Monday, October 25, 2010

Metasploit BETA

Since the "gag order" has been lifted since the official launch of Metasploit Pro, I thought I might share some screen shots and some quick thoughts about Metasploit Pro (Beta).  It is a web interface that

The install/setup of Metasploit Pro (Beta) is really self explanatory.  Just some quick initial configurations settings to get started.


That's it, that's all there is to it. Of course if you want to leverage NeXpose vulnerability scanning, further configuration will be needed.

To start off, you have to create a Project where you will define the subnet(s) and Metasploit users you want to access the project/results.



Once you've got the Project created, you can create separate tasks underneath that Project. Below is a "Host and Service Discovery" task.





Then once you run the task you can view the task status. Below is the "Host and Service Discovery" task running that we created above.


Once that scan is complete you can view the Hosts that were discovered:


Metasploit Pro also has a "Campaign" capability allowing you to setup and manage a Social Engineering/Phishing Campaign to allow you to attack the human factor. Definitely useful!!




So as you can see, the Metasploit Pro product is aesthetically pleasing, intuitive, and will no undoubtedly compete with the the other competitors in the penetration testing software category.  Couple it with the NeXpose vulnerability scanner, it is a complete vulnerability, exploiting, and social engineering package.  The reporting was pretty decent as well for providing the information to your company or clients.



Thursday, September 30, 2010

In a Computer Worm, a Possible Biblical Clue

Interesting look at the Stuxnet worm that has been in the headlines. Beyond some of the technical indicators, they believe another biblical clue is in the code for the worm....

In a Computer Worm, a Possible Biblical Clue (CNBC)
http://www.cnbc.com/id/39435594/

Saturday, May 15, 2010

Modern cars vulnerable to malicious hacks - tech - 14 May 2010 - New Scientist

This is related to a previous post about how cars will be a new hack hobby. They say you have to be physically present...think a Netbook and with a wireless carrier card tucked under the seat.

Modern cars vulnerable to malicious hacks - tech - 14 May 2010 - New Scientist

Wednesday, May 12, 2010

Adobe Shockwave Player Multiple Memory Vulnerabilities

You didn't think that Acrobat and Flash would keep all the attention did you?


Adobe Shockwave Player 11.5.6.606 (DIR) Multiple Memory Vulnerabilities

Tuesday, May 11, 2010

May 2010 Microsoft Patches

It's that time of the month again...no not that one.  It's Microsoft Patch Tuesday.  Get patching kids!!

Microsoft Security Bulletin Summary for May 2010

Vulnerability in Outlook Express and Windows Mail Could Allow Remote Code Execution (978542) Vulnerability in Microsoft Visual Basic for Applications Could Allow Remote Code Execution (978213)

Microsoft Exploitability Index for May 2010 Bulletin Release


Saturday, May 8, 2010

Security firm reveals Microsoft's 'silent' patches

Nice Microsoft, nice.  This would be been disastrous if it broke things.

Security firm reveals Microsoft's 'silent' patches