<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-3963961130093583831.comments</id><updated>2009-02-09T17:22:59.572-08:00</updated><title type='text'>Security Aegis</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://securityaegis.blogspot.com/feeds/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/comments/default'/><link rel='alternate' type='text/html' href='http://securityaegis.blogspot.com/'/><author><name>Jason</name><uri>http://www.blogger.com/profile/10133191127714276720</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>16</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3963961130093583831.post-5344077360758010068</id><published>2009-02-09T17:17:00.000-08:00</published><updated>2009-02-09T17:17:00.000-08:00</updated><title type='text'>can you post your top favorite articles, forum top...</title><content type='html'>can you post your top favorite articles, forum topics, and other types of content from the ethicalhacker.net forum?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/5041074392105161469/comments/default/5344077360758010068'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/5041074392105161469/comments/default/5344077360758010068'/><link rel='alternate' type='text/html' href='http://securityaegis.blogspot.com/2009/02/ehnet.html?showComment=1234228620000#c5344077360758010068' title=''/><author><name>Andre Gironda</name><uri>http://www.blogger.com/profile/17414510788948258195</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://securityaegis.blogspot.com/2009/02/ehnet.html' ref='tag:blogger.com,1999:blog-3963961130093583831.post-5041074392105161469' source='http://www.blogger.com/feeds/3963961130093583831/posts/default/5041074392105161469' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-3963961130093583831.post-3376613095603373583</id><published>2009-02-06T16:28:00.000-08:00</published><updated>2009-02-06T16:28:00.000-08:00</updated><title type='text'>&lt;3!</title><content type='html'>&amp;lt;3!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/3900204266148879029/comments/default/3376613095603373583'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/3900204266148879029/comments/default/3376613095603373583'/><link rel='alternate' type='text/html' href='http://securityaegis.blogspot.com/2009/02/return-from-vegas.html?showComment=1233966480000#c3376613095603373583' title=''/><author><name>Lion's Blood</name><uri>http://www.blogger.com/profile/15073369698713206001</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://securityaegis.blogspot.com/2009/02/return-from-vegas.html' ref='tag:blogger.com,1999:blog-3963961130093583831.post-3900204266148879029' source='http://www.blogger.com/feeds/3963961130093583831/posts/default/3900204266148879029' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-3963961130093583831.post-5404872265960416299</id><published>2009-02-05T03:07:00.000-08:00</published><updated>2009-02-05T03:07:00.000-08:00</updated><title type='text'>AppLocker id Win7 should bring some needed improve...</title><content type='html'>AppLocker id Win7 should bring some needed improvements, lets hope =)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/3900204266148879029/comments/default/5404872265960416299'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/3900204266148879029/comments/default/5404872265960416299'/><link rel='alternate' type='text/html' href='http://securityaegis.blogspot.com/2009/02/return-from-vegas.html?showComment=1233832020000#c5404872265960416299' title=''/><author><name>Jason</name><uri>http://www.blogger.com/profile/10133191127714276720</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13587241887433827338'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://securityaegis.blogspot.com/2009/02/return-from-vegas.html' ref='tag:blogger.com,1999:blog-3963961130093583831.post-3900204266148879029' source='http://www.blogger.com/feeds/3963961130093583831/posts/default/3900204266148879029' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-3963961130093583831.post-621731461155165424</id><published>2009-02-03T14:27:00.000-08:00</published><updated>2009-02-03T14:27:00.000-08:00</updated><title type='text'>Friday – Day five was all about Windows sec. More ...</title><content type='html'>Friday – Day five was all about Windows sec. More Windows active directory than I ever wanted to know about… well not quite, but close. No one ever told me most application whitelisting server software was just pretty front ends over AD! Should’ve guessed.&lt;BR/&gt;------------&lt;BR/&gt;Only if the application whitelisting was so easy. AD Software Restriction Policies have been around for the longest time but are practically unusable. I think the application whitelisting is much more than SRP. The technology needs to be able to operate without management overhead in large environments.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/3900204266148879029/comments/default/621731461155165424'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/3900204266148879029/comments/default/621731461155165424'/><link rel='alternate' type='text/html' href='http://securityaegis.blogspot.com/2009/02/return-from-vegas.html?showComment=1233700020000#c621731461155165424' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://securityaegis.blogspot.com/2009/02/return-from-vegas.html' ref='tag:blogger.com,1999:blog-3963961130093583831.post-3900204266148879029' source='http://www.blogger.com/feeds/3963961130093583831/posts/default/3900204266148879029' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-3963961130093583831.post-9007487110589106181</id><published>2008-10-24T18:58:00.000-07:00</published><updated>2008-10-24T18:58:00.000-07:00</updated><title type='text'>wow judging by the other people you interviewed I'...</title><content type='html'>wow judging by the other people you interviewed I'm honored to be included.  &lt;BR/&gt;&lt;BR/&gt;so thanks!&lt;BR/&gt;&lt;BR/&gt;As an update you may want to hit up Mike Murray he's really in tune to security careers and how they are affected by different events.&lt;BR/&gt;&lt;BR/&gt;-CG</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/774096990763089582/comments/default/9007487110589106181'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/774096990763089582/comments/default/9007487110589106181'/><link rel='alternate' type='text/html' href='http://securityaegis.blogspot.com/2008/10/fears-for-infosec-interview-article.html?showComment=1224899880000#c9007487110589106181' title=''/><author><name>chris</name><uri>http://www.blogger.com/profile/08725211059186839473</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://securityaegis.blogspot.com/2008/10/fears-for-infosec-interview-article.html' ref='tag:blogger.com,1999:blog-3963961130093583831.post-774096990763089582' source='http://www.blogger.com/feeds/3963961130093583831/posts/default/774096990763089582' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-3963961130093583831.post-1879695114356208724</id><published>2008-10-24T05:56:00.000-07:00</published><updated>2008-10-24T05:56:00.000-07:00</updated><title type='text'>Great article, and thank you for offering me the o...</title><content type='html'>Great article, and thank you for offering me the opportunity to contribute.  I think we'll see some big changes down the road, and only time will tell what those are.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/774096990763089582/comments/default/1879695114356208724'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/774096990763089582/comments/default/1879695114356208724'/><link rel='alternate' type='text/html' href='http://securityaegis.blogspot.com/2008/10/fears-for-infosec-interview-article.html?showComment=1224852960000#c1879695114356208724' title=''/><author><name>Mad Irish</name><uri>http://www.madirish.net</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://securityaegis.blogspot.com/2008/10/fears-for-infosec-interview-article.html' ref='tag:blogger.com,1999:blog-3963961130093583831.post-774096990763089582' source='http://www.blogger.com/feeds/3963961130093583831/posts/default/774096990763089582' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-3963961130093583831.post-7436380431889932094</id><published>2008-10-06T18:12:00.000-07:00</published><updated>2008-10-06T18:12:00.000-07:00</updated><title type='text'>thanks for the comment Vince!I actually agree, i a...</title><content type='html'>thanks for the comment Vince!&lt;BR/&gt;&lt;BR/&gt;I actually agree, i am also enamored with it. Having the knowledge of the tools assumes knowledge of pre requisite security, and both these combined give a basis for a pentester. It's being on our side of the fence though, as most of the pentesters/infosec folks have a HUGE gripe with the CEH. I'm hoping that this revamped curriculum will change some minds.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/9031191135982534200/comments/default/7436380431889932094'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/9031191135982534200/comments/default/7436380431889932094'/><link rel='alternate' type='text/html' href='http://securityaegis.blogspot.com/2008/10/certified-ethical-hacker-version-6.html?showComment=1223341920000#c7436380431889932094' title=''/><author><name>Jason</name><uri>http://www.blogger.com/profile/10133191127714276720</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13587241887433827338'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://securityaegis.blogspot.com/2008/10/certified-ethical-hacker-version-6.html' ref='tag:blogger.com,1999:blog-3963961130093583831.post-9031191135982534200' source='http://www.blogger.com/feeds/3963961130093583831/posts/default/9031191135982534200' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-3963961130093583831.post-6081448614090200224</id><published>2008-10-06T14:09:00.000-07:00</published><updated>2008-10-06T14:09:00.000-07:00</updated><title type='text'>I'm actually rather enamored with the CEH certific...</title><content type='html'>I'm actually rather enamored with the CEH certification.  I don't have one currently and I'm not even sure if it will end up being my career direction, but I really like the thought of it.  The nicest thing is that most of the talent and skills required to do such a job are either there or not, which should quickly make it apparent when preparing for this cert whether one is cut out for it or not.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/9031191135982534200/comments/default/6081448614090200224'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/9031191135982534200/comments/default/6081448614090200224'/><link rel='alternate' type='text/html' href='http://securityaegis.blogspot.com/2008/10/certified-ethical-hacker-version-6.html?showComment=1223327340000#c6081448614090200224' title=''/><author><name>Vince McDonald</name><uri>http://logicalsecurity.com/index.html</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://securityaegis.blogspot.com/2008/10/certified-ethical-hacker-version-6.html' ref='tag:blogger.com,1999:blog-3963961130093583831.post-9031191135982534200' source='http://www.blogger.com/feeds/3963961130093583831/posts/default/9031191135982534200' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-3963961130093583831.post-3432284865137520515</id><published>2008-09-29T10:49:00.000-07:00</published><updated>2008-09-29T10:49:00.000-07:00</updated><title type='text'>haha! good comments ntp!I will take all these into...</title><content type='html'>haha! good comments ntp!&lt;BR/&gt;&lt;BR/&gt;I will take all these into account. Email me sometime, i'd love to chat more about security =)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/5006454708719105012/comments/default/3432284865137520515'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/5006454708719105012/comments/default/3432284865137520515'/><link rel='alternate' type='text/html' href='http://securityaegis.blogspot.com/2008/09/listing-of-security-related-certs-i.html?showComment=1222710540000#c3432284865137520515' title=''/><author><name>Jason</name><uri>http://www.blogger.com/profile/10133191127714276720</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13587241887433827338'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://securityaegis.blogspot.com/2008/09/listing-of-security-related-certs-i.html' ref='tag:blogger.com,1999:blog-3963961130093583831.post-5006454708719105012' source='http://www.blogger.com/feeds/3963961130093583831/posts/default/5006454708719105012' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-3963961130093583831.post-4669651753924284711</id><published>2008-09-29T10:45:00.000-07:00</published><updated>2008-09-29T10:45:00.000-07:00</updated><title type='text'>This is indeed a good model to go by.  The reason ...</title><content type='html'>This is indeed a good model to go by.  The reason I love these pentest frameworks is that they provide a good reference. Entering the security field is daunting, and they provide a decent ground for the tools and structure a pentester or ethical hacker should be following. They are not best things since sliced bread, but they are handy and good to have bookmarked =)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/7770562176486340745/comments/default/4669651753924284711'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/7770562176486340745/comments/default/4669651753924284711'/><link rel='alternate' type='text/html' href='http://securityaegis.blogspot.com/2008/09/quick-post-pentest-framework.html?showComment=1222710300000#c4669651753924284711' title=''/><author><name>Jason</name><uri>http://www.blogger.com/profile/10133191127714276720</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13587241887433827338'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://securityaegis.blogspot.com/2008/09/quick-post-pentest-framework.html' ref='tag:blogger.com,1999:blog-3963961130093583831.post-7770562176486340745' source='http://www.blogger.com/feeds/3963961130093583831/posts/default/7770562176486340745' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-3963961130093583831.post-3743765026134112415</id><published>2008-09-29T10:35:00.000-07:00</published><updated>2008-09-29T10:35:00.000-07:00</updated><title type='text'>Hello ntp!These two aren't really required for any...</title><content type='html'>Hello ntp!&lt;BR/&gt;&lt;BR/&gt;These two aren't really required for anyone, you are correct. My employer however will pay for them and has their own training for them. These are just stepping stones and adds to the resume, not anything I'm counting on =)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/433617736532336307/comments/default/3743765026134112415'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/433617736532336307/comments/default/3743765026134112415'/><link rel='alternate' type='text/html' href='http://securityaegis.blogspot.com/2008/09/new-projects-920.html?showComment=1222709700000#c3743765026134112415' title=''/><author><name>Jason</name><uri>http://www.blogger.com/profile/10133191127714276720</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13587241887433827338'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://securityaegis.blogspot.com/2008/09/new-projects-920.html' ref='tag:blogger.com,1999:blog-3963961130093583831.post-433617736532336307' source='http://www.blogger.com/feeds/3963961130093583831/posts/default/433617736532336307' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-3963961130093583831.post-1874038646026215367</id><published>2008-09-29T07:01:00.000-07:00</published><updated>2008-09-29T07:01:00.000-07:00</updated><title type='text'>I'd be curious to see how Security Innovation fair...</title><content type='html'>I'd be curious to see how Security Innovation fairs as they were not on your list</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/9220363184144952880/comments/default/1874038646026215367'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/9220363184144952880/comments/default/1874038646026215367'/><link rel='alternate' type='text/html' href='http://securityaegis.blogspot.com/2008/09/1st-annual-cbt-awards.html?showComment=1222696860000#c1874038646026215367' title=''/><author><name>ntp</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://securityaegis.blogspot.com/2008/09/1st-annual-cbt-awards.html' ref='tag:blogger.com,1999:blog-3963961130093583831.post-9220363184144952880' source='http://www.blogger.com/feeds/3963961130093583831/posts/default/9220363184144952880' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-3963961130093583831.post-8058041914037793731</id><published>2008-09-29T07:00:00.000-07:00</published><updated>2008-09-29T07:00:00.000-07:00</updated><title type='text'>I understand CISSP and OSCP, but why would you eve...</title><content type='html'>I understand CISSP and OSCP, but why would you even consider CPTS or CEH?  Isn't CEH the certification program where 95% of instructors have 0% real-world pen-test experience (i.e. never have done one)?  Why CPTS?  Why CEH?  Who's asking for them and what's the point?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/433617736532336307/comments/default/8058041914037793731'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/433617736532336307/comments/default/8058041914037793731'/><link rel='alternate' type='text/html' href='http://securityaegis.blogspot.com/2008/09/new-projects-920.html?showComment=1222696800000#c8058041914037793731' title=''/><author><name>ntp</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://securityaegis.blogspot.com/2008/09/new-projects-920.html' ref='tag:blogger.com,1999:blog-3963961130093583831.post-433617736532336307' source='http://www.blogger.com/feeds/3963961130093583831/posts/default/433617736532336307' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-3963961130093583831.post-4628614274949397706</id><published>2008-09-29T06:57:00.000-07:00</published><updated>2008-09-29T06:57:00.000-07:00</updated><title type='text'>A lot of this was pulled from other sources includ...</title><content type='html'>A lot of this was pulled from other sources including the ISSAF and &lt;A HREF="http://wirelessdefence.org/Contents/Wireless%20Pen%20Test%20Framework_001.html" REL="nofollow"&gt;WirelessDefence.org&lt;/A&gt;.&lt;BR/&gt;&lt;BR/&gt;Some of my friends like these sorts of pen-test frameworks, but I think they are not very real world.&lt;BR/&gt;&lt;BR/&gt;I often view network pen-testing as&lt;BR/&gt;1) the ability to identify or get full-knowledge information on the actual pieces of the puzzle (footprint and fingerprint)&lt;BR/&gt;2) the ability to replicate that environment exactly, including as many original software artifacts as possible (especially code in the form of binaries or source)&lt;BR/&gt;3) the ability to test and inspect the replicated environment instead of the one that you'd rather not break (i.e. the production one)&lt;BR/&gt;&lt;BR/&gt;since nobody else looks at it that way, i think that this industry is due for a revolution.  even the OSSTMM 3.0 (the full version I'm talking about here) stands to take some concepts from the three point model that I just proposed</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/7770562176486340745/comments/default/4628614274949397706'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/7770562176486340745/comments/default/4628614274949397706'/><link rel='alternate' type='text/html' href='http://securityaegis.blogspot.com/2008/09/quick-post-pentest-framework.html?showComment=1222696620000#c4628614274949397706' title=''/><author><name>ntp</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://securityaegis.blogspot.com/2008/09/quick-post-pentest-framework.html' ref='tag:blogger.com,1999:blog-3963961130093583831.post-7770562176486340745' source='http://www.blogger.com/feeds/3963961130093583831/posts/default/7770562176486340745' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-3963961130093583831.post-820506006333599400</id><published>2008-09-29T06:49:00.000-07:00</published><updated>2008-09-29T06:49:00.000-07:00</updated><title type='text'>OSCP is the best technical certification program I...</title><content type='html'>OSCP is the best technical certification program I have seen so far, especially to 2008/2009 standards.  GSE just has insane requirements and a minimal set of people have met them (11 in 5 years?!).&lt;BR/&gt;&lt;BR/&gt;OPST is very forwarding looking.  This is only worthwhile if you have mastered the technical focus of your career and want to postulate what is possible on the strategic process side.  It could also become a dominant measure of tactical technical ability, but in 2008/2009 it is not quite there yet.&lt;BR/&gt;&lt;BR/&gt;CISSP and all ISC2 certifications are on their way out, regardless of the promises, the re-certification, and the continual education processes.  However, many venues will continue to worship them for an unknown reason.&lt;BR/&gt;&lt;BR/&gt;One of the major institutions requiring certification is the US military and government information assurance programs.  The DODI 8570.01M is the manual that anyone interested in certification should read (please don't read just the SANS version, they are very biased).&lt;BR/&gt;&lt;BR/&gt;SCNP/SCNA is a very good path to take for the IAT track - the material is good and widely available.  SANS and ISC2 pretty much own all of the other track paths, although the CERT CSIH and ISACA CISA keep the program somewhat vendor neutral.&lt;BR/&gt;&lt;BR/&gt;I have never considered ISC2 or SANS to be vendor neutral (they are vendors in my mind).  However I have some nice things to say about SANS, but they are hit or miss and will have to wait for another time.&lt;BR/&gt;&lt;BR/&gt;OSCP is certainly worth everyone's time and energy.  While there is more depth to CWSP, I think OSWP is more relevant today.  I do not like the OSWP reliance on Backtrack tools, even though right now they happen to be the most complete.&lt;BR/&gt;&lt;BR/&gt;OSWP is going to be both important and popular soon.  The training and certification are cheap, consistent, and timely.  This is a serious win.  Although the syllabus for OSWP is awesome -- the &lt;A HREF="http://www.sans.org/training/description.php?mid=3" REL="nofollow"&gt;SANS Wireless Ethical Hacking Pen-Test course&lt;/A&gt; appears to be even better if you check out Days 1-6 in detail.  I would recommend both to those who want to specialize in WiFi/WEP assessments.  Woops I just said something nice about SANS training, although you should note that it is incredibly expensive and taking 6 days out of your work life might be a pretty big deal.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/5006454708719105012/comments/default/820506006333599400'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/5006454708719105012/comments/default/820506006333599400'/><link rel='alternate' type='text/html' href='http://securityaegis.blogspot.com/2008/09/listing-of-security-related-certs-i.html?showComment=1222696140000#c820506006333599400' title=''/><author><name>ntp</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://securityaegis.blogspot.com/2008/09/listing-of-security-related-certs-i.html' ref='tag:blogger.com,1999:blog-3963961130093583831.post-5006454708719105012' source='http://www.blogger.com/feeds/3963961130093583831/posts/default/5006454708719105012' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-3963961130093583831.post-3717129931784795154</id><published>2008-09-29T06:31:00.000-07:00</published><updated>2008-09-29T06:31:00.000-07:00</updated><title type='text'>OffSec101 gets a 6 out of 10 (and improving).  Wir...</title><content type='html'>OffSec101 gets a 6 out of 10 (and improving).  Wireshark University I give a 3 out of 10 (but also improving despite the low mark).&lt;BR/&gt;&lt;BR/&gt;SANS is hit or miss.  Most of these others that I have seen are 2 out of 10 at best, but I haven't seen a lot of the ones that you've listed.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/5507080882332308793/comments/default/3717129931784795154'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3963961130093583831/5507080882332308793/comments/default/3717129931784795154'/><link rel='alternate' type='text/html' href='http://securityaegis.blogspot.com/2008/09/computer-based-trianing-cbts-for.html?showComment=1222695060000#c3717129931784795154' title=''/><author><name>ntp</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://securityaegis.blogspot.com/2008/09/computer-based-trianing-cbts-for.html' ref='tag:blogger.com,1999:blog-3963961130093583831.post-5507080882332308793' source='http://www.blogger.com/feeds/3963961130093583831/posts/default/5507080882332308793' type='text/html'/></entry></feed>