Signal 42 - Information Technology News
CityClubCasino.com - Get 7 times match bonus upto $100 per day!
BingoFantasy.com - Get $5 Free!
RaceTrackCasino.com
Bingo777.com - Get $5 Free!

Pulse Of The Web


Technology News Archive
April 2007
February 2007
January 2007
December 2006
November 2006
October 2006
September 2006
August 2006
July 2006
June 2006
May 2006
April 2006
March 2006
February 2006
January 2006
December 2005
November 2005
October 2005
September 2005
August 2005
July 2005
June 2005
May 2005
April 2005
March 2005
February 2005
January 2005
December 2004

Technology News Feed Add Information Technology News Feed to Google
Add Information Technology News to My Yahoo!
Add Information Technology News to My MSN!
Information Technology News Feed Syndication
We support:

Apache
XFree86
Cygwin
Linux Documentation Project
CURL
GNU
ProFTPd
Sudo-ftp
Sudo

Useful Tutorials:

PostgreSQL
FreeBSD
Python
GCC
PHP4

 

Security Researchers Update Open-Source Exploit Tool


Thursday, 13 January 2005

A group of security volunteers on Tuesday released a new version of an advanced open-source framework for developing, testing and using exploits.


The Metasploit Framework 2.3 is the latest evolution of a project that began as a lark and has turned into a serious tool for penetration testing and exploit development. The framework, which is written in Perl and runs on most Unix (news - web sites) systems and Windows, is a somewhat less formal version of pen-testing tools such as Core Security Technologies Inc.'s Core Impact or Immunity Inc.'s Canvas, but it is designed to be every bit as powerful and easy to use.


The new version contains a host of updated capabilities and an expanded library of custom-made exploits and payloads, usable against vulnerabilities in Windows, Linux (news - web sites) and some Unix variants. The framework is fronted by a clean user interface and it takes just a few clicks to get to the point where users can enter an IP address and port number and run an exploit against a target system.


Users can scroll through a Web interface that can be sorted by either exploits or payloads. Clicking on a specific exploit brings up a description of the vulnerability, including a link to the original advisory if there is one, and a list of vulnerable versions. Users then can click on a version, such as Windows XP (news - web sites), and see a list of available payloads capable of exploiting the flaw.


After choosing a payload, the user is presented with a page asking for the name of the remote host and perhaps one or two other pieces of data, depending on the payload. One more click and the payload is on its way to the unsuspecting host.


Click here to read more about the Metasploit Framework.


In the past couple of years, user-friendly exploitation tools have become quite common and any aspiring cracker need only visit one of hundreds of security or underground sites to find not just the tools, but detailed instructions on how to find vulnerable targets and what to do once they've gained access to a machine. The Metasploit Framework certainly could be used for those purposes as well, but it was designed for the use of administrators and security researchers interested in running exploits against their own systems.


And, it still requires a bit of knowledge and skill to find vulnerable target hosts and to know which payload is the right one to exploit a particular vulnerability. The system's main developer, HD Moore, who is well-known within the security community as a researcher, author and frequent speaker at security conferences, acknowledged that some people in the industry are nervous about the release of tools as powerful as the framework, but he said that the capabilities it provides to users are necessary.


"The framework is quickly becoming a standard tool for both penetration testing and security product validation. I believe that giving end users the power to test their own security measures restores a much-needed balance to the information security industry. The best-selling security products are all defensive in nature; the only way you can gauge their effectiveness is to actively test them," Moore said.


"There is a common argument that the framework allows less-skilled attackers to break into systems that they would not be able to access otherwise. Most of the exploit modules included with the framework are actually based on publicly available exploit code. Only rarely does the framework provide an attack vector that is not already available to the script kiddies at large. There have been a handful of cases where we released the first public exploit module for a vulnerability, only to discover that the 'underground' cracking groups have had an exploit of their own for quite some time. The Framework gives the network administrator with the same capabilities as the people who are attacking their networks."


The Metasploit Framework also comes with a unique license that allows commercial vendors to integrate it into their own products and then resell it. Researchers also can write their own modules for the framework and sell them as commercial products.

Source: Ziff Davis via Yahoo


All trademarks and copyrighted information contained herein are the property of their respective owners.



Related Articles


 
Best Voip Service Providers



Order SunRocket

From $16.60, unlimited minutes with 12-month prepay.

Rating:

Free Uniden cordless phone, no activation fee!




Order Packet8

From $9.99 (special promotion), unlimited minutes, no contract!

Rating:

Save Over $120!




Order ViaTalk

From $15.95, unlimited minutes with 24-month contract

Rating:

Free Exxon-Mobil gas card!




Order Netzero

From $14.99 unlimited minutes, no contract!, 3 months free.

Rating:

Get Three Months of NetZero VoIP Free!

Security News
Voip News
Telecom News
Hardware News




A   B   C   D   E   F   G   H   I   J   K   L   M   N   O   P   Q   R   S   T   U   V   W   X   Y   Z