DEFCON-18-Linn-Multiplayer-Metasploit.pdf

(2783 KB) Pobierz
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
Multiplayer Metasploit
Tag-Team Pen Testing and Reporting
Ryan Linn
Defcon 18
Sunday, July 4, 2010
858575656.013.png 858575656.014.png 858575656.015.png 858575656.016.png
Outline
• Description of Problem
• Discussion of current solutions
• Overview of XMLRPC database
integration
• Discussion of types of objects
• Demos
Sunday, July 4, 2010
858575656.001.png 858575656.002.png 858575656.003.png
What’s the problem?
• Pen testing/security audit teams need
to share information
• How do you plan further action?
• What about deltas from previous tests?
• No easy way to automate reporting
Sunday, July 4, 2010
858575656.004.png 858575656.005.png 858575656.006.png
Analysis of current solutions
• Dradis - best alternative, imports data
great, but hard to further actions, no
integration with other tools
• Leo - geared toward one person and
logging/reporting only
• Wiki - multi-user but arbitrary
organization, hard to convert to further
action or reporting
Sunday, July 4, 2010
858575656.007.png 858575656.008.png 858575656.009.png
overview of solution
• Metasploit is readily available
• Extend XMLRPC to facilitate DB
transactions
• XMLRPC extension allows central
logging
• All information is actionable
• Data can be added real time
Sunday, July 4, 2010
858575656.010.png 858575656.011.png 858575656.012.png
Zgłoś jeśli naruszono regulamin