Penetration Testing mailing list archives

Re: Core Impact vs. Canvas vs. Metasploit


From: Paul Asadoorian <paul () pauldotcom com>
Date: Wed, 3 May 2006 10:11:53 -0400

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Having used all three of these software packages/frameworks, here are my general thoughts:

- - I like Metasploit and CANVAS because I can run them on my powerbook, which means I can now do entire pen tests from OS X, which is convenient and cost effective

- - Metasploit & CANVAS work awesome, but lack the report features of CORE IMPACT

- - IMPACT has a nice feature where you can send email to you potential victims with a URL that points back to the IMPACT server and exploits the client. This can be accomplished manually, however IMPACT logs and reports the entire process, which saves time in "Word Programming".

- - IMPACT is the best choice, in my opinion, if you are going to be auditing internally for a large organization (See the SANS What Works http://www.sans.org/info.php?id=1088 with Larry Pesce and Alan Paller).

If you are pen tester, it depends on your budget and how much time you have. I also think that Metasploit can be extended to provide many of the features that will make a pen testers life easier and am impressed with the enhacenments in version 3.0. I also use CANVAS quite extensively, which is a great selling point to those Fortune 1000 companies when you can tell them that you use a commercial tool to audit their network (I am a HUGE fan of open-source, however corporate types seem to like the fact that we use a commercial tool, and CANVAS won't break the bank).

Paul

PS. We discuss pen testing, frameworks, Google hacking, and automated information gathering in our podcast interview with Johnny Long, http://www.pauldotcom.com/2006/04/pauldotcom_security_weekly_spe_7.html

- --
Paul Asadoorian
Email:   paul () pauldotcom com
Web:     http://pauldotcom.com

Fingerprint: 2693 0204 8497 2E5F 4853  11D5 1153 6151 487F E094



On Apr 27, 2006, at 2:08 PM, virtuale () hushmail com wrote:

Hi,

For those who have been using one or more of the subj. products -

How do the products compare? What are the key technical adv/ disadvantages of each product?

The cost of the products is different. There must be something about the technical part that is significantly different. I'm trying to figure that out.

My personal experience - both canvas and core support advanced agent chaining, modules are python-based.

I'm not sure how level2-3 agents in core map to canvas's helium but level0 seem to be pretty similar in the way syscalls are proxied/ socket reuse (strikingly similar, i'd say :)

Encoders are similar in all three, e.g. xor, chunk, unicode/ widechar. Is the price the only differentiator?

V



---------------------------------------------------------------------- --------
This List Sponsored by: Cenzic

Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to win the Analyst's Choice Award from eWeek. As attacks through web applications continue to rise, you need to proactively protect your applications from hackers. Cenzic has the most comprehensive solutions to meet your application security penetration testing and vulnerability management needs. You have an option to go with a
managed service (Cenzic ClickToSecure) or an enterprise software
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service can
help you: http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit for you to confirm your results from other product. Contact us at request () cenzic com for details. ---------------------------------------------------------------------- --------


- --
Paul Asadoorian
Email:   paul () pauldotcom com
Web:     http://pauldotcom.com

Fingerprint: 2693 0204 8497 2E5F 4853  11D5 1153 6151 487F E094






-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (Darwin)

iD8DBQFEWLoqEVNhUUh/4JQRAlkwAJ0Y2mPUlEI9ifjqnH3pEldHN3ME9gCfT+aU
ftz2V/eCzdtFCcNhLnmSMGc=
=SDQC
-----END PGP SIGNATURE-----

------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security? Why not go with the #1 solution - Cenzic, the only one to win the Analyst's Choice Award from eWeek. As attacks through web applications continue to rise, you need to proactively protect your applications from hackers. Cenzic has the most comprehensive solutions to meet your application security penetration testing and vulnerability management needs. You have an option to go with a managed service (Cenzic ClickToSecure) or an enterprise software (Cenzic Hailstorm). Download FREE whitepaper on how a managed service can help you: http://www.cenzic.com/news_events/wpappsec.php And, now for a limited time we can do a FREE audit for you to confirm your results from other product. Contact us at request () cenzic com for details.
------------------------------------------------------------------------------


Current thread: