[Full-disclosure] HD Moore
Valdis.Kletnieks at vt.edu
Valdis.Kletnieks at vt.edu
Mon May 5 16:20:17 BST 2008
On Sun, 04 May 2008 16:27:49 BST, n3td3v said:
> On Fri, May 2, 2008 at 9:32 AM, Nate McFeters <nate.mcfeters at gmail.com> wrote:
> > Oh that... Yeah, shame on hd... Maybe he was busy updating metasploit
> > so that real researchers have a great vulnerability development
> > framework, or something else that provided some worth to people.
>
> Maybe he was busy updating Metasploit so that script kids have a great
> vulnerability development framework.
>
> He should stop providing them with a great vulnerability development framework.
There's 2 really great uses for metasploit for white hat security guys:
1) When you're handed a /16 or two during a pen test, and need a quick way
to poke a whole bunch of machines for a vulnerability, it's hard to roll-your-own
exploit tester as fast as you can chinese-menu one in metasploit.
2) It's a *great* tool for impressing on a PHB just how easy it is to launch
an exploit for something at one of the unsecured systems he's responsible for.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 226 bytes
Desc: not available
Url : http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20080505/612cf0b8/attachment.bin
Full-Disclosure is hosted and sponsored by Secunia.