-
Hack Like a Pro: How to Use Netcat, the Swiss Army Knife of Hacking Tools
-
How To: Manually Exploit EternalBlue on Windows Server Using MS17-010 Python Exploit
2 Responses
They can set up their own servers or computers to hack, primarily through Virtual Box or Virtual Machine.
However a majority of "cybersecurity" engineers lack any experience hacking, hence why security jobs are hot.
As for your other questions, I'm not sure how to answer them. A majority of "white hats" are not as skilled as they should be, but technology is always advancing and so they have to continuously learn new things.
Problem solving capabilities is key.
Developing that and coupling it with your technical knowledge is the best way to go about it. It's been said before by myself, OTW, and many others; problem solving is a critical skill to have for hacking.
Labs are a good option to test your hacking, as well as bug bounties to develop your zero day exploit finding skills, et cetera.
There are many ways to develop yourself that isn't just "hack this and you get better" and in fact, sometimes that isn't even the best way.
The worst thing to happen in a lesson, is for you to have no problems to solve. What if, for instance, you hack a website and it goes off without a hitch? You've not gotten better, you've learnt nothing.
The reason a lot of security professionals are maybe not as good as they'd like to be, is because their only experience, the only way they've dealt with security is defensively. However, learning how your opponents will attack you is critical. It's just like warfare, know your enemy. Having this knowledge will have you much better equipped to defend against attacks because you know what their next steps are likely to be, therefore, you can stay a step ahead.
This is why we're all here, this is what I try to explain to everyone. We can give you all the answers, and that's all well and good, but you learn very little that way. Learn to solve the problems you're faced with, and you're then that much better equipped to deal with future problems.
ghost_
Share Your Thoughts