Thursday, May 01, 2008

CEH Training...or...Drinking from the Firehose

Decided to hone some skills that were getting rusty since my foray into corporate information security policy....hacking and countermeasures. Or as some know it better, the CEH training. 5 days, 4 volumes, over 2300 pages. Overwhelming would describe the amount of information that was presented to the class. We had a decent sized class and a pretty good instructor. He knew the present state of the hacking industry and was able to focus our attention on the more relevant details of the course, which is ESSENTIAL when trying to process so much info. We also were actually preparing for the CEH exam at the same time, but that is more of a side note than the class itself. I won't bore anyone with what we learned, I just thought I would share with you some of my experiences while out of work (ha ha) and in training. As I said before, we had a good sized class, 10 students. A good mixture of backgrounds as well. A couple of developers, a couple of DBAs, some security people from larger companies where their skills and job titles are way more focused than mine, and a couple of general security folk (like me). It made for some very good discussions and learning when it came to topics that people were either familiar with or were asking more information about. We didn't have to rely on the instructor for every single answer, we had subject matter experts in the room. The amount of material is to say the least, daunting. And rumor has it that the next version or iteration of the courseware is going to increase. I can't see this increasing without extending the days that you sit or it will start to diminish the course. You get to a point where it becomes counter-productive to try and learn so much in such a short period of time. Break it down into smaller classes or extend the time for that single class.

The upside to all of this is that I did learn what I needed to learn. The downside is now I am paranoid. I now know how easy it is to exploit systems, especially ones that are NOT patched. Once you realize the risk you face, you tend to see things a bit differently (at least for the short term). But I also know that you need to take the parts from any training you attend and be able to apply them to your current job. Therein lies the task before me. Taking only the relevant pieces from this training (or any other for that matter) and applying them to my current job and employer and ensuring that they get the best bang for the buck, or ROI if you prefer corporate speak.

That is all for now...I will update again once I have stopped the paranoia from making me unplug every PC in my house for fear that I will get hacked.