3 ms·
That product looks awfully similar to Metasploit ( http://www.metasploit.com/ http://www.metasploit.com/ ) , no? How is it different? I watched the demo video
by bjg 16y ago
That product looks awfully similar to Metasploit ( http://www.metasploit.com/ http://www.metasploit.com/ ) , no?
How is it different? I watched the demo video and couldn't really tell.
- fmavituna 16y agoMetasploit mostly focuses on Infrastructure and exploiting known vulnerabilities. Netsparker is solely focused on web application security (detection & exploitation). For example Netsparker can crawl AJAX/Javascript apps, support form authentication etc. Metasploit on the other hand possibly will never do that kind of stuff.
- tptacek 16y agoYou are comparing a $1000 commercial product to open source Ruby code. Metasploit is sponsored by Rapid7, which does in fact have a product that is competitive with your offering. Do we need to get into a detailed discussion of why I think the plug for your scanner is inappropriate for this thread? Or can we just let it suffice to say that HN isn't a great place to promote products on random threads?
- fmavituna 16y agoI'm not comparing, I'm telling the difference. Just like Netsparker will not do port scanning, possibly Metasploit will not do full web app stuff. You can talk with someone from Rapid7 and they'll tell you the same thing. And for the record I love Metasploit, it's a fantastic tool. We have a good relationship with Rapid7 guys, they even has a module to import Netsparker results into Metasploit and we keep getting synced with them in new updates. > Or can we just let it suffice to say that HN isn't a great place to promote products on random threads? Personally I love seeing other HNers to send their relative products, projects, startups, commercial ideas, job ads in HN threads, I don't think there is anything wrong with that. You might think otherwise, that's why there is one upvote and one downvote button.
- tptacek 16y agoMetasploit isn't web application penetration tool. W3af, the other open source security tool Rapid7 sponsors, is. Meanwhile, Rapid7's commercial offering, Nexpose, also crawls Ajax applications and, if this flaw is as simple as people seem to think it is, would likely have found it... as would OWASP WebScarab or Burp (a tool that costs a fraction of what your tool does and belongs in the back pocket of every web developer). I'm responding harshly because I do not agree with your logic (to wit: any thread involving security is a great place to plug your scanner) and because I found your comparison of Netsparker to Metasploit disingenuous: Metasploit simply isn't Rapid7's web app offering.
- randallsquared 16y agoI found your comparison of Netsparker to Metasploit disingenuous I have no position on whether he should mention his product in a news thread about SQLI, but he was responding directly to bjg, who said: That product looks awfully similar to Metasploit ( http://www.metasploit.com/ http://www.metasploit.com/ ) , no? How is it different? So, his "comparison" was just responding to someone saying "Hos is it different?", literally.
- marcamillion 16y agoI don't know when HN became a place where hackers felt afraid of plugging their products - given that we are all hackers trying to build/sell products - where appropriate. I don't get the big fuss. If it was a story about Bingo Cards, and patio11 plugged bcc.com I am pretty sure you wouldn't be all worked up about this. Let's just calm it down a notch and not try to be kingmaker's here. If the community found the plug abhorrent, they would downvote it. He would get the point. Although, to be quite honest, now you have given his product even more promotion and visibility so it's a net positive for him - not sure it's the result you wanted in the first place. And given that I would likely do something similar, kudos to him for every extra dollar he has earned from your rant.
- iuguy 16y agoDisclaimer: I use Metasploit on a more or less daily basis, as well as Burp Suite Pro and more recently have been evaluating NetSparker Community Edition as our Canvas D2 subscription is up for renewal, and we've been considering switching to NetSparker. I've met Ferruh once at DC4420[1] and he seemed like a sound guy to have a beer with. Ferruh was simply responding to a direct question about how it was different. Sure, he's the author but a) he was asked. b) he's probably best suited. Ferruh isn't running a matasano scale operation, he's doing it on his own, peldi style. It's not inappropriate for him to discuss his product, nor to answer questions on it - this is a startup community after all. At what point did you become the HN comment police? [1] http://www.dc4420.org http://www.dc4420.org
- deleted 16y ago[deleted]
- iuguy 16y agoAs someone who uses Metasploit, Canvas, Burp Suite Pro and am currently evaluating Netsparker I might be able to offer an unbiased view. Metasploit is an exploitation framework. There's different versions available (community, pro etc.). The community version has a web app scanner and is reasonably ok, but it tends to be caught by intrusion detection systems fairly easily and it's payloads often don't clean up properly. It's better suited to infrastructure exploitation, but can be used in a web app context. Canvas[1] has some limited web app scanning capability but has more of a core focus on infrastructure exploitation. Burp Suite Pro[2] is a framework for testing web applications. It's probably the best tool out there for testing web apps (if you know what you're doing). It's also ludicrously cheap and there is a free version for non-commercial use. It comes with a fairly comprehensive web app scanner. NetSparker is a web application scanner. From what I can tell it's mainly competing with things like Accunetix. It has some features that are similar to Metasploit Pro but focuses primarily on the application layer. It sits more between Burp Suite Pro and Canvas for my purposes. You can download an eval from http://www.mavitunasecurity.com/ http://www.mavitunasecurity.com/ or the community edition. [1] http://www.immunityinc.com http://www.immunityinc.com [2] http://www.portswigger.net http://www.portswigger.net