Recent Posts
- ITWeb Security Summit
- Security Forum 2012
- PrintJob MITM – Testers Wanted
- Getting your message across: Screenshots
- Scammers gonna scam
- EU legislation – Digging below the FUD line (cont.)
- EU legislation – Digging below the FUD line
- Commandline Kung-fu – Solution
- {Quick Post} Commandline Kung-fu needed! Apply within
- Unsung Heros (the list)
Archives
@ChrisJohnRiley
- Well I know which sauce @joshcorman and I will NOT be having #PoorMonkey twitpic.com/9n92pr 3 days ago
- [SuggestedReading] A closer look into the RSA SecureID software token goo.gl/fb/04gik 5 days ago
- Headed on safari… if I'm not back in a few days, send food! #iTWebsec 5 days ago
- [SuggestedReading] Web Application Penetration testing with Google Chrome Browser goo.gl/fb/XFqIK 6 days ago
- [SuggestedReading] Weekly Metasploit Update: CCTV, SCADA, and More! goo.gl/fb/QBapj 6 days ago
- RT @joshcorman: Not sitting w/ @ChrisJohnRiley anymore. Our table was referred to as the "slacker table in the back" for this workshop 6 days ago
Flickr Photos
|
Links
Disclaimer
The contents of this personal blog are solely my own opinions and comments, as such they do not reflect the opinions of my employer(s) past, present or future. No legal liability is accepted for anything you do, think, or consider fact as the basis of articles and links posted on this blog.
"Three to one...two...one...probability factor of one to one...we have normality, I repeat we have normality. Anything you still can’t cope with is therefore your own problem."
Note: A large portion of content I post on my blog comes from "live blogging" of security conferences. These posts are in notes form and are written live during a talk. As such errors and emissions are expected. I'm only human after all!




You know this already but metasploit is supposed help speed up exploit development not just be a ./sploit replacement.
Sure… Metasploit is a great resource when it comes to exploit writing. I was referring (probably badly) to the typical “point and click” security professionals who want to understand the how and why of the underlying exploit code, instead of just relying on HD and co. to write the exploits for them.
From my viewpoint you need to understand how the vulnerable program works, and how it can be exploited, before you can use the parts of Metasploit that make exploit creation easier. After all Metasploit isn’t going to look at the executable and just spit out a suitable exploit for it. Maybe that’s planned for Metasploit 3.3 though
Nothing surprises me anymore.