Re: Core Impact vs. Canvas vs. Metasploit

From: Paul Asadoorian (paul@pauldotcom.com)
Date: Wed May 03 2006 - 10:11:53 EDT


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Having used all three of these software packages/frameworks, here are
my general thoughts:

- - I like Metasploit and CANVAS because I can run them on my
powerbook, which means I can now do entire pen tests from OS X, which
is convenient and cost effective

- - Metasploit & CANVAS work awesome, but lack the report features of
CORE IMPACT

- - IMPACT has a nice feature where you can send email to you potential
victims with a URL that points back to the IMPACT server and exploits
the client. This can be accomplished manually, however IMPACT logs
and reports the entire process, which saves time in "Word Programming".

- - IMPACT is the best choice, in my opinion, if you are going to be
auditing internally for a large organization (See the SANS What Works
http://www.sans.org/info.php?id=1088 with Larry Pesce and Alan Paller).

If you are pen tester, it depends on your budget and how much time
you have. I also think that Metasploit can be extended to provide
many of the features that will make a pen testers life easier and am
impressed with the enhacenments in version 3.0. I also use CANVAS
quite extensively, which is a great selling point to those Fortune
1000 companies when you can tell them that you use a commercial tool
to audit their network (I am a HUGE fan of open-source, however
corporate types seem to like the fact that we use a commercial tool,
and CANVAS won't break the bank).

Paul

PS. We discuss pen testing, frameworks, Google hacking, and automated
information gathering in our podcast interview with Johnny Long,
http://www.pauldotcom.com/2006/04/pauldotcom_security_weekly_spe_7.html

- --
Paul Asadoorian
Email: paul@pauldotcom.com
Web: http://pauldotcom.com

Fingerprint: 2693 0204 8497 2E5F 4853 11D5 1153 6151 487F E094

On Apr 27, 2006, at 2:08 PM, virtuale@hushmail.com wrote:

> Hi,
>
> For those who have been using one or more of the subj. products -
>
> How do the products compare? What are the key technical adv/
> disadvantages of each product?
>
> The cost of the products is different. There must be something
> about the technical part that is significantly different. I'm
> trying to figure that out.
>
> My personal experience - both canvas and core support advanced
> agent chaining, modules are python-based.
>
> I'm not sure how level2-3 agents in core map to canvas's helium but
> level0 seem to be pretty similar in the way syscalls are proxied/
> socket reuse (strikingly similar, i'd say :)
>
> Encoders are similar in all three, e.g. xor, chunk, unicode/
> widechar. Is the price the only differentiator?
>
> V
>
>
>
> ----------------------------------------------------------------------
> --------
> This List Sponsored by: Cenzic
>
> Concerned about Web Application Security?
> Why not go with the #1 solution - Cenzic, the only one to win the
> Analyst's
> Choice Award from eWeek. As attacks through web applications
> continue to rise,
> you need to proactively protect your applications from hackers.
> Cenzic has the
> most comprehensive solutions to meet your application security
> penetration
> testing and vulnerability management needs. You have an option to
> go with a
> managed service (Cenzic ClickToSecure) or an enterprise software
> (Cenzic Hailstorm). Download FREE whitepaper on how a managed
> service can
> help you: http://www.cenzic.com/news_events/wpappsec.php
> And, now for a limited time we can do a FREE audit for you to
> confirm your
> results from other product. Contact us at request@cenzic.com for
> details.
> ----------------------------------------------------------------------
> --------
>

- --
Paul Asadoorian
Email: paul@pauldotcom.com
Web: http://pauldotcom.com

Fingerprint: 2693 0204 8497 2E5F 4853 11D5 1153 6151 487F E094

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (Darwin)

iD8DBQFEWLoqEVNhUUh/4JQRAlkwAJ0Y2mPUlEI9ifjqnH3pEldHN3ME9gCfT+aU
ftz2V/eCzdtFCcNhLnmSMGc=
=SDQC
-----END PGP SIGNATURE-----

------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to win the Analyst's
Choice Award from eWeek. As attacks through web applications continue to rise,
you need to proactively protect your applications from hackers. Cenzic has the
most comprehensive solutions to meet your application security penetration
testing and vulnerability management needs. You have an option to go with a
managed service (Cenzic ClickToSecure) or an enterprise software
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service can
help you: http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit for you to confirm your
results from other product. Contact us at request@cenzic.com for details.
------------------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:55:54 EDT