• Cornelius_Wangenheim@lemmy.world
    link
    fedilink
    arrow-up
    159
    arrow-down
    1
    ·
    5 days ago
    1. No one’s hiring you unless you have an OSCP or similar certification.
    2. A real pen test will set off all kinds of alarms.
    3. You don’t get paid until you deliver a 100+ page report detailing what you did and your findings.
    • ameancow@lemmy.world
      link
      fedilink
      English
      arrow-up
      23
      ·
      5 days ago

      You’re implying that people who post on 4-chan have no clue how the real world works and no idea what business is like and how people make money!

    • Captain Howdy@lemm.ee
      link
      fedilink
      arrow-up
      24
      arrow-down
      4
      ·
      5 days ago
      1. Most folks dgaf about certs, and I agree with them. Certs are BS. I only have certs because employers paid for them and in tech (especially security) there’s a LOT of free time if you know what you’re doing. Certs only prove you can pass a test.

      2. Bold of you to assume most companies have intrusion detection systems and that their monitoring isn’t muted half the time.

      3. Findings come from an automated report generated by a scanner that does literally all the work.

      OP post is really not that far off. It’s an easy gig.

      Source: I’ve worked on both sides.