Home > Software Quality News > Penetration testing tool released by Metasploit founder
Software Quality News:
EMAIL THIS

Penetration testing tool released by Metasploit founder

By Dennis Fisher, News Director
02 Aug 2006 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

H.D. Moore has been a busy man. The researcher behind the Metasploit Project Tuesday released a new tool for finding vulnerabilities in Internet Explorer ActiveX controls. Plus Wednesday, ahead of his talk at the Black Hat conference in Las Vegas, Moore released the first full beta of version 3.0 of the Metasploit Framework, his penetration testing software.

The new ActiveX tool, called AxMan, is a fuzzing engine designed to find flaws in COM objects in IE 6.0. AxMan is Web-based and works by listing all of the COM objects and the TypeLib data associated with them. The tool then uses that information to test each of the objects' properties and methods, Moore said in the release notes for AxMan.

The beta of Metasploit 3.0 has a slew of new features and modifications, including support for multiple shells for each exploit and new denial-of-service modules.

Moore has been in the spotlight for several weeks. Last month he declared July as the "Month of Browser Bugs" in which he posted details of a new browser flaw each day. Among the flaws he identified were a serious flaw in Internet Explorer involving an integer overflow error in the Common Controls library 'comctl32.dll', and multiple flaws in Firefox, which were addressed last week by the Mozilla Foundation.

Moore is scheduled to talk about the new version of the framework Wednesday at Black Hat.

News Editor Eric B. Parizo contributed to this article.

This article originally appeared on SearchSecurity.com.

Tags: Software security testing and techniquesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Software security testing and techniques
Free Web proxy security tools software testers should get to know
How to get management on board with Web 2.0 security issues
Web application security best practices: Tips on implementation
Testing strategies for complex environments
How to make your software tamperproof
Ways to approach application performance testing on a tight budget
How can I tell if my software security has been breached?
Is online application testing for smartphones different from other software testing?
Software testers facing six big challenges today, StarWest keynoter says
Lesser-known free software testing tools testers should try

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Software Development Methods - Extreme Programming, Agile Programming, Scrum
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2006 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts