Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 43 guests online
 
Advertisement

You are here: Home arrow Featuresarrow Book Reviewsarrow Review - Metasploit Toolkit for Penetration Testing
EH-Net
May 24, 2013, 04:22:03 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Review - Metasploit Toolkit for Penetration Testing  (Read 12685 times)
0 Members and 1 Guest are viewing this topic.
UNIX
Hero Member
*****
Offline Offline

Posts: 1235


View Profile
« on: August 07, 2009, 03:25:48 AM »

I did a review on the book Metasploit Toolkit for Penetration Testing, Exploit Development, and Vulnerability Research..hope you like it.

Quote


The book is divided into 5 chapters (Introduction to Metasploit, Architecture, Environment, and Installation, Metasploit Framework and Advanced Environment Configurations, Advanced Payloads and Add-on Modules and Adding new Payloads) and 5 case studies.


The first chapter gives an introduction to Metasploit for those who are not familiar with it yet. The reader will know after reading this how it is structured, Metasploit's history, short description of some payloads etc. Unfortunately the authors did not explain why to use one over the other payload or give a more detailed explanation on them.


Chapter two explains how to actually install Metasploit and advices to keep your system up to date.


Chapter three is as short as chapter two (11 pages versus 5 pages) and only covers some basic knowledge about the content of your Metasploit framework installation directory and how to use the setg-command.


The fourth chapter covers meterpreter, VNC inject and PassiveX payloads, auxiliary modules and automation of a pen-test with autopwn. As this chapter is again very short (18 pages) it is lacking in detail and only provides a brief overview of the mentioned topics although it is not that bad at all.


Adding new Payloads which is the title of the fifth and last chapter, finally gives a good explanation on MSF 3.x (which the whole book should have covered) and how to add new exploit and auxiliary payloads as well as building a SIP invite auxiliary module. Although a short chapter too it is well written and explains the tasks in an easy to follow way.


Full review can be read at www.awesec.com.

I know that this book is already outdated and many reviews are already available, but as I had the opportunity to get my hands on a copy of it, i still decided to read through it and write a little review.

More reviews to come. Smiley
« Last Edit: August 12, 2009, 05:10:55 AM by awesec » Logged
timmedin
Sr. Member
****
Offline Offline

Posts: 469



View Profile WWW
« Reply #1 on: August 09, 2009, 08:21:31 PM »

Any idea at what point in time the book was written? MSF changes so fast
thanks so HD Moore and crew.
Logged

twitter.com/timmedin | http://blog.securitywhole.com
dalepearson
Sr. Member
****
Offline Offline

Posts: 357


View Profile WWW
« Reply #2 on: August 10, 2009, 04:33:33 AM »

Book is from 2007 if I remember currently, I have not read / reviewed the book myself but I dont think there are any current alternatives.
Logged

UNIX
Hero Member
*****
Offline Offline

Posts: 1235


View Profile
« Reply #3 on: August 10, 2009, 04:57:19 AM »

The book was written/ published on September 1, 2007. I haven't found any good alternatives covering metasploit, though I am quite sure that one will come sooner or later, hopefully from Moore himself.

However, there are some resources available at the internet which are in my opinion better than the book from above.
Logged
Andrew Waite
Hero Member
*****
Offline Offline

Posts: 928



View Profile WWW
« Reply #4 on: August 10, 2009, 05:03:29 AM »

However, there are some resources available at the internet which are in my opinion better than the book from above.

Any links in particular you're willing to share?
Logged

UNIX
Hero Member
*****
Offline Offline

Posts: 1235


View Profile
« Reply #5 on: August 10, 2009, 05:20:30 AM »

Sure. I will check my booksmarks when I am at home and update this post. If I remember correctly I had a few ones where I thought that are good to read.
Should I forget it please feel free to remind me via PM.
Logged
Jhaddix
Sr. Member
****
Offline Offline

Posts: 317



View Profile WWW
« Reply #6 on: August 23, 2009, 06:23:19 PM »

Offsec should have some stuff coming along soon for free MSF training, also The Academy pro has a metasploit category, and Rob fuller will be doing their trianing on pentesting w/BT4 which has plenty of practical MSF =)
Logged

TalioGladius
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #7 on: August 26, 2009, 02:45:46 PM »

I wish they'd release a new version of this one.
Logged
UNIX
Hero Member
*****
Offline Offline

Posts: 1235


View Profile
« Reply #8 on: August 26, 2009, 03:01:03 PM »

Totally forgot about this one. Seems I can't find the correct bookmarks I made some time ago. Guess I will have to go through all bookmarks I have and sort them out a little, already lost the overview of them.
Logged
Stocky
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #9 on: September 26, 2009, 03:46:56 PM »

Try Metasploit Unleashed:

http://www.offensive-security.com/metasploit-unleashed/

Logged
3PIL0GU3
Newbie
*
Offline Offline

Posts: 38


View Profile
« Reply #10 on: October 01, 2009, 03:09:34 AM »

While im still in the process of completing this Hackerdemia disc for Heorot.net, i had a gander at some of the powerpoint archieves that HDM had prepared on the future of the MSF sounds interesting can't wait to see how it continues in its development lifecycle over the next few years/
Logged

----------------------------
CEH
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.084 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.