Metasploit, Back Track, and Core Impact Comparison

Metasploit is an open source platform for doing vulnerability investigation and development. It handles building shell code and delivery code. The user selects the payload and then selects the exploit to use.

How to use Metasploit
Discovery: The Metasploit GUI is a powerful tool that visually displays all the exploits currently available. In order to launch an exploit a user must find out what products are running on a target system. Once the target has been detected, the user can locate an exploit.

Attack: Once the target exploit has been found double clicking it will open an exploit window or right click and click ‘execute’. Once the exploit has started, the GUI for all of them will appear similar. You will select your target and launch the payload for the attack.
Report: Metasploit has a reporting engine with many standard reports like PDF, CSV, and HTML. Once the attack is complete, you can review the reports generated by the engine.
Limitations of Metasploit
·        Majority of exploits are for windows operating system.
·        Large amount of import data slows exploits.
·        To get the best out of Metasploit, you will require the services of a professional.

·        It does not produce a clear and informative report.

                                                                       Back Track

Back Track is a recognized specialized Linux distribution focusing on security tools for penetration testers and security experts. It supports for live CD and Live USB functionality.
It provides users with easy access to large collection of security tools, which includes:
Gerix Wifi Cracker

How to use Back Track
The tool is ran from inside or outside the environment, it involves the following steps:
Installation: We will install the Back track from a live CD On a clean computer. It is the same step as installing a new Linux operating system.
Discovery: Tools like Wireshark, NetworkMiner, and dsniff are you used to discover targets and vulnerability on a system.
Exploit: We will exploit this vulnerability with Medusa and all other exploitation tools on the back track.
Report: We will gather all the results of the exploits and create a report.

·        Majority of exploits are for windows operating system, it has few exploits for Mac OS.
·        To get the best out of Back track, you will require the services of a professional.
·        The Penetration testing is not automated. You will need a different tool for both discovery and exploitation phase.
It does not produce a clear and informative report.

                                                                              Core Impact

It is a commercial shell code and payload generator. Core impact allows the user to ensure compliance with industry and government regulations.

How to use Core Impact
Information gathering: This step collects data about the targeted network, using network discovery and port scanner. This step can also be accomplished by importing information from a network mapping tool or vulnerability scanner.
Attack: During an attack, it automatically selects and launches remote attacks leveraging IP, OS, and service information obtained in the information-gathering phase. The user can choose to launch every attack against each target host.
Report generation: It generates clear, informative reports that provide data about the targeted host, audits of all exploits performed, and details about proven vulnerabilities. The user can view and print reports using Crystal reports.

·        You cannot change the source code. It is not an open source tool, which makes the source code unavailable.
·        It is expensive. If you work for a small organization, you may not be able to afford it.
·        Importing external vulnerability data can be sluggish. If you have very large Nessus NBE files, it can take a long time to import these files.
·        It does not have a command line interface.

Core Impact
Back Track
Operating system
It runs on Linux and Windows OS.
It runs on Linux. It is not fully functional on windows OS. It can crash the operating system.
It makes use of its own operating system through a live CD or live USB stick.
Expensive, because it is not OpenSource.

 Free, because it is OpenSource
Free, because it is OpenSource
Type of Penetration testing
The penetration testing is automated.
You can perform discovery and exploitation with the same tool.
The penetration testing is automated. You can perform discovery and exploitation with the same tool.
The penetration testing is not automated.
You will need a different tool for both discovery and exploitation phase.
Location of penetration testing
You have to be on the same network with the targeted host.
You have to be on the same network with the targeted host.
External and Internal
You don’t have to be on the same network with the targeted host.
It does produce a clear and informative report. The report provides information about the host, which will include the details about the vulnerabilities.

It does not produce a clear and informative report.
It only shows the exploit information.
It does not produce a clear and informative report.
Each tool has its own report.
Ease of Usage
It is easy to use, because of the GUI interface.
It is not easy to use. To get the best out of Metasploit, you will require the services of a professional.
It is not easy to use. To get the best out of Back track, you will require the services of a professional.
The interface is web based.
GUI and Command line
Msfgui is the GUI interface.
Msfconsole is the command line interface.

GUI and command line
Each tool has its own interface.
Vulnerability database
It is large
You can import external vulnerability database.
It is small
You can import external vulnerability database
It is small
You cannot import external vulnerability database, because each tool has its own database


Popular posts from this blog

Andriod Cryptocurrency Clipboard Hijacking Crypto Malware Found On Google Play Store

High-Severity SHAREit App Flaws Open Files for the Taking

Hackers Deleted VFEmail Entire Data and Backups