Cybersecurity Journey

Hi peers, I'm taking this Linux course to help me with my Cybersecurity Journey
Comments
-
After you feel comfortable using the Linux command line (this course), look into the Kali Linux distribution for a lot of pen testing and security tools all part of a Linux distribution.
1 -
Hello Kevin thank you for your advice, where can I find Kali Linux Studying Materials?
0 -
I know there are various books on Kali Linux; there are probably some web sites, too. Kali Linux is based on Debian Linux (which is the base for Ubuntu). Kali is just another distribution of Linux. When you get through this course and feel comfortable using Linux as a user, then use your favorite search engine to find the (free) Kali distribution (probably kali.org). It is still Linux. It simply has a bunch of tools included in the distribution, Now, learning how to use those tools requires reading books, manual pages and documentation. Of course, that is part of you learning about cybersecurity. During your learning about cybersecurity, you hear about using a tool called nmap, for example, you can easily find that tool (and many others) as part of the Kali Linux distribution. The good news: Your journey of learning has just begun. The bad news: Your journey of learning never ends.
1 -
@KevinCSmallwood said:
After you feel comfortable using the Linux command line (this course), look into the Kali Linux distribution for a lot of pen testing and security tools all part of a Linux distribution.Hello Kevin. I would not consider myself a prodigy in Linux and cybersecurity. In a Youtube channel, Chris Titus Tech, he goes about this as: "If you're going into security researching, you need to learn the fundamentals. You need to learn networking and the basics of a Linux system. You need to learn all these things, and you should be using its upstream of Debian and installing those things specifically... and if you can't install those programs and you can't make those customizations, well, you're just a script kiddie at that point."
Don't you think beginners should also learn not only the tools but Linux itself? Managing packages, etc.? I'd also like to hear your opinions on this.
0 -
I agree 100%! Security is a broad field affecting so many parts of a system. A well-versed cybersecurity practitioner should know programming (and secure programming practices) along with understanding how programs, and the Linux kernel works, in order to discover ways to exploit those programs. As you pointed out another exploit could be with installing or updating software packages (such as introducing Trojan Horses). Most people will specialize. OS security? Web security? Network security? Red team vs. blue team vs. purple team. Pick an area and start digging into it. If it interests you, keep digging/drilling down. Technology changes daily. The good news: your knowledge journey has just begun. The bad news: it will likely never end. I suggested looking into Kali Linux (based on Debian) because it pulls a lot of Pen Testing tools together. This may be a source of areas to explore. Metasploit is a nice tool, but if you only learn how to use it and not what it is doing under the hood, then, yes, you are nothing more than a Script Kiddie. Seeing that Metasploit has a buffer overflow exploit for an old version of the Apache Web Server will, hopefully, incentivize you to find out what a "buffer overflow" is and how to use it to gain control of a system, for example. Knowing that there is a tool that can brute-force passwords may enable you to better understand what makes a good password (and I would prefer to use the term "pass phrase" since it implies a long password made up of several words). I just mentioned two of the dozens of tools in the Kali Linux distribution. But, yes, learn to walk before you run. Learn to use Linux (this course). Then, learn what is call Systems Administration (or Management). Then Network Administration. All of this may direct you into an area of security that you are interested in. When I teach Linux Systems Administration, I mention that some people specialize in PAM (Pluggable Authentication Modules) or udev (User Device Management). There is so much to learn (and it changes constantly). How do you eat an elephant? One bite at a time. I hope this helps. By the way, I've been working with UNIX and now Linux for over 42 years, and I don't begin to know everything! I learn new things every day! Good luck!
1 -
@KevinCSmallwood said:
I agree 100%! Security is a broad field affecting so many parts of a system. A well-versed cybersecurity practitioner should know programming (and secure programming practices) along with understanding how programs, and the Linux kernel works, in order to discover ways to exploit those programs. As you pointed out another exploit could be with installing or updating software packages (such as introducing Trojan Horses). Most people will specialize. OS security? Web security? Network security? Red team vs. blue team vs. purple team. Pick an area and start digging into it. If it interests you, keep digging/drilling down. Technology changes daily. The good news: your knowledge journey has just begun. The bad news: it will likely never end. I suggested looking into Kali Linux (based on Debian) because it pulls a lot of Pen Testing tools together. This may be a source of areas to explore. Metasploit is a nice tool, but if you only learn how to use it and not what it is doing under the hood, then, yes, you are nothing more than a Script Kiddie. Seeing that Metasploit has a buffer overflow exploit for an old version of the Apache Web Server will, hopefully, incentivize you to find out what a "buffer overflow" is and how to use it to gain control of a system, for example. Knowing that there is a tool that can brute-force passwords may enable you to better understand what makes a good password (and I would prefer to use the term "pass phrase" since it implies a long password made up of several words). I just mentioned two of the dozens of tools in the Kali Linux distribution. But, yes, learn to walk before you run. Learn to use Linux (this course). Then, learn what is call Systems Administration (or Management). Then Network Administration. All of this may direct you into an area of security that you are interested in. When I teach Linux Systems Administration, I mention that some people specialize in PAM (Pluggable Authentication Modules) or udev (User Device Management). There is so much to learn (and it changes constantly). How do you eat an elephant? One bite at a time. I hope this helps. By the way, I've been working with UNIX and now Linux for over 42 years, and I don't begin to know everything! I learn new things every day! Good luck!I deeply appreciate your comprehensive response. Your level of expertise is truly impressive. It's a testament to the ever-evolving nature of Linux and systems administration. The fact that even after 42 years, there's still so much to learn is incredibly motivating. After seven years of my own exploration, I'm even more aware of the vastness of this field. Thank you for sharing your knowledge. What kind of roadmap would you suggest for those who want to become a cloud engineer? Where do you think I should get training/certifications?
0 -
Thank you very much. My philosophy is that you never stop learning (as long as you are open to it). Linux and FOSS is very vast! I don't know the stats off the top of my head, but it sure seems that several new commands and systems are coming out every week!
Just to be very clear, I am an independent contractor teaching classes for The Linux Foundation since 2014. So, not certain I can be totally unbiased. I try, but to be honest, I'm not that aware of other training programs. I will suggest that you look into The Linux Foundation's IT Professional programs. There is one specifically for Cloud Engineering. You can find that here: https://training.linuxfoundation.org/training/cloud-engineer-itprofessionalprogram/. This is an independent study set of courses (and two certification exams) similar to this (LFS101) course. Again, I'm just not too aware of all the programs out there, but I am familiar with several of the courses in The Linux Foundation's IT Professional program. I've taught the first two courses in this program several times. Again, this program is independent study and not Instructor led training and is priced that way. Taking Instructor led training is more expensive (but that's how I earn my income).
Before teaching, I was a Software Development Manager (in UNIX-like systems) for much of my career. I've always enjoyed mentoring people. I often learn as much from my students as they learn from me (well, I hope they learn from me!). If you have further comments or questions, let me know. I enjoy interacting with other techies. There are always new things to learn.
0 -
@aguinaldo said:
Hello Kevin thank you for your advice, where can I find Kali Linux Studying Materials?Check this book.
L I N U X B A S I C S
FOR HACKERS
G e t t i n g S t a r t e d w i t h
N e t w o r k i n g , S c r i p t i n g ,
and Security in Kali0
Categories
- All Categories
- 203 LFX Mentorship
- 203 LFX Mentorship: Linux Kernel
- 812 Linux Foundation IT Professional Programs
- 365 Cloud Engineer IT Professional Program
- 183 Advanced Cloud Engineer IT Professional Program
- 82 DevOps Engineer IT Professional Program
- 129 Cloud Native Developer IT Professional Program
- 119 Express Training Courses
- 119 Express Courses - Discussion Forum
- Microlearning - Discussion Forum
- 6.5K Training Courses
- 40 LFC110 Class Forum - Discontinued
- 71 LFC131 Class Forum
- 39 LFD102 Class Forum
- 217 LFD103 Class Forum
- 16 LFD110 Class Forum
- 29 LFD121 Class Forum
- LFD125 Class Forum
- 16 LFD133 Class Forum
- 6 LFD134 Class Forum
- 17 LFD137 Class Forum
- 70 LFD201 Class Forum
- 3 LFD210 Class Forum
- 2 LFD210-CN Class Forum
- 2 LFD213 Class Forum - Discontinued
- 128 LFD232 Class Forum - Discontinued
- 1 LFD233 Class Forum
- 2 LFD237 Class Forum
- 23 LFD254 Class Forum
- 716 LFD259 Class Forum
- 109 LFD272 Class Forum
- 3 LFD272-JP クラス フォーラム
- 13 LFD273 Class Forum
- 205 LFS101 Class Forum
- LFS111 Class Forum
- 2 LFS112 Class Forum
- 1 LFS116 Class Forum
- 3 LFS118 Class Forum
- LFS120 Class Forum
- 1 LFS142 Class Forum
- 2 LFS144 Class Forum
- 3 LFS145 Class Forum
- 1 LFS146 Class Forum
- 15 LFS148 Class Forum
- 15 LFS151 Class Forum
- 1 LFS157 Class Forum
- 49 LFS158 Class Forum
- LFS158-JP クラス フォーラム
- 4 LFS162 Class Forum
- 1 LFS166 Class Forum
- 2 LFS167 Class Forum
- 1 LFS170 Class Forum
- 1 LFS171 Class Forum
- 3 LFS178 Class Forum
- 2 LFS180 Class Forum
- 1 LFS182 Class Forum
- 5 LFS183 Class Forum
- 30 LFS200 Class Forum
- 737 LFS201 Class Forum - Discontinued
- 2 LFS201-JP クラス フォーラム
- 17 LFS203 Class Forum
- 109 LFS207 Class Forum
- 2 LFS207-DE-Klassenforum
- LFS207-JP クラス フォーラム
- 301 LFS211 Class Forum
- 55 LFS216 Class Forum
- 48 LFS241 Class Forum
- 43 LFS242 Class Forum
- 37 LFS243 Class Forum
- 13 LFS244 Class Forum
- 1 LFS245 Class Forum
- LFS246 Class Forum
- LFS248 Class Forum
- 44 LFS250 Class Forum
- 1 LFS250-JP クラス フォーラム
- LFS251 Class Forum
- 143 LFS253 Class Forum
- LFS254 Class Forum
- LFS255 Class Forum
- 6 LFS256 Class Forum
- 1 LFS257 Class Forum
- 1.3K LFS258 Class Forum
- 9 LFS258-JP クラス フォーラム
- 135 LFS260 Class Forum
- 160 LFS261 Class Forum
- 41 LFS262 Class Forum
- 82 LFS263 Class Forum - Discontinued
- 15 LFS264 Class Forum - Discontinued
- 11 LFS266 Class Forum - Discontinued
- 21 LFS267 Class Forum
- 18 LFS268 Class Forum
- 36 LFS269 Class Forum
- 6 LFS270 Class Forum
- 199 LFS272 Class Forum
- 1 LFS272-JP クラス フォーラム
- 2 LFS147 Class Forum
- 1 LFS274 Class Forum
- 3 LFS281 Class Forum
- 15 LFW111 Class Forum
- 257 LFW211 Class Forum
- 176 LFW212 Class Forum
- 12 SKF100 Class Forum
- 1 SKF200 Class Forum
- 2 SKF201 Class Forum
- 786 Hardware
- 199 Drivers
- 68 I/O Devices
- 37 Monitors
- 96 Multimedia
- 174 Networking
- 91 Printers & Scanners
- 83 Storage
- 752 Linux Distributions
- 82 Debian
- 67 Fedora
- 16 Linux Mint
- 13 Mageia
- 23 openSUSE
- 147 Red Hat Enterprise
- 31 Slackware
- 13 SUSE Enterprise
- 354 Ubuntu
- 463 Linux System Administration
- 39 Cloud Computing
- 70 Command Line/Scripting
- Github systems admin projects
- 91 Linux Security
- 78 Network Management
- 101 System Management
- 46 Web Management
- 55 Mobile Computing
- 17 Android
- 28 Development
- 1.2K New to Linux
- 1K Getting Started with Linux
- 378 Off Topic
- 113 Introductions
- 176 Small Talk
- 20 Study Material
- 518 Programming and Development
- 304 Kernel Development
- 211 Software Development
- 1.8K Software
- 263 Applications
- 180 Command Line
- 3 Compiling/Installing
- 405 Games
- 311 Installation
- 78 All In Program
- 78 All In Forum
Upcoming Training
-
August 20, 2018
Kubernetes Administration (LFS458)
-
August 20, 2018
Linux System Administration (LFS301)
-
August 27, 2018
Open Source Virtualization (LFS462)
-
August 27, 2018
Linux Kernel Debugging and Security (LFD440)