4 ms·
For those who aren't familiar with the Metasploit Project, it's an open source collection of safe and vetted exploits. Once an exploit module makes it into the
by raffi 14y ago
For those who aren't familiar with the Metasploit Project, it's an open source collection of safe and vetted exploits. Once an exploit module makes it into the Metasploit Framework, it's immediately available to ~250K users. The Metasploit Framework isn't just exploits though, it's an integration point for offensive capabilities that simply work together. It's also very easy to hook your own stuff into it.
There are several programs that build on the Metasploit Framework and take advantage of it. Rapid7 has commercial penetration testing products. I build the open source Armitage GUI for it and a commercial add-on called Cobalt Strike.
It's worth spending some time to learn how it works and what it does. Here's a few links:
Metasploit Unleashed Wiki:
http://www.offensive-security.com/metasploit-unleashed/Main_Page http://www.offensive-security.com/metasploit-unleashed/Main_...
My 7-part course on pen testing (with Cobalt Strike & MSF):
http://www.advancedpentest.com/training http://www.advancedpentest.com/training
Quick demo of what it looks like to attack a workstation and use it as a hop point to get other things:
http://www.youtube.com/watch?feature=player_embedded&v=S_ejYRTM8J0 http://www.youtube.com/watch?feature=player_embedded&v=S...
The best way to try the Metasploit Framework is to setup BackTrack Linux in a virtual machine:
http://www.backtrack-linux.org/ http://www.backtrack-linux.org/
A free vulnerable target is the Metasploitable virtual machine, available at:
http://sourceforge.net/projects/metasploitable/files/Metasploitable2/ http://sourceforge.net/projects/metasploitable/files/Metaspl...
- moloch 14y agoThis particular gentleman also has a few good presentations on Metasploit I saw at Defcon/Bsides: http://www.youtube.com/watch?v=G-JaHWaLmgc&hd=1 http://www.youtube.com/watch?v=G-JaHWaLmgc&hd=1 http://www.youtube.com/watch?v=y2M3SpOzeJY&hd=1 http://www.youtube.com/watch?v=y2M3SpOzeJY&hd=1