In the event you haven't tried it out, here's a brief walk-through of some of the nice features and capabilities of Metasploit Express.


<-- If your vulnerability scanner has found a specific vulnerability you can search for it in Metasploit Express to confirm there's an exploit module as shown here.

<-- You can then manually launch the exploit on your target host.


<-- Once a vulnerability has been exploited and the payload delivered, you can gather evidence as shown here.
<-- Or, you just can just obtain a remote command prompt showing that you've compromised the host.

There are numerous other features within Metasploit Express that allow you to automate host discovery, the exploitation process and so on...just a bit much to cover in one blog post. Perhaps I'll cover that in detail in my next edition of Hacking For Dummies. :)
All in all, Metasploit Express is a security testing tool you shouldn't be without. It's a great way to "prove" those security vulnerabilities you discover are indeed a business problem.
0 comments:
Post a Comment