Metasploit

View: New views
5 Messages — Rating Filter:   Alert me  

Metasploit

by Jon Kibler-2 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

How well do you know metasploit?

I thought I knew it fairly well. Turns out, I do know half of what I thought I
knew about metasploit. I am really surprised at how much metasploit can do that
I did not know about.

I am currently working through Offensive Security's Metasploit Unleashed online
course. It is currently a "donate to HFC"-ware course. It is a great course, and
I highly recommend it! I have learned a lot and I am only about half through the
course. (I keep going back and redoing old exercises as I get new ideas from new
material, so I am kind of slow... I should have been done by now!)

Anyway, if you use metasploit -- and if you are a pen tester, you really should
be using it!! -- I recommend you check out the course and see how your
metasploit knowledge stacks up against the course.

Jon
- --
Jon R. Kibler
Chief Technical Officer
Advanced Systems Engineering Technology, Inc.
Charleston, SC  USA
o: 843-849-8214
c: 843-813-2924
s: 843-564-4224
s: JonRKibler
e: Jon.Kibler@...
e: Jon.R.Kibler@...
http://www.linkedin.com/in/jonrkibler

My PGP Fingerprint is:
BAA2 1F2C 5543 5D25 4636 A392 515C 5045 CF39 4253


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.8 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAkrpjbAACgkQUVxQRc85QlPYsACfffUIBlr/g58ruujm10BUcfo2
RjMAn028BQC5Obc3IYtW2Qtw2Tud4Kr8
=5lDP
-----END PGP SIGNATURE-----




==================================================
Filtered by: TRUSTEM.COM's Email Filtering Service
http://www.trustem.com/
No Spam. No Viruses. Just Good Clean Email.



------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.

http://www.iacertification.org
------------------------------------------------------------------------

Re: Metasploit

by jfvanmeter :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message


Interresting, do you have a link to the course?

----- Original Message -----
From: "Jon Kibler" <Jon.Kibler@...>
To: pen-test@...
Sent: Thursday, October 29, 2009 8:42:24 AM GMT -05:00 US/Canada Eastern
Subject: Metasploit

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

How well do you know metasploit?

I thought I knew it fairly well. Turns out, I do know half of what I thought I
knew about metasploit. I am really surprised at how much metasploit can do that
I did not know about.

I am currently working through Offensive Security's Metasploit Unleashed online
course. It is currently a "donate to HFC"-ware course. It is a great course, and
I highly recommend it! I have learned a lot and I am only about half through the
course. (I keep going back and redoing old exercises as I get new ideas from new
material, so I am kind of slow... I should have been done by now!)

Anyway, if you use metasploit -- and if you are a pen tester, you really should
be using it!! -- I recommend you check out the course and see how your
metasploit knowledge stacks up against the course.

Jon
- --
Jon R. Kibler
Chief Technical Officer
Advanced Systems Engineering Technology, Inc.
Charleston, SC  USA
o: 843-849-8214
c: 843-813-2924
s: 843-564-4224
s: JonRKibler
e: Jon.Kibler@...
e: Jon.R.Kibler@...
http://www.linkedin.com/in/jonrkibler

My PGP Fingerprint is:
BAA2 1F2C 5543 5D25 4636 A392 515C 5045 CF39 4253


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.8 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAkrpjbAACgkQUVxQRc85QlPYsACfffUIBlr/g58ruujm10BUcfo2
RjMAn028BQC5Obc3IYtW2Qtw2Tud4Kr8
=5lDP
-----END PGP SIGNATURE-----




==================================================
Filtered by: TRUSTEM.COM's Email Filtering Service
http://www.trustem.com/
No Spam. No Viruses. Just Good Clean Email.



------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.

http://www.iacertification.org
------------------------------------------------------------------------

------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.

http://www.iacertification.org
------------------------------------------------------------------------


Get a Clue! WAS: Re: Metasploit

by Jon Kibler-2 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Jon Kibler wrote:
<SNIP!>
> I am currently working through Offensive Security's Metasploit Unleashed online course.
<SNIP!>

I hate to reply to my own email, BUT...

<rant>
I received dozens of (mostly off-list) messages, "I cannot find the course, will
you please send me a link"? Folks, get a clue! How can you call yourself a pen
tester if you cannot find an online course hiding in plain site? How do you
expect to be able to penetrate systems through obscure weaknesses when you miss
the 6,500Kgm gorilla in the room?

If you cannot find the course without a hint, perhaps you should be on the
Security Basics list and not the Pen Test list!! This list more or less presumes
*some* basic knowledge -- like how to use Google. (In case you don't know how to
use Google, please read: Google Hacking for Penetration Testers by Johnnie Long.)

BTW, clue: google on: Offensive Security Metasploit Unleashed

</rant>

Jon

P.S. This rant does not mean that you should not contact me with questions
regarding my posts. Those who know me, know that I am always more than willing
to help, time permitting. However, please check to obvious first!

P.S.S. For those of you that emailed me off-list asking where to find the
course... no, I will not out you. For those that emailed the list with the
question... well, what can I say?

JK
- --
Jon R. Kibler
Chief Technical Officer
Advanced Systems Engineering Technology, Inc.
Charleston, SC  USA
o: 843-849-8214
c: 843-813-2924
s: 843-564-4224
s: JonRKibler
e: Jon.Kibler@...
e: Jon.R.Kibler@...
http://www.linkedin.com/in/jonrkibler

My PGP Fingerprint is:
BAA2 1F2C 5543 5D25 4636 A392 515C 5045 CF39 4253


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.8 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAkrwYlIACgkQUVxQRc85QlPb6gCfX72lIGKOIjqUXAX9h2DxaFBL
uvkAoIJV7aNQLmIG/dvcKahNTiblWL4z
=h0BZ
-----END PGP SIGNATURE-----




==================================================
Filtered by: TRUSTEM.COM's Email Filtering Service
http://www.trustem.com/
No Spam. No Viruses. Just Good Clean Email.



------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.

http://www.iacertification.org
------------------------------------------------------------------------

Re: Get a Clue! WAS: Re: Metasploit

by Eric Milam :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Although I agree with some of what Jon states below.  I think it was
rude not to include the link.  It did only take me about 5 seconds with
Google.  (Although I got the info in Sept through the Offsec Blog...and
you guys should sign up for the newsletter!)

In the immortal words of muts -> Try Harder!

http://www.offensive-security.com/metasploit-unleashed/

Best of luck!

Eric
OSCP!



Jon Kibler wrote:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> Jon Kibler wrote:
> <SNIP!>
>  
>> I am currently working through Offensive Security's Metasploit Unleashed online course.
>>    
> <SNIP!>
>
> I hate to reply to my own email, BUT...
>
> <rant>
> I received dozens of (mostly off-list) messages, "I cannot find the course, will
> you please send me a link"? Folks, get a clue! How can you call yourself a pen
> tester if you cannot find an online course hiding in plain site? How do you
> expect to be able to penetrate systems through obscure weaknesses when you miss
> the 6,500Kgm gorilla in the room?
>
> If you cannot find the course without a hint, perhaps you should be on the
> Security Basics list and not the Pen Test list!! This list more or less presumes
> *some* basic knowledge -- like how to use Google. (In case you don't know how to
> use Google, please read: Google Hacking for Penetration Testers by Johnnie Long.)
>
> BTW, clue: google on: Offensive Security Metasploit Unleashed
>
> </rant>
>
> Jon
>
> P.S. This rant does not mean that you should not contact me with questions
> regarding my posts. Those who know me, know that I am always more than willing
> to help, time permitting. However, please check to obvious first!
>
> P.S.S. For those of you that emailed me off-list asking where to find the
> course... no, I will not out you. For those that emailed the list with the
> question... well, what can I say?
>
> JK
> - --
> Jon R. Kibler
> Chief Technical Officer
> Advanced Systems Engineering Technology, Inc.
> Charleston, SC  USA
> o: 843-849-8214
> c: 843-813-2924
> s: 843-564-4224
> s: JonRKibler
> e: Jon.Kibler@...
> e: Jon.R.Kibler@...
> http://www.linkedin.com/in/jonrkibler
>
> My PGP Fingerprint is:
> BAA2 1F2C 5543 5D25 4636 A392 515C 5045 CF39 4253
>
>
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.8 (Darwin)
> Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
>
> iEYEARECAAYFAkrwYlIACgkQUVxQRc85QlPb6gCfX72lIGKOIjqUXAX9h2DxaFBL
> uvkAoIJV7aNQLmIG/dvcKahNTiblWL4z
> =h0BZ
> -----END PGP SIGNATURE-----
>
>
>
>
> ==================================================
> Filtered by: TRUSTEM.COM's Email Filtering Service
> http://www.trustem.com/
> No Spam. No Viruses. Just Good Clean Email.
>
>
>  
> ------------------------------------------------------------------------
>
> ------------------------------------------------------------------------
> This list is sponsored by: Information Assurance Certification Review Board
>
> Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.
>
> http://www.iacertification.org
> ------------------------------------------------------------------------



------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.

http://www.iacertification.org
------------------------------------------------------------------------


Re: Metasploit

by admin-179 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Jon Kibler wrote:

> How well do you know metasploit?
>
> I thought I knew it fairly well. Turns out, I do know half of what I thought I
> knew about metasploit. I am really surprised at how much metasploit can do that
> I did not know about.
>
> I am currently working through Offensive Security's Metasploit Unleashed online
> course. It is currently a "donate to HFC"-ware course. It is a great course, and
> I highly recommend it! I have learned a lot and I am only about half through the
> course. (I keep going back and redoing old exercises as I get new ideas from new
> material, so I am kind of slow... I should have been done by now!)
>
> Anyway, if you use metasploit -- and if you are a pen tester, you really should
> be using it!! -- I recommend you check out the course and see how your
> metasploit knowledge stacks up against the course.
>
> Jon

Thanks for the heads up. I have only scanned the first few chapters so far, I will make time for this.

Thanks again
Dave

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iD8DBQFK8gt9BStvyIzJtOARAlavAJwMJ85F5gm9S23iey0Y29t2qi5P7gCfVyp/
V8nNlAwnL8pZPgLj6DTBA5E=
=kj5w
-----END PGP SIGNATURE-----

------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.

http://www.iacertification.org
------------------------------------------------------------------------