TMCnet News
Metasploit Releases Version 3.3Nov 19, 2009 (Close-Up Media via COMTEX) -- The Metasploit Project announced the immediate availability of version 3.3 of the Metasploit Framework, an open source exploit development and penetration testing platform. Incorporating community contributions from 12 months of development effort, Metasploit 3.3 has updated its framework with a particular focus on expanding its exploit coverage, payload, stability, performance, third-party integration capabilities and platform support. "The Metasploit community has worked hard over the last 12 months to build a penetration testing platform with unique features and unmatched flexibility," said HD Moore, chief architect of Metasploit and chief security officer at Rapid7, which manages the Metasploit Project. "I'm confident that Metasploit users will immediately benefit from the new capabilities of the framework and I look forward to raising the bar even further in the coming months." The Metasploit Project stated that key enhancements include: - Expanded Exploit Coverage. This release features advances in exploit coverage across a wide range of targets, now including more than 440 exploits, 215 auxiliary modules and hundreds of payloads, including an in-memory VNC service and the Meterpreter. Covering over 400 CVEs, Metasploit continues to provide a large database of publicly available exploits. - Additional Platform Support. The latest version of the Metasploit Framework is supported on all modern operating systems, including 32-bit and 64-bit versions of Windows, Linux and Mac OS X. The framework also runs on a wide variety of devices, from the Apple iPhone to IBM mainframes. This release is the first version to support Ruby 1.9.1, Windows 7 and a native console interface on the Windows platform. AIX support as a target platform has been improved, with a number of additional payloads, which support versions 5.3.7 through 6.1.4 of the AIX platform. Oracle databases are now first-class targets to Metasploit with the addition of pre-authentication, post-authentication and SQL injection modules. - Payload. Metasploit 3.3 provides additional support for advanced payloads, including support for JSP payloads, IPv6, NX and DEP. In addition, Metasploit now supports advanced payload masking to aid penetration testers using social engineering techniques. The Meterpreter payload now supports screen shots, packet sniffing and key stroke logging. - Improved Performance and Manageability. Metasploit 3.3 loads faster than previous versions due to performance improvements made to the core libraries and module loader. Windows users will see an improvement in both the usability and responsiveness of the Metasploit console on that platform. Metasploit 3.3 also improves manageability, with simplified installation on Windows and Linux, an improved user interface and notification of last update times. Performance and stability have also been a focus of this release. - Enhanced Integration with The Open Source Vulnerability Database (OSVDB). This release features enhanced integration with the OSVDB, with all relevant exploits having associated OSVDB ID references and two-way links between the osvdb.org entry and the metasploit.com module browser. CVE references have been modified across the entire module tree. - Community-Driven. With a community-based development team, this release of the Metasploit Framework was driven by numerous key contributors, including James Lee, Yoann Guillot, Steve Tornio, MC, Chris Gates, Alexander Kornbrust, Ramon Carvalle, Stephen Fewer, Ryan Linn, Lurene Grenier, Mike Kershaw, Patrick Webster, Max Moser, Efrain Torres, Alexander Sotirov, Ty Bodell, Joshua Drake, JR, Carlos Perez, Kris Katterjohn and many others. The Metasploit Project is managed by Rapid7, a provider of unified vulnerability management, compliance and penetration testing solutions that deliver intelligence about an organization's entire IT environment. ((Comments on this story may be sent to [email protected])) |
