SlideShare a Scribd company logo
Importance of Penetration
Testing Education
JASMINE M JACKSON
Stats
 Hometown: Berkeley, CA
 Currently reside: Charlotte, NC
 Masters in Computer Science, Graduate Certificate in Information Security and
Privacy from University of North Carolina at Charlotte (UNCC)
 Assistant Organizer of OWASP Charlotte Chapter
 Have security certifications: GSEC, GWAPT, and currently studying for the OSCP
 Currently work as a penetration tester
PassionForPentesting
 Created the blog in 2012
 Frustrated of not being in the information security field
 Blog is an online portfolio that displays my skills in web applications security,
forensics, etc., through write-ups.
 Blog is also used to teach the absolute beginner about information security with
cost-effective training options.
Cost-Effective Training Courses
 PentesterLab (www.penesterlab.com)
 Have different badges – essential, android, capture the flag, etc. This is $19.99/month
 Also has a bootcamp portion - which is free
 OverTheWire (www.overthewire.org/wargames)
 Have different “wargames” in different topics – Unix (Bandit), Natas (Web-Security) –
this is free
 HackTheBox (www.hackthebox.eu)
 Have different labs that are similar to the OSCP. Need to hack the registration screen to
obtain product key. – this is free
Cost-Effective Training Courses cont’d
 Vulnerable By Design (www.vulnhub.com)
 Vulnerable machines with different levels of difficulty (easy, medium, and hard)
 This is free
 PicoCTF (www.picoctf.com)
 Intended for high school students, but all are welcome (I have write-ups on
PassionForPentesting.com)
 Have different categories – forensics, web security, etc.
 This is free
 OWASP (www.owasp.org)
 Have different projects (Juice Shop, Security Shepherd) that are useful for hacking
 This is free
QUESTIONS?

More Related Content

PDF
WTF is Penetration Testing
PDF
What is pentest
PDF
WTF is Penetration Testing
PPTX
So you wanna be a pentester - free webinar to show you how
PDF
Understanding the Importance of a Penetration Testing Course.pdf
PDF
Building security into the pipelines
WTF is Penetration Testing
What is pentest
WTF is Penetration Testing
So you wanna be a pentester - free webinar to show you how
Understanding the Importance of a Penetration Testing Course.pdf
Building security into the pipelines

More from Vandana Verma (17)

PPTX
Applying OWASP web security testing guide (OWSTG)
PDF
Running an app sec program with OWASP projects_ Defcon AppSec Village
PDF
SARCON Talk - Vandana Verma Sehgal
PDF
Sacon 2020 living in the world of zero trust v1.0
PDF
Addo 2019 vandana_dev_secops_culturalchange
PDF
App Sec village DevSecOps as a culture
PPTX
Oscp - Journey
PPTX
Web sockets - Pentesting
PPTX
Story of http headers
PPTX
Security audits & compliance
PPTX
Basics of Server Side Template Injection
PPTX
SIEM Vendor Neutrality
PPTX
Getting started with android
PPTX
Identity & access management
PPTX
Chariot generic presentation owaspwia_Infosecgirls
PDF
OWASP - Dependency Check
PDF
Incident response in Cloud
Applying OWASP web security testing guide (OWSTG)
Running an app sec program with OWASP projects_ Defcon AppSec Village
SARCON Talk - Vandana Verma Sehgal
Sacon 2020 living in the world of zero trust v1.0
Addo 2019 vandana_dev_secops_culturalchange
App Sec village DevSecOps as a culture
Oscp - Journey
Web sockets - Pentesting
Story of http headers
Security audits & compliance
Basics of Server Side Template Injection
SIEM Vendor Neutrality
Getting started with android
Identity & access management
Chariot generic presentation owaspwia_Infosecgirls
OWASP - Dependency Check
Incident response in Cloud
Ad

Recently uploaded (20)

PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPT
Teaching material agriculture food technology
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Unlocking AI with Model Context Protocol (MCP)
PPTX
Big Data Technologies - Introduction.pptx
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PPTX
MYSQL Presentation for SQL database connectivity
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
cuic standard and advanced reporting.pdf
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Network Security Unit 5.pdf for BCA BBA.
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Teaching material agriculture food technology
Mobile App Security Testing_ A Comprehensive Guide.pdf
Review of recent advances in non-invasive hemoglobin estimation
Unlocking AI with Model Context Protocol (MCP)
Big Data Technologies - Introduction.pptx
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Per capita expenditure prediction using model stacking based on satellite ima...
Understanding_Digital_Forensics_Presentation.pptx
The Rise and Fall of 3GPP – Time for a Sabbatical?
NewMind AI Monthly Chronicles - July 2025
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
MYSQL Presentation for SQL database connectivity
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Building Integrated photovoltaic BIPV_UPV.pdf
cuic standard and advanced reporting.pdf
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
20250228 LYD VKU AI Blended-Learning.pptx
Network Security Unit 5.pdf for BCA BBA.
Ad

Importance of Penetration Testing

  • 1. Importance of Penetration Testing Education JASMINE M JACKSON
  • 2. Stats  Hometown: Berkeley, CA  Currently reside: Charlotte, NC  Masters in Computer Science, Graduate Certificate in Information Security and Privacy from University of North Carolina at Charlotte (UNCC)  Assistant Organizer of OWASP Charlotte Chapter  Have security certifications: GSEC, GWAPT, and currently studying for the OSCP  Currently work as a penetration tester
  • 3. PassionForPentesting  Created the blog in 2012  Frustrated of not being in the information security field  Blog is an online portfolio that displays my skills in web applications security, forensics, etc., through write-ups.  Blog is also used to teach the absolute beginner about information security with cost-effective training options.
  • 4. Cost-Effective Training Courses  PentesterLab (www.penesterlab.com)  Have different badges – essential, android, capture the flag, etc. This is $19.99/month  Also has a bootcamp portion - which is free  OverTheWire (www.overthewire.org/wargames)  Have different “wargames” in different topics – Unix (Bandit), Natas (Web-Security) – this is free  HackTheBox (www.hackthebox.eu)  Have different labs that are similar to the OSCP. Need to hack the registration screen to obtain product key. – this is free
  • 5. Cost-Effective Training Courses cont’d  Vulnerable By Design (www.vulnhub.com)  Vulnerable machines with different levels of difficulty (easy, medium, and hard)  This is free  PicoCTF (www.picoctf.com)  Intended for high school students, but all are welcome (I have write-ups on PassionForPentesting.com)  Have different categories – forensics, web security, etc.  This is free  OWASP (www.owasp.org)  Have different projects (Juice Shop, Security Shepherd) that are useful for hacking  This is free