Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 28 guests and 2 members online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow Toolsarrow Metasploit 3.0 Watch
Ethical Hacker Community Forums
January 09, 2009, 01:45:31 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2009 - May 4 - 9. Boot Camps & an Ethical Hacking Conf. www.chicagocon.com
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Metasploit 3.0 Watch  (Read 2757 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2442


Editor-In-Chief


View Profile WWW
« on: November 04, 2006, 01:25:40 AM »

As we get closer to a final release, Metasploit v3.0 Beta 3 has been released. Download it here:

http://www.metasploit.org/projects/Framework/msf3/#download

Share your thoughts on v3.0, Metasploit in general or anything else that comes to mind when it comes to exploit frameworks.

Here's one to get the ball rolling... By the strict definition of what we've come to know this term to be (those who blindly use tools, scripts and exploit code written by someone else without knowing how to do it themselves), does that make most who use Metasploit script kiddies, even us 'professionals' in IT and security?

Don
Logged

CISSP, MCSE, CEH, Security+ SME
Kev
Guest
« Reply #1 on: November 04, 2006, 02:07:04 PM »

LOL! That’s a good topic to get some debate going.  I don’t think you will get 2 people to agree exactly what a script kiddie is because we all have our own idea.  Mine is simple. A script kiddie is someone that has no idea of how or why a tool is working but only knows how to blindly point and click and hopes  occasionally he hits a vulnerable target.   If using a tool that someone else wrote makes you a script kiddie, well then every hacker on this planet is a script kiddie, because who doesn’t use nmap for instance.  The trick is really understanding networking, operating systems, tcp/ip, and really know how to use the tools. Sometimes you have to understand that not everything a tool tells you is correct and you have to interpret the results. You might even have to “play” with the tool to do some custom and new things.  This comes from experience by doing a lot of hacking. 

I know of some very good pentesters that don’t code tools and only use the tools others have written. The difference is they have been doing it a long time and can really make the tools work well and know how to interpret the results.   On the other hand, to be an elite hacker in the “black hat” sense, you have to know coding and write your own trojans and if you are lucky enough to find a new exploit no one has found, then you will be able to penetrate places others will never crack.  Heck, maybe a script kiddie is just someone that uses a name like L33t HaX0r , Ha Ha!  Smiley
« Last Edit: November 04, 2006, 08:17:34 PM by Kev » Logged
mn_kthompson
Jr. Member
**
Offline Offline

Posts: 58



View Profile WWW
« Reply #2 on: November 04, 2006, 10:00:01 PM »

I'd like to add to what Kev said.  "Script Kiddie" is a term of derision for an individual who doesn't look for new exploits and doesn't do anything to improve the security posture of the computer using community, he or she simply downloads a tool and starts searching for a place to use it.

There is a big difference between that individual and a penetration tester, a respected professional that is hired to assess the security of an organization and improve the security posture of that organization.

Although it may be difficult to see a major difference, I think the motivation of the person using the tools is one of the ways to distinguish between a script kiddie and a penetration tester.  That is, of course, in addition to what Kev said about script kiddies not understanding how the tools work.
Logged
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1049


View Profile WWW
« Reply #3 on: November 05, 2006, 01:03:00 PM »

 you'd be surprised at the number of people i see that cant even work MSF on the command line... it even keeps some of the kids out.

the real power of MSF will be from some of the plugins, scripting, and the meterpreter. that will keep most of the kids away from the real power.

if you are upset that some lamers can point click and hack your box, you should have patched it to begin with.
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2007, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.043 seconds with 24 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
How many security events including conferences and training do you attend a year:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2009 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.