Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 75 guests and 1 member online
 
Advertisement

You are here: Home arrow Resourcesarrow Toolsarrow SecurityForest: Another Exploit Framework
EH-Net
May 18, 2013, 01:08:40 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: SecurityForest: Another Exploit Framework  (Read 6994 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4165


Editor-In-Chief


View Profile WWW
« on: May 17, 2006, 03:58:14 PM »

Quote
SecurityForest's Exploitation Framework is similar in concept to the open-source Metasploit Framework and the commercial offerings such as Immunity's CANVAS and Core Security Technology's Impact.

The major difference between the above mentioned frameworks and the SecurityForest Exploitation Framework is that it leverages the massive amount of exploits available in the ExploitTree. These exploits are publically available and do not have to be re-written to be used in the framework (no matter what language and sometimes no matter what OS).

It basically acts as a Graphical User Interface to the ExploitTree which is dynamically updated at the same time as the ExploitTree.

The above mentioned frameworks are great and the Exploitataion Framework doesn't even compare to them on a technical level, it just fills the gap.

The Exploitation Framework is provided for legal penetration testing and research purposes only.

http://www.securityforest.com/wiki/index.php/Exploitation_Framework

Don
« Last Edit: May 17, 2006, 04:00:18 PM by don » Logged

CISSP, MCSE, CSTA, Security+ SME
Dengar13
Sr. Member
****
Offline Offline

Posts: 380



View Profile
« Reply #1 on: May 17, 2006, 04:19:43 PM »

Awesome Don!  This is just what I needed.  I had a pen-test last night and this would have been great to use.
Logged

A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
pcsneaker
Jr. Member
**
Offline Offline

Posts: 73


View Profile
« Reply #2 on: May 21, 2006, 11:26:40 AM »

I would'nt say that this framework is awesome.

After having a look at this I have to say that there is still a lot of work for the maintainers and the community to do before that framework becomes useable.

If you download the exploit tree you get about 2000 exploits (statistcs give you that number) but in the framework there are definitions for about 20 of them - that means that you can use that 20 out of the box.

If you want to use others you have to add them to the framework - the problem is that there is no documentation of the whole system (at least I could not find it) so you have to figure out yourself if there is the exploit you want to use and after that how to add it to the framework.

Furthermore the website is a little bit confusing - after having downloaded the exploit tree iit took me a while to find where to download the framework.

The idea is not bad but it really needs at least a minimum of documentation to be useable in a pentest...
Logged

MCSA:Security (W2k, W2k3)
MCSE:Security (W2k, W2k3)
CPTS, Network+
Dengar13
Sr. Member
****
Offline Offline

Posts: 380



View Profile
« Reply #3 on: May 21, 2006, 03:58:37 PM »

There is a section where you can download and add expolits and you can add your own custom ones if you wanted to.  This should be a great tool once there is more documentation and expolits to choose from. 
Logged

A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 8.623 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.