Showing posts with label Tools. Show all posts
Showing posts with label Tools. Show all posts

DEFCON 16: List of tools and stuff released

Defcon 16 tools and utilities

DEFCON, the 9000+ attendee hacker conference in Vegas has become a sort of hydra conference. It has become more like a global fair than what most people think of conferences; even the badge is highly unique.

I say this because there are so many things to do at DEFCON, other than going to talks, that you could spend your whole weekend looking at the “World’s Largest Boar!”, so to speak. One of the CTF (Capture the Flag) contest winners this year actually exclaimed that he only made it to 2 talks in 12 years! I am also one of those individuals who barely get a chance to go to talks and now that the speaker pool is so diverse, it’s hard to find all of the “stuff” they release.

Before anyone has a chance to post “it’s all on the DEFCON CD dummy,” I want to challenge them to try. After a weekend of googling (which came back with few results) and making contact with some of the speakers, I provide you with a mostly accurate list of “stuff” that was released at DEFCON this year. If any of the information is inaccurate, or a tool is missing, please contact me and I will update this post.

Beholder – by Nelson Murilo and Luis Eduardo

  • Description: An open source wireless IDS program
  • Homepage Link: http://www.beholderwireless.org/
  • Email Address: bh@beholderwireless.org
  • The Middler – by Jay Beale

  • Description: The end-all be-all of MITM tools
  • Homepage Link: http://www.themiddler.com/ (Online?)
  • Preface Link: http://www.intelguardians.com/themiddler.html
  • ClientIPS – by Jay Beale

  • Description: An open source inline “transparent” client-side IPS
  • Homepage Link: http://www.ClientIPS.org/ (Online?)
  • Marathon Tool – by Daniel Kachakill

  • Description: A Blind SQL Injection tool based on heavy queries
  • Download Link: DEFCON 16 CD. No online link found.
  • Email Address: dani@kachakil.com
  • The Phantom Protocol – by Magnus Brading

  • Description: A Tor-like protocol that fixes some of Tor’s major attack vectors
  • Homepage Link: http://code.google.com/p/phantom
  • Email Address: brading@fortego.se
  • ModScan – by Mark Bristow

  • Description: A SCADA Modbus Network Scanner
  • Homepage Link: http://modscan.googlecode.com/
  • Email Address: mark.bristow@gmail.com
  • Grendel Scan – by David Byrne

  • Description: Web Application scanner that searches for logic and design flaws as well as the standard flaw seen in the wild today (SQL Injection, XSS, CSRF)
  • Homepage Link: http://grendel-scan.com/
  • iKat – interactive Kiosk Attack Tool (This site has an image as a banner that is definitely not safe for work! – You have been warned) by Paul Craig

  • Description: A web site that is dedicated to helping you break out of Kiosk jails
  • Homepage Link: http://ikat.ha.cked.net
  • Email Address: paul.craig@security-assessment.com
  • DAVIX – by Jan P. Monsch and Raffael Marty

  • Description: A SLAX based Linux Distro that is geared toward data/log visualization
  • Homepage Link: http://code.google.com/p/davix/
  • Download Link: http://www.geekceo.com/davix/davix-0.5.0.iso.gz
  • Email Addresses: jan.monsch@iplosion.com and raffy@secviz.org
  • CollabREate – by Chris Eagle and Tim Vidas

  • Description: An IDA Pro plugin with a server backend that allows multiple people to collaborate on a single RE (reverse engineering) project.
  • Homepage Link: http://www.idabook.com/defcon
  • Email Addresses: cseagle@gmail.com and tvidas@gmail.com
  • Dradis – by John Fitzpatrick

  • Description: A tool for organizing and sharing information during a penetration test
  • Homepage: http://dradis.sourceforge.net
  • Email Address: john.fitzpatrick@mwrinfosecurity.com
  • Squirtle – by Kurt Grutzmacher

  • Description: A Rouge Server with Controlling Desires that steals NTLM hashes.
  • Homepage: http://code.google.com/p/squirtle (Live?)
  • Email Address: grutz@jingojango.net
  • WhiteSpace – by Kolisar

  • Description: A script that can hide other scripts such as CSRF and iframes in spaces and tabs
  • Download Link: DEFCON 16 CD
  • VoIPer – by nnp

  • Description: VoIP automated fuzzing tool with support for a large number of VoIP applications and protocols
  • Homepage Link: http://voiper.sourceforge.net/
  • Barrier – by Errata Security

  • Description: A browser plugin that pen-tests every site that you visit.
  • Homepage Link: http://www.erratasec.com
  • Email Address: sales@erratasec.com
  • Psyche – by Ponte Technologies

  • Description: An advanced network flow visualization tool that is not soley based on time.
  • Homepage Link: http://psyche.pontetec.com/
  • * Rob Fuller is a security researcher and pen-tester. He can be found on Twitter and in Room 362.

    [Source: zdnet]

    Hex liveCD

    HeX is a project aimed at the NSM (Network Security Monitoring) community for use by network security analysts. The developers believe that simplicity and analysis work flow logic must be enhanced and emphasized through-out the process of designing this liveCD. Not only have they carefully chosen all the necessary applications and tools to be included to the liveCD, they have also tested them to make sure everything running as smooth as possible. In order to summarize the objective of HeX, they are trying to develop the first and foremost Network Security Monitoring & Network Based Forensics liveCD!

    HeX Main Features

    HeX Main Menu - Cleaner look and more user interface oriented and maximum 4 levels depth HeX Main Menu allows quick access to all the installed applications in HeX.

    Terminal - This is exactly what you need, the ultimate analyzt console!

    Instant access to all the Network Security Monitoring(NSM) and Network Based Forensics(NBF) Toolkits via Fluxbox Menu. We have also categorized them nicely so that you know what to use conditionally or based on scenario.

    Instant access to the Network Visualization Toolkit, you can watch the network traffics in graphical presentation and that assist you in identifying large scale network attacks easily.

    Instant access to Pcap Editing Tools which you can use to modify or anonymize the pcap data, it’s great especially when you want to share your pcap data.

    Network and Pentest Toolkits contain a lot of tools to perform network or application based attacks, you can generate malicious packets using them and study malicious packets using those analysis tools listed in NSM-Toolkit and NBF-Toolkit as well.

    While we think HeliX liveCD is better choice in digital forensics arsenal, Forensics-Toolkit can be considered as the add-on for people who are interested in doing digital forensics.

    Under Applications, there are Desktop, Sysutils and Misc, all of them are pretty self-explained and contain user based applications such as Firefox, Liferea, Xpdf and so forth. Additionally, Misc contains some useful scripts, for example you can just start ssh service by clicking on SSHD-Start.

    You can download HeX 1.0.3 here:

    hex-i386-1.0.3.iso

    [Source:Rawpacket]

    IDA Disassembler on the iPhone? Yep.

    Ilfak Guilfanov has reported that IDA has been ported to the iPhone. Unbelievable? Yes. Is it useful? Who cares! IDA on the iPhone is hot!

    Don’t act like you don’t want IDA for your iPhone, you know you do.

    From the “Hex Blog”:

    Good news for real iPhone fans: we ported IDA to iPhone! It can handle any application and provides the same analysis as on other platforms. It is funny to see IDA on a such small device:

    Ilfak says only the heartiest of researchers and iPhone fans will use it as the interface is clumsy and done through terminal emulation. Here’s a shot from Ilfak’s blog on the tool actually running on the phone:

    All I can ask is that this soon be sent to the Apple App Store or linked to in some other way, it will be the first thing I put on my new iPhone.

    To Ilfak, well done, you’ve made my Friday!

    [All images courtesy of Ilfak’s blog]

    [Source: zdnet]

    More Worm and Virus Source Code

    From Wormblog reader Adli Abdul W., more virus and worm source code. The Neworder site contains links to the virus source code for Melissa, ILOVEYOU, and other mass mailers and traditional viruses. Note that these are for educational purposes only, are detected by any decent AV engine, and use only on a testbed network you have the authority to use.

    So, what can you do with these sorts of things? You can set up a research lab that tests, for example, your detection algorithms and implementations. If you're developing a plugin to a mail client or even a mail server, this can be an invaluable aid in your testbed. If you're testing a new AV signature engine, this is also useful. While the worms themselves aren't all that complex, the techniques they used are still around.

    [Source:wormblog]

    Anti-Malware Tools: Intrusion Detection Systems

    Martin Overton, from IBM in the UK, is back with another interesting malware paper. He's got an outline of how to use Snort to detect malware in transit on the wire.

    When most people think of tools to combat malware, very few will give a passing thought to Intrusion Detection Systems, why?

    Common reasons include:

    • They don’t realise that IDS systems can be used against malware (viruses, Trojans, worms, etc.)
    • They are too difficult to setup, maintain and use.
    • That they are too prone to false alarms.
    This paper will investigate the use of IDS systems, specifically to counter/block/detect malware. What’s more, this paper will focus on SNORT (which is a free IDS system available for both UNIX and Windows).

    This paper will include instructions and guidance on the setup of such a system, numerous examples of suitable rules to detect and block malware and useful tools that can make the sifting of logs easier and more palatable as well as configuration and other tools and utilities that may be useful in managing and maintaining SNORT.

    The use of an IDS system can be extremely useful in cases of fast burning or very complex malware outbreaks as a stop-gap until the anti-virus vendors manage to get reliable updates out to their customers.

    An IDS is also useful in identifying infected systems in your organization that need remedial action before the ‘trickle’ of infections become a ‘torrent’ and you are left fighting to keep your head above the rising waters.

    This paper is based on the recent two-part article written for Virus Bulletin [October and November 2004] and parts of that article have been used with their permission.

    Anti-Malware Tools: Intrusion Detection Systems

    [Source:wormblog]

    DDoSVax Worm Traffic Analysis

    The Swiss research group hosted under the banner of 'DDoSVAX' has been known for many years for doing good work. They have used some of their measurement infrastructure to analyze worm traffic, as well. Several worms are studied and presented on their website:

    More Zotob Removal Tools

    I posted a list of two Zotob removal tools the other day, but it seems that more are out. If you're building a USB keychain for malware removal and Zotob cleanup, these should be on it. They don't replace a full blown AV scanner, but they can help you in a crisis time. Many thanks to Donna's blog for the list.

    [Source:wormblog]

    Worm Mitigation Technical Details

    If you've been wondering how some very large networks have been able to use their network layer to defeat worm outbreaks, you should look over this Cisco technical document. It shows you how to track and defeat worms using NetFlow analysis tools.

    Internet worms have had a severe impact on many enterprise customers. Recently developed tools and architectural techniques can be employed to assist with the mitigation of worm activity in an enterprise environment.

    This paper provides:

    • A conceptual overview of worm mitigation techniques
    • Details for deployment of these techniques into an overall solution for enterprise customers
    This document has been written from a solution standpoint. It is primarily designed to provide a tool kit for dealing with the issue of Internet worms within an enterprise environment. Although this is the primary motivation of this document, the overall solution has application well beyond this primary purpose and additionally provides capability for detecting and responding to other security incidents.
    Source: Worm Mitigation Technical Details,

    [Source:wormblog]

    Nepenthes: Malware Collection Tool

    Very similar to MWCollect, there's another way to collect automatically spreading malware using Nepenthes. Described on the project's website, "Nepenthes is a versatile tool to collect malware. It acts passively by emulating known vulnerabilities and downloading malware trying to exploit these vulnerabilities." If you're looking to capture bots, worms, and other malware, this looks like a very useful tool.

    MWCollect and Nepenthes are very similar to eachother n how they work, and if you can't spare the space or the hassel of steting up and maintaining a real Windows box as a honeypot, this may help you achieve your collection goals.

    [Source:wormblog]

    VX reversing II, sasser B

    The Sasser worm from May of 2004 provides an excellent example of modern malware in a reverse engineering setting. Eduardo Labir's article for the CodeBreakers Journal is a nice tutorial on how to really get into code, analyze it, and understand what is going on.

    Tools you'll want to have handy: VMware, so that you don't trash your main machine (another throwaway machine may also be used, but a virtual system is most often a handy way to keep the number of physical machines down); OllyDbg, a (free) 32-bit debugger with plenty of nice features; and IDApro, one of the best disassembler tools I can find (it's commercial, and sometimes the HT editor can do in a pinch).

    The well known worm Sasser has been one of the viruses which has received more attention in the press in the latest months. It's author, an 18 years old student from Germany, after causing lots of troubles to many home users and small enterprises faces up to several years of prison. Sasser is not a well programmed virus, it's success is entirely due to the exploit it implements, which was announced by Microsoft in one of their security bulletins. In this paper, we will reverse Sasser.B - the second of its variants - showing how it works and also how to clean your computer after infection.

    Source: VX reversing II, sasser B, Eduardo Labir, in the CodeBreakers Journal. Eduardo also has a nice piece entitled VX reversing I, The Basics where you may want to begin if this is new to you.

    [Source:wormblog]

    Updated Microsoft Malicious Software Removal Tool (March, 2006)

    Microsoft has updated their malware removal tool. This is a tool that runs at Windows Update time and can also be downloaded and run on-demand. It is not a continual defense, unlike most AV products. Updates for March, 2006, include:

    Source: Malicious Software Removal Tool,

    [Source:wormblog]

    A FastWorm Scan Detection Tool for VPN Congestion Avoidance

    Speaking of DIMVA, here's a set of slides from last year's conference that describe a scanning worm detection system. While none of the foundations are new (detect scanning by looking for failed connection requests and unanswered packets), this is a real- world demonstration of it's efficacy. Not surprisingly, P2P apps tend to give false positives. From a slide deck, A FastWorm Scan Detection Tool for VPN Congestion Avoidance, by Arno Wagner,Thomas Dubendorfer, Roman Hiestand, Christoph Goldi, and Bernhard Plattner, from DIMVA 2006.

    [Source:wormblog]

    Enabling Internet Worms And Malware Investigation And Defense Using Virtualization

    While lengthy, it's good reading if you're wondering about large-scale studies of real malware in a controlled laboratory network setting.

    Internet worms and malware remain a threat to the Internet, as demonstrated by a number of large-scale Internet worm outbreaks, such as the MSBlast worm in 2003 and the Sasser worm in 2004. Moreover, every new wave of outbreak reveals the rapid evolution of Internet worms and malware in terms of infection speed, virulence, and sophistication. Unfortunately, our capability to investigate and defend against Internet worms and malware has not seen the same pace of advancement.

    In this dissertation, we present an integrated, virtualization-based framework for malware capture, investigation and defense. This integrated framework consists of a frontend and a back-end. The front-end is a virtualization-based honeyfarm architecture, called Collapsar, to attract and capture real-world malware instances from the Internet. Collapsar is the first honeyfarm that virtualizes full systems and enables centralized management of honeypots while preserving their distributed presence. The back-end is a virtual malware "playground," called vGround, to perform destruction-oriented experiments with captured malware or worms, which were previously expensive, inefficient, or even impossible to conduct.

    On top of the integrated framework, we have developed a number of defense mechanisms from various perspectives. More specifically, based on the unique infection behavior of each worm we run in vGround, we define a behavioral footprinting model for worm profiling and identification, which complements the state-of-the-art content-based signature approach. We also develop a provenance-aware logging mechanism, called process coloring, that achieves higher efficiency and accuracy than existing systems in revealing malware break-ins and contaminations.

    Source: Enabling Internet Worms And Malware Investigation And Defense Using Virtualization

    [Source:wormblog]

    SIS Analysis Toolkit

    A departure from the normal, boring academic stuff, and actually on to something I've never featured here before (I think): mobile phone malware. The SIS Analysis Toolkit, according to the website, "consists of a base Perl module, SisDump, and a number of perl scripts and utilities useful for analyzing malware." I have to admit I've never looked at mobile phone malware. Surprisingly, it seems to be a growth niche in the past couple of years, from the early days of things like Caribe to more recent SIS malware likeMabir and more, mobile phone malware has been evolving. Most of it seems to target the Symbian60 platform, which is popular with Nokia phones and is a rich mobile computing environment.

    I haven't played with these tools (I don't own a Symbian60 phone), but if you're curious about exploring your phone or any of the malware that may be on it, this looks like the right place to start.

    [Source:wormblog]

    Hacking the Malware– A reverse-engineer’s analysis

    A nice, thorough analysis of a Yahoo! instant messaging worm by Rahul Mohandas, showing how he decoded the exploit, reverse engineered it, and it's effects. Very good example, and something you can learn from.

    This paper attempts to document an approach on how the hackers make use of the vulnerabilities to install malicious software on the vulnerable machine. A comprehensive reverse code engineered analysis of the malicious software (Win32.Qucan.a) and the various protection schemes against the worm by various security products are also discussed.

    I also describe an approach to setting up a flexible laboratory environment using virtual workstation software such as VMware, and demonstrate the process of reverse engineering a worm using a range of system monitoring tools in conjunction with a disassembler.

    I hope this document will help the Malware researchers, Intrusion Analysts and other Security professionals to conduct a more viable and comprehensive research.

    Source: Hacking the Malware– A reverse-engineer’s analysis

    [Source:wormblog]

    Google ships open-source Web security assessment tool

    Google ships open-source Web security assessment toolThe Google security team has released a free, open-source Web app security assessment tool capable of flagging vulnerabilities and potential security threats in Internet-facing applications.

    The tool, called Ratproxy, is described as a passive Web application security audit tool designed to analyze legitimate, browser-driven interactions with tested Web applications — to automatically pinpoint, annotate, and prioritize potential flaws or areas of concern on the fly.

    Ratproxy was created by Michal Zalewsky (left), the browser hacking guru who joined the search engine giant last July.

    According to Zalewski, Ratproxy is meant to complement active crawlers and manual proxies currently used to test complex Web 2.0 applications.

    The proxy analyzes problems such as cross-site script inclusion threats, insufficient cross-site request forgery defenses, caching issues, potentially unsafe cross-domain code inclusion schemes and information leakage scenarios, and much more.

    …It features a sophisticated content-sniffing functionality capable of distinguishing between stylesheets and Javascript code snippets, supports SSL man-in-the-middle, on the fly Flash ActionScript decompilation, and even offers an option to confirm high-likelihood flaw candidates with very lightweight, a built-in active testing module.

    Last but not least, if you are undecided, the proxy may be easily chained with third-party security testing proxies of your choice.

    [ SEE: Google’s anti-malware team comes out of the shadows ]

    Currently in beta, Ratproxy (see source code and screenshot) is available on Linux, *BSD, MacOS X, and Windows (Cygwin).

    This isn’t the first open-source security tool to come out of Google’s security team. Last year, the company released a fuzz testing tool that was used internally to find multiple vulnerabilities in Internet-critical software products.

    The fuzzer, called Flayer, is an analysis and flow alteration tool that has been used to find errors in real software. In the past year, results from Flayer has led to the discovery of security holes in several open-source products, including OpenSSH, OpenSSL, LibTIFF and libPNG.

    [Source: zdnet]

    Download Three Free Tools to Eradicate SQL Injection Attacks

    An escalation in SQL injection attacks aimed at websites based on ASP and ASP.NET technologies has prompted Microsoft to take action. Immediately after the explosion of SQL injection exploits the Redmond company highlighted resources available for administrators to bulletproof websites, but initially offered only a set of guidelines and pointed to the collection of best practices documentation already available. In addition, Microsoft has
    coordinated the release of three free security tools designed to eradicate SQL Injection attacks.

    Security
     Article: Download Three Free Tools to Eradicate SQL Injection Attacks
    Comments: Security
    Credits: Microsoft

    "Today, Microsoft is releasing two new SQL injection defense and detection tools, URLScan 3.0 and Microsoft Source Code Analyzer for SQL Injection (MSCASI). We are also excited to announce the release of HP Scrawlr, a SQL injection detection tool developed by HP Web Security Research Group in conjunction with Microsoft. Each of these tools works differently and each attacks the SQL injection problem from a different angle, and in combination they complement each other well," revealed Bryan Sullivan, Security Product Manager SDL team.

    What it is important to note is that none of the vulnerabilities involved in the spate of SQL injection attacks are server-side. Microsoft has made it clear that there are no security holes to plug in the web server code, and that instead, weaknesses in the applications dealing with end user input are being exploited. In the context in which the applications fail to adhere to the best practices guidelines outlined by Microsoft, input containing malicious code and syntax can be introduced into queries to the database, that could potentially compromise not only the database or a specifically targeted website but even the entire underlining web server.

    "UrlScan version 3.0 Beta, a security tool that restricts the types of HTTP requests that Internet Information Services (IIS) will process. By blocking specific HTTP requests, the UrlScan helps prevent potentially harmful requests. Microsoft Source Code Analyzer for SQL Injection Community Technology Preview (June 2008), a tool that can be used to detect ASP code susceptible to SQL injection attacks. Scrawlr, a free scanner, developed by HP Web Security Research Group in conjunction with Microsoft, which will allow customers to identify whether their Web sites might be susceptible to SQL injection," explained Andrew Cushman, Director, Microsoft Security Response Center (MSRC).

    UrlScan version 3.0 Beta is available for download here.
    Microsoft Source Code Analyzer for SQL Injection Community Technology Preview (June 2008) is available for download here.
    Scrawlr is available for download here.

    [Source: softpedia]

    BackTrack 3 Final has been released!

    Muts, Martin and Max have slaved for weeks and months, together with the help of many remote-exploit'ers to bring you this fine release. As usual, this version overshadows the previous ones with extra cool things.

    SAINT
    SAINT has provided BackTrack users with a functional version of SAINT, pending a free request for an IP range license through the SAINT website, valid for 1 year.

    Maltego
    The guys over at Paterva have created a special version of Maltego v2.0 with a community license especially for BackTrack users. We would like to thank Paterva for co-operating with us and allowing us to feature this amazing tool in BackTrack.

    Nessus
    Tenable would not allow for redistribution of Nessus on BackTrack 3.

    Kernel
    2.6.21.5. Yes, yes, stop whining....We had serious deliberations concerning the BT3 kernel. We decided not to upgrade to a newer kernel as wireless injection patches were not fully tested and verified. We did not want to jeopardize the awesome wireless capabilities of BT3 for the sake of sexiness or slightly increased hardware compatibilities. All relevant security patches have been applied.

    Tools
    As usual, updated, sharpened, SVN'ed and armed to the teeth. This release we have some special features such as spoonwep, fastrack and other cool additions.

    Availability
    For the first time we distribute three different version of Backtrack 3
         - CD version
         - USB version
         - VMWare version

    BackTrack 3 final download page is here:
    http://remote-exploit.org/backtrack_download.html


    Final Requests
    We request the community to not mirror or torrent this release, or otherwise distribute it online without our knowledge. We are trying to gather statistics about bt3 downloads. If you would like to mirror BT3 then please:

    1) Think again! Traffic generated by BT3 downloads is CRAZY.
    2) Please contact us before doing so.
    3) Send us monthly statistics of downloads for the iso.

    If you would like to add a link to BackTrack downloads to your website, please use:

    http://www.remote-exploit.org/backtrack_download.html as the download link.


    Rants
    Problems, fixes, bugs, opinions - should all end up in our Remote Exploit community forums, and our wiki:

    http://forums.remote-exploit.org
    http://wiki.remote-exploit.org


    [Source :Astalavista]

    MSF eXploit Builder

    The Metasploit killer coding ninjas' katana

    MSF eXploit Builder
    MMSF-eXploit Builder is a Windows GUI to build Metasploit Framework exploit modules. It will help you to edit/modify/create/test exploit modules for the Metasploit Framework

    MSF-XB ToorCon9 version available: Download (73Mb)

    Presentation (TOORCON9)


    Sample video (SWF) (VNSECON07 Special Edition)

    Screenshot

    Presentation (VNSECON07)

    Article about MSF-XB in the international IT Security magazine Hakin9 (French version):
    http://hakin9.org/fr/haking/issues/7a_2007.html

    Version history:
    20071105
    * TOORCON9 version released: Just test it! :-)
    20070815
    * Patch #2
    Fix a bug where the "Save exploit's code" button was not properly saving the source code of the exploit.
    Download it in the MSF-XB installation directory and restart MSF-XB.
    20070814
    * Patch #1 for the
    "C:\Program Files\Metasploit\Framework3\bin\ruby: No such file or directory -- C:/Program Files/Metasploit/Framework3/home/framework/tools/pattern_create.rb (LoadError)" error.
    NOTE: the Metasploit Framework could return one extra unwanted character while using the CreatePattern() method.
    To fix it, just edit the \lib\rex\text.rb file and change:
    - buf[0..length]
    + buf[0,length]
    20070813
    * VNSECON07 Special Edition released: tons of new features and enhancements ;-)
    20070502
    * Support for the Metasploit framework final v3.x version added
    * A lot of bugs fixed (and probably added ;-)
    * Better support of non-english Windows
    * A lot of new features added: the assistant is now usable!
    * New design: Vista's style (experimental)
    * Database of useful links (tutorials) added
    * Macro-codes support added (experimental)
    * Syntaxical coloration removed (too slow actually)

    TODO list
    A lot! :-) ...
    LiveUpdate feature
    Rewrite it in Ruby? (msfgui style)

    https://www.securinfos.info/metasploit/MSF-XB002.JPG

    What you can do with it:

    Edit a MSF exploit module Both 2.x and 3.x modules should be supported

    Create a new exploit module MSF-XB comes with an assistant :
    It uses a local opcodes/return addresses database and let you use the power-handy-full tools of the MSF (memdump/PatternCreate/patternOffset...) and more!
    It is also able to generate PoC code in Python and Perl (more coming)
    All of this in just few clicks.

    Print an exploit code You can print a module or export it as a .DOC, .PDF, ... file

    Test an exploit The exploit will be started in the same way as with MSFcli.exe
    ==> i recommend to use msfweb or msfgui instead for now

    Source: Washington Post

    The FirePack Exploitation Kit Localized to Chinese

    Tuesday, May 13, 2008The
    process of localizing open source malware, as well as publicly
    obtainable web malware explotation kits is continuing to receive the
    attention of malicious attackers, the Chinese underground in
    particular. Starting from MPack and IcePack's original localizations to Chinese, the FirePack exploitation kit is the latest one to have been recently localized to Chinese, and the trend is only starting to emerge.

    What
    is prompting Chinese users to translate these kits to their native
    language anyway? Is it the kit's popularity, success rates, lack of
    alternatives, or capability matching with the rest of the
    internaltional underground community? I'd go for the last point.

    [Source: Dancho Danchev's Blog]