Metasploit Framework 3.0 Product Review - Information Security Magazine - Page 1

Metasploit Framework 3.0 Product Review

PENETRATION TESTING


Metasploit Framework 3.0
REVIEWED BY PETER GIANNACOPOULOS

Metasploit LLC
Price: Free

The Metasploit Framework

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

is a platform for developing, testing and executing exploit code for all popular Unix, Linux and Windows platforms; it's an essential tool for the serious penetration tester or security professional. The latest release only serves to further cement its formidable capabilities.

Installation is a breeze: download the appropriate package (Windows or Linux) and execute. The Meta-sploit Framework can either be used via the familiar and capable console interface or the much improved Web interface. For a free product, it contains surprisingly good documentation for users and developers, so it's fairly easy to get productive quickly.

Metasploit has a searchable database of more than 180 exploits, targeting multiple processor architectures and operating systems, with more than 70 payloads that can be delivered to exploitable systems. Using the product is ridiculously simple: select the exploit via the Web or console GUI, specify target, payload and options, and run the exploit. It really is as easy as "point, click, own."

This was first published in July 2007