sunnuntai 27. maaliskuuta 2011

What is Metasploit tool for?

Metasploit is a framework, or tool, which contains lot of automated vulnerability scripts. A vulnerability is a known mechanism of an operating system - and one that is not desired. "Vuln"s began to be discussed somewhere around the same time as computers in the 1990s were connected to Internet. Before the Internet era (I mean the time when Internet really was an option for average Joe) it didn't matter so much whether you had vulnerabilities in the operating system, since no-one would be knocking on the door.

Metasploit is quite heavy. At least for one who is used to running individual security tools like netcat, nmap and so, the Metasploit seems gigantic. It reminds a little bit the IOS command language used in Cisco routers. You can ask questions, set values, set modes, and execute scripts. The framework can be used to test actual vulnerabilities in a connected network, or when you have a direct connection to another IP-based host via eg. a router, home switch, or similar. 

