Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 58 guests and 1 member online
You are here:
Home
Resources
Tools
Rapid7 Introduces Metasploit Pro
EH-Net
May 21, 2013, 05:37:32 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Resources
>
Tools
(Moderator:
don
) >
Rapid7 Introduces Metasploit Pro
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Rapid7 Introduces Metasploit Pro (Read 18604 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4165
Editor-In-Chief
Rapid7 Introduces Metasploit Pro
«
on:
October 20, 2010, 08:59:52 AM »
We knew it was coming, so read on. If you want a live demo with HD Moore, join him for a live Metasploit Pro demo on November 2nd @ 2pm Eastern. Register here:
http://bit.ly/dqhMZB
Quote
Rapid7 Introduces Metasploit Pro - The World’s First Penetration Testing Solution that Achieves Unrestricted Remote Network Access Through Firewalls
Metasploit Pro First to Offer Team Collaboration to Increase Efficiency of Security Testing
BOSTON, Mass. – October 19, 2010 – Rapid7®, the leading provider of unified vulnerability management and penetration testing solutions, today announced the availability of Metasploit Pro™, the new software for security professionals in enterprises, government agencies and consulting firms who need to make network security testing more efficient to reduce costs. Unlike alternative products, Metasploit Pro improves the efficiency of penetration testers by providing unrestricted remote network access and enabling teams to collaborate efficiently. Metasploit Pro exceeds the functionality of Metasploit Express™ with support for security testing of custom Web applications, managing client-side campaigns against end-users and additional evasion features.
“Metasploit Pro completes our suite of penetration testing products and addresses the needs of the penetration testing expert who requires advanced features,” said Mike Tuchen, Rapid7 president and CEO. “We built Metasploit Pro with the same intuitive interface and efficient workflows of Metasploit Express and added advanced features that enable penetration testers to compromise networks deeper and faster. As a result, they can complete their security testing in less time, greatly reducing the overall impact on security budgets.”
The Metasploit® Framework is the most widely used and mature solution in the market with more than one million unique downloads in the past year and the world’s largest, public database for quality assured exploits. As organizations face increasing threats to complex, business-critical systems, the ability to simulate realistic attacks on their infrastructure in a fast and cost-effective manner is critical. Only Metasploit products are based on the Metasploit Framework, the gold standard for penetration testing, and are therefore best suited to emulate realistic attacks.
And let's not forget this...
Quote
Metasploit Pro is available immediately for $15,000 per named user, per year and includes support with dedicated SLAs provided by Rapid7 staff.
For full press release:
http://www.rapid7.com/news-events/press-releases/2010/2010-introduces-metasploit-pro.jsp
For product info:
http://www.rapid7.com/products/metasploit-pro.jsp
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
ckirsch
Newbie
Offline
Posts: 10
Re: Rapid7 Introduces Metasploit Pro
«
Reply #1 on:
October 21, 2010, 10:34:18 AM »
You can already download a fully featured trial version to take Metasploit Pro for a test drive. Here's the download link:
http://www.rapid7.com/downloads/metasploit-pro.jsp
Chris
Logged
Ketchup
Hero Member
Offline
Posts: 1021
Re: Rapid7 Introduces Metasploit Pro
«
Reply #2 on:
October 21, 2010, 09:46:27 PM »
This is exciting news. The price is rather hefty, but I believe it is still cheaper than Core IMPACT. I can't wait until someone does a side by side comparison of the two. I will have to play with the trial version in the mean time.
Logged
~~~~~~~~~~~~~~
Ketchup
ckirsch
Newbie
Offline
Posts: 10
Re: Rapid7 Introduces Metasploit Pro
«
Reply #3 on:
October 22, 2010, 10:20:07 AM »
Yes, it's about half the price of Core Impact Pro. Metasploit Pro is designed for professional penetration testers in consulting firms and red teams.
There are also other options available, for example Metasploit Express for $3,000, which is designed for vulnerability management teams who want to correctly assess their risks by checking if a vulnerability is actually exploitable.
Of course, there is always the free, open-source Metasploit Framework. Version 3.5.0 just came out two days ago, so make sure you update your installation if you have it already! The Framework is funded through the commercial editions and contains the same exploits and modules but doesn't include the same web GUI and lacks some of the advanced features such as workflow, web app scanning & exploitation, social engineering campaigns & VPN pivoting.
Logged
ckirsch
Newbie
Offline
Posts: 10
Re: Rapid7 Introduces Metasploit Pro
«
Reply #4 on:
October 22, 2010, 10:23:14 AM »
BTW - you were also asking about a comparison of Core vs Metasploit Pro. Pro is very new, so no public comparison is available yet but check out the HackMiami Pwn-Off between Core Impact Pro and Metasploit Express, which has a smaller feature set than Metasploit Pro.
You can read the review here:
http://www.n00bz.net/
Logged
BillV
Hero Member
Offline
Posts: 1892
Re: Rapid7 Introduces Metasploit Pro
«
Reply #5 on:
October 25, 2010, 12:56:37 PM »
Quote from: ckirsch on October 22, 2010, 10:23:14 AM
BTW - you were also asking about a comparison of Core vs Metasploit Pro. Pro is very new, so no public comparison is available yet but check out the HackMiami Pwn-Off between Core Impact Pro and Metasploit Express, which has a smaller feature set than Metasploit Pro.
You can read the review here:
http://www.n00bz.net/
Are you from the HackMiami group by chance?
I met a couple of those guys recently at the Hacker Halted conference and sat in on one of the presentations. Cool group of people and definitely doing some interesting things.
Logged
ckirsch
Newbie
Offline
Posts: 10
Re: Rapid7 Introduces Metasploit Pro
«
Reply #6 on:
October 27, 2010, 08:43:23 AM »
Hi BillV,
no, I'm not with HackMiami - yes, they're cool guys. I'm actually with Rapid7, the people behind Metasploit. On this forum to keep the community informed of recent developments and to answer questions about Metasploit.
Chris
Logged
DrivinTin
Jr. Member
Offline
Posts: 51
Net+, Sec+, C|EH, ECSA, CISSP, CASP
Re: Rapid7 Introduces Metasploit Pro
«
Reply #7 on:
November 02, 2010, 11:43:54 AM »
There is a live demo with HD today at 2pm EDT for those wanting more info.
https://www1.gotomeeting.com/register/691980513
Logged
Currently working on:
A UAV Project
Speaking and conferences
sil
Hero Member
Offline
Posts: 549
Re: Rapid7 Introduces Metasploit Pro
«
Reply #8 on:
November 02, 2010, 12:43:15 PM »
Quote from: ckirsch on October 22, 2010, 10:23:14 AM
BTW - you were also asking about a comparison of Core vs Metasploit Pro. Pro is very new, so no public comparison is available yet but check out the HackMiami Pwn-Off between Core Impact Pro and Metasploit Express, which has a smaller feature set than Metasploit Pro.
You can read the review here:
http://www.n00bz.net/
Ahem
Hate to be the bearer of realistic news here, but I think I'll wait until metasploit professional has matured a bit. The difference between Core and Metasploit would be Core's capability and experience at developing weaponized 0day from reversed Patch Tuesday's and advisories.
HDMoore is a helluva guy (hey HD, I know you pop in from time to time) however, Core has some seriously scary guys. HD is literally a one man team (very effective one not to take anything away whatsoever.) Metasploit was and is popular because of the granularity involved with being able to plop in anything your heart desires. From a "geek" slash "hacker" perspective its cool however, from the Whitehat/Crystalbox side of the show... No one is getting their hands dirty. After all, WTH would I be plopping down $30k for Core or to be more precise $3k for a contractor license
Two ways to skin a cat here.
Anyhow, unless Rapid7's MSploit Pro is ready to deploy some highly effective unseen exploits immediately, I anticipate MSploit Pro to be a real slow seller. I mean this in a respectful, articulate and "matter of factly" tone so don't confuse it with negativity. Right now, if I can't "get it poppin" with Canvas + Metasploit community + some social engineering, then I move on to Core when financially practical. I can't think of a reason to replace or "assist" my existing tools so it would be a hard pitch to my CTO.
me: "I need MSploit Pro"
him: "why I just got you Canvas with exploit packs"
me: "Because I uh.... Well metasploit community is limited..."
him: "to what... What could it possibly do that you couldn't socially engineer your way in"
me: "reports!"
Make sense? Most of the times I have to fight tooth and nail for tools that I need and I have to make my budget money go the distance. I LOVE playing with tools, but until I see something "to the extreme", I would be hard pressed arguing the case to purchase it. I DL'd a copy, just haven't had time to play with it yet. I would love to put it to my OWN testing then make a vid to post
As I've shown before, I managed to get more "exploited" with Canvas than I did metasploit:
http://www.infiltrated.net/Metasploit-Express-Versus-Canvas/
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
hdmoore
Newbie
Offline
Posts: 5
Re: Rapid7 Introduces Metasploit Pro
«
Reply #9 on:
November 02, 2010, 03:10:06 PM »
Just chiming in real quick; The Metasploit team within Rapid7 consists of six full-time developers, the core community team is another 10, and we leverage the wider community contributions in our products as well. This collaborative approach for the shared core framework is why the commercial versions are more than competitive with other products on the market and why we continue to invest in the community.
The Metasploit commercial products are selling well not because they contain exclusive exploits, but because they make penetration testing relatively simple and handle the annoying parts of security work (automation, auditing, reporting, team collaboration). Most of what you can do in the commercial products can be done with the free framework, this is intentional, and our differentiators are really around how you use the capabilities within the framework, not the capabilities themselves.
The great thing about using the same Metasploit core as the free product is that you can leverage modules written by third-party developers. The exploithub.com project is one approach to getting access to additional exploits, but any exploits developed internally for the free version of Metasploit Framework can be used seamlessly with the commercial products.
-HD
Logged
sil
Hero Member
Offline
Posts: 549
Re: Rapid7 Introduces Metasploit Pro
«
Reply #10 on:
November 02, 2010, 03:31:07 PM »
HD, thanks for coming back again and clarifying things. First off, thanks for the many years of reading material and keeping metasploit cool. Second, congrats on doing things your way with metasploit even with the Rapid7 purchase/joint venture, I'm sure politricks can be a pain sometimes but hopefully Rapid is smart enough to let you continue running the metasploit show. Thirdly... Yes! I will get around to putting a video on Metasploit Express to counter Metasploit versus Canvas (just really busy) I know I said I would and I haven't forgot...
Anyway, its good to see the numbers (how many developers, etc.), albeit known that many companies don't like sharing this information (perhaps we could go kick chameleon @ eeye). It gives a lot of credibility for those who are unaware of 1) metasploit 2) Rapid7 and 3) the merger/buyout between the two.
Don't get my initial post wrong, I love metasploit, I use it intensely professionally and academically (learning) for a variety of things not limited to penetration testing. I'm aware of ExploitHub's POV and direction and would love to see that pan out. It would likely be a "sick" mashup for pentesters if a ZDI/iDefense approach was taken. "Mix and match your metasploit modules." THAT would be worth it by far.
I spoke with Ivan Arce via email about this one time (pay for play security research) and they (Core) decided it didn't fit their model. THAT is something to think about for a moment. Look @ what Dave @ Immunity has going on with like D2 Exploit pack, etc., or ZDI. Any indications/hints of you guys (Rapid+Metasploit) doing the same - Pay for Play/Security Research/Exploit Wednesdays_to_Metasploit_Modules?
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
GAWN - GIAC Assessing Wireless Networks
: Karen Millen Dresses Things did improve as the decade gone on
(0) by
dtree70fx
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Programming
: Finished Python Course in Codecademy now what?
(11) by
securitian
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
Tutorials
: Need guidance
(8) by
r0ckm4n
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.