SlideShare a Scribd company logo
Cyber Security (2150002)
Active Learning Assignment
on
Metasploit
Prepared By:
Patel RajalKumar H.
(160123109013)
Guided By :
Prof. Abhishek Harit
Electrical Department
Batch-B3
Gandhinagar Institute Of technology 1
Introduction
• The Metasploit is a computer security that provides information
about security vulnerabilities and aids in penetration testing and
IDS signature development.
• Its best-known sub-project is the open source Metasploit
Framework, a tool for developing and executing exploit code
against a remote target machine.
• The Metasploit is well known for its anti-forensic and evasion
tools, some of which are built into the Metasploit Framework.
Gandhinagar Institute Of technology 2
History
• Metasploit was created by H. D. Moore in 2003 as a portable
network tool using Perl. By 2007, the Metasploit Framework
had been completely rewritten in Ruby.
• On October 21, 2009, the Metasploit Project announced that it
had been acquired by Rapid7, a security company that
provides unified vulnerability management solutions.
• Like comparable commercial products such as Immunity's
Canvas or Core Security Technologies' Core Impact,
Metasploit can be used to test the vulnerability of computer
systems or to break into remote systems.
Gandhinagar Institute Of technology 3
• Like many information security tools, Metasploit can be used for
both legitimate and unauthorized activities.
• Since the acquisition of the Metasploit Framework, Rapid7 has
added two open core proprietary editions called Metasploit
Express and Metasploit Pro.
• Metasploit's emerging position as the de facto exploit
development framework led to the release of software
vulnerability advisories often accompanied by a third party
Metasploit exploit module that highlights the exploitability, risk
and remediation of that particular bug.
Gandhinagar Institute Of technology 4
• Metasploit 3.0 began to include fuzzing tools, used to discover
software vulnerabilities, rather than just exploits for known
bugs. This avenue can be seen with the integration of the
lorcon wireless (802.11) toolset into Metasploit 3.0 in
November 2006. Metasploit 4.0 was released in August 2011.
Gandhinagar Institute Of technology 5
Metasploit Framework
• The basic steps for exploiting a system using the Framework
include:
1. Choosing and configuring an exploit (code that enters a target
system by taking advantage of one of its bugs; about 900
different exploits for Windows, Unix/Linux and Mac OS X
systems are included).
2. Optionally checking whether the intended target system is
susceptible to the chosen exploit.
Gandhinagar Institute Of technology 6
3. Choosing and configuring a payload (code that will be
executed on the target system upon successful entry for
instance, a remote shell or a VNC server).
4. Choosing the encoding technique so that the intrusion-
prevention system (IPS) ignores the encoded payload.
5. Executing the exploit.
Gandhinagar Institute Of technology 7
Metasploit interfaces
1. Metasploit Framework Edition
• The free version. It contains a command line interface, third-party
import, manual exploitation and manual brute forcing. This free
version of metasploit project also includes Zenmap, a well known
ports-scanner and a compiler for Ruby, the language in which this
version of metasploit was written.
2. Metasploit Community Edition
• In October 2011, Rapid7 released Metasploit Community Edition, a
free, web-based user interface for Metasploit. Metasploit Community
is based on the commercial functionality of the paid-for editions with
a reduced set of features, including network discovery, module
browsing and manual exploitation. Metasploit Community is included
in the main installer.
Gandhinagar Institute Of technology 8
3. Metasploit Express
• In April 2010, Rapid7 released Metasploit Express, an open-core
commercial edition for security teams who need to verify
vulnerabilities. It offers a graphical user interface, integrates nmap
for discovery, and adds smart brute forcing as well as automated
evidence collection.
4. Metasploit Pro
3. In October 2010, Rapid7 added Metasploit Pro, an open-core
commercial Metasploit edition for penetration testers. Metasploit
Pro adds onto Metasploit Express with features such as Quick Start
Wizards/Meta Modules, building and managing social engineering
campaigns, web application testing, an advanced Pro Console,
dynamic payloads for anti-virus evasion, integration with Nexpose
for ad-hoc vulnerability scans, and VPN pivoting.
Gandhinagar Institute Of technology 9
5. Armitage
• Armitage is a graphical cyber attack management tool for the
Metasploit Project that visualizes targets and recommends exploits.
It is a free and open source network security tool notable for its
contributions to red team collaboration allowing for shared
sessions, data, and communication through a single Metasploit
instance.[11]
6. Cobalt Strike
• Cobalt Strike is a collection of threat emulation tools provided by
Strategic Cyber LLC (https://cobaltstrike.com/) to work with the
Metasploit Framework. Cobalt Strike includes all features of
Armitage and adds post-exploitation tools, in addition to report
generation features.
Gandhinagar Institute Of technology 10
Gandhinagar Institute Of technology 11

More Related Content

PDF
A Comparison Study of Open Source Penetration Testing Tools
PDF
IRJET- Penetration Testing using Metasploit Framework: An Ethical Approach
PPT
Malware analysis on android using supervised machine learning techniques
PDF
AI approach to malware similarity analysis: Maping the malware genome with a...
PPTX
Open Source Insight: Meltdown, Spectre Security Flaws “Impact Everything”
PPTX
Anti malware solution using Machine Learning
PPTX
Information Security Awareness
PPTX
SecureIoT Security Knowledge Base
A Comparison Study of Open Source Penetration Testing Tools
IRJET- Penetration Testing using Metasploit Framework: An Ethical Approach
Malware analysis on android using supervised machine learning techniques
AI approach to malware similarity analysis: Maping the malware genome with a...
Open Source Insight: Meltdown, Spectre Security Flaws “Impact Everything”
Anti malware solution using Machine Learning
Information Security Awareness
SecureIoT Security Knowledge Base

What's hot (20)

PPTX
Malware Analysis
PPTX
Introduction to penetration testing
PPTX
Malware Detection Using Machine Learning Techniques
PPTX
Adversary Emulation and Its Importance for Improving Security Posture in Orga...
PDF
IRJET- Android Malware Detection using Machine Learning
DOCX
robust malware detection for iot devices using deep eigen space learning
PPTX
Software Security Assurance for DevOps
PPTX
IOT Security FUN-damental
PDF
Handy penetration testing tools
PDF
Intrusion Detection Systems By Anamoly-Based Using Neural Network
PPTX
IoT Security - Preparing for the Worst
PDF
Advanced Endpoint Protection
PDF
Application layer security protocol
PPTX
PDF
System Security @ NECSTLab and Breaking the Laws of Robotics: Attacking Indus...
PPTX
Final project.ppt
PPTX
Cognitive Computing in Security with AI
PPTX
IDSECCONF 2020 : A Tale Story of Building and Maturing Threat Hunting Program
Malware Analysis
Introduction to penetration testing
Malware Detection Using Machine Learning Techniques
Adversary Emulation and Its Importance for Improving Security Posture in Orga...
IRJET- Android Malware Detection using Machine Learning
robust malware detection for iot devices using deep eigen space learning
Software Security Assurance for DevOps
IOT Security FUN-damental
Handy penetration testing tools
Intrusion Detection Systems By Anamoly-Based Using Neural Network
IoT Security - Preparing for the Worst
Advanced Endpoint Protection
Application layer security protocol
System Security @ NECSTLab and Breaking the Laws of Robotics: Attacking Indus...
Final project.ppt
Cognitive Computing in Security with AI
IDSECCONF 2020 : A Tale Story of Building and Maturing Threat Hunting Program
Ad

Similar to Meta sploit (cyber security) (20)

PPTX
Finalppt metasploit
PPTX
Metasploit
PDF
Exploits Attack on Windows Vulnerabilities
PPTX
Introduction of Metasploit and task.pptx
PPTX
Introduction to metasploit
 
PDF
01 Metasploit kung fu introduction
PPTX
Introduction to Metasploit
 
PPTX
Metasploit Framework and Payloads supported
PDF
24 33 -_metasploit
PPT
[null]Metapwn - Pwn at a puff by Prajwal Panchmahalkar
PDF
Metaploit
PPTX
Introduction To Exploitation & Metasploit
PDF
Metasploit Computer security testing tool
PPTX
Metasploit
PPTX
Metasploit (Module-1) - Getting Started With Metasploit
PPTX
Metasploit
PDF
Metasploitation part-1 (murtuja)
PDF
Introduction to Metasploit
PPTX
metaploit framework
Finalppt metasploit
Metasploit
Exploits Attack on Windows Vulnerabilities
Introduction of Metasploit and task.pptx
Introduction to metasploit
 
01 Metasploit kung fu introduction
Introduction to Metasploit
 
Metasploit Framework and Payloads supported
24 33 -_metasploit
[null]Metapwn - Pwn at a puff by Prajwal Panchmahalkar
Metaploit
Introduction To Exploitation & Metasploit
Metasploit Computer security testing tool
Metasploit
Metasploit (Module-1) - Getting Started With Metasploit
Metasploit
Metasploitation part-1 (murtuja)
Introduction to Metasploit
metaploit framework
Ad

More from Rajal Patel (6)

PPT
phase lag Design using Rout locous
PPT
construction of underground cable
PPTX
Concentric Winding (EED)
PPT
Basic Principle of dc chopper
PPT
Demultiplexing of buses of 8085 microprocessor
PPT
Types of dc generator
phase lag Design using Rout locous
construction of underground cable
Concentric Winding (EED)
Basic Principle of dc chopper
Demultiplexing of buses of 8085 microprocessor
Types of dc generator

Recently uploaded (20)

PDF
ANTIBIOTICS.pptx.pdf………………… xxxxxxxxxxxxx
PDF
Supply Chain Operations Speaking Notes -ICLT Program
PDF
TR - Agricultural Crops Production NC III.pdf
PDF
RMMM.pdf make it easy to upload and study
PPTX
IMMUNITY IMMUNITY refers to protection against infection, and the immune syst...
PDF
Insiders guide to clinical Medicine.pdf
PDF
FourierSeries-QuestionsWithAnswers(Part-A).pdf
PPTX
Introduction_to_Human_Anatomy_and_Physiology_for_B.Pharm.pptx
PDF
Abdominal Access Techniques with Prof. Dr. R K Mishra
PDF
VCE English Exam - Section C Student Revision Booklet
PPTX
Pharmacology of Heart Failure /Pharmacotherapy of CHF
PDF
The Lost Whites of Pakistan by Jahanzaib Mughal.pdf
PDF
O7-L3 Supply Chain Operations - ICLT Program
PPTX
Pharma ospi slides which help in ospi learning
PDF
Black Hat USA 2025 - Micro ICS Summit - ICS/OT Threat Landscape
PPTX
PPT- ENG7_QUARTER1_LESSON1_WEEK1. IMAGERY -DESCRIPTIONS pptx.pptx
PPTX
Renaissance Architecture: A Journey from Faith to Humanism
PPTX
human mycosis Human fungal infections are called human mycosis..pptx
PPTX
Cell Structure & Organelles in detailed.
PDF
grade 11-chemistry_fetena_net_5883.pdf teacher guide for all student
ANTIBIOTICS.pptx.pdf………………… xxxxxxxxxxxxx
Supply Chain Operations Speaking Notes -ICLT Program
TR - Agricultural Crops Production NC III.pdf
RMMM.pdf make it easy to upload and study
IMMUNITY IMMUNITY refers to protection against infection, and the immune syst...
Insiders guide to clinical Medicine.pdf
FourierSeries-QuestionsWithAnswers(Part-A).pdf
Introduction_to_Human_Anatomy_and_Physiology_for_B.Pharm.pptx
Abdominal Access Techniques with Prof. Dr. R K Mishra
VCE English Exam - Section C Student Revision Booklet
Pharmacology of Heart Failure /Pharmacotherapy of CHF
The Lost Whites of Pakistan by Jahanzaib Mughal.pdf
O7-L3 Supply Chain Operations - ICLT Program
Pharma ospi slides which help in ospi learning
Black Hat USA 2025 - Micro ICS Summit - ICS/OT Threat Landscape
PPT- ENG7_QUARTER1_LESSON1_WEEK1. IMAGERY -DESCRIPTIONS pptx.pptx
Renaissance Architecture: A Journey from Faith to Humanism
human mycosis Human fungal infections are called human mycosis..pptx
Cell Structure & Organelles in detailed.
grade 11-chemistry_fetena_net_5883.pdf teacher guide for all student

Meta sploit (cyber security)

  • 1. Cyber Security (2150002) Active Learning Assignment on Metasploit Prepared By: Patel RajalKumar H. (160123109013) Guided By : Prof. Abhishek Harit Electrical Department Batch-B3 Gandhinagar Institute Of technology 1
  • 2. Introduction • The Metasploit is a computer security that provides information about security vulnerabilities and aids in penetration testing and IDS signature development. • Its best-known sub-project is the open source Metasploit Framework, a tool for developing and executing exploit code against a remote target machine. • The Metasploit is well known for its anti-forensic and evasion tools, some of which are built into the Metasploit Framework. Gandhinagar Institute Of technology 2
  • 3. History • Metasploit was created by H. D. Moore in 2003 as a portable network tool using Perl. By 2007, the Metasploit Framework had been completely rewritten in Ruby. • On October 21, 2009, the Metasploit Project announced that it had been acquired by Rapid7, a security company that provides unified vulnerability management solutions. • Like comparable commercial products such as Immunity's Canvas or Core Security Technologies' Core Impact, Metasploit can be used to test the vulnerability of computer systems or to break into remote systems. Gandhinagar Institute Of technology 3
  • 4. • Like many information security tools, Metasploit can be used for both legitimate and unauthorized activities. • Since the acquisition of the Metasploit Framework, Rapid7 has added two open core proprietary editions called Metasploit Express and Metasploit Pro. • Metasploit's emerging position as the de facto exploit development framework led to the release of software vulnerability advisories often accompanied by a third party Metasploit exploit module that highlights the exploitability, risk and remediation of that particular bug. Gandhinagar Institute Of technology 4
  • 5. • Metasploit 3.0 began to include fuzzing tools, used to discover software vulnerabilities, rather than just exploits for known bugs. This avenue can be seen with the integration of the lorcon wireless (802.11) toolset into Metasploit 3.0 in November 2006. Metasploit 4.0 was released in August 2011. Gandhinagar Institute Of technology 5
  • 6. Metasploit Framework • The basic steps for exploiting a system using the Framework include: 1. Choosing and configuring an exploit (code that enters a target system by taking advantage of one of its bugs; about 900 different exploits for Windows, Unix/Linux and Mac OS X systems are included). 2. Optionally checking whether the intended target system is susceptible to the chosen exploit. Gandhinagar Institute Of technology 6
  • 7. 3. Choosing and configuring a payload (code that will be executed on the target system upon successful entry for instance, a remote shell or a VNC server). 4. Choosing the encoding technique so that the intrusion- prevention system (IPS) ignores the encoded payload. 5. Executing the exploit. Gandhinagar Institute Of technology 7
  • 8. Metasploit interfaces 1. Metasploit Framework Edition • The free version. It contains a command line interface, third-party import, manual exploitation and manual brute forcing. This free version of metasploit project also includes Zenmap, a well known ports-scanner and a compiler for Ruby, the language in which this version of metasploit was written. 2. Metasploit Community Edition • In October 2011, Rapid7 released Metasploit Community Edition, a free, web-based user interface for Metasploit. Metasploit Community is based on the commercial functionality of the paid-for editions with a reduced set of features, including network discovery, module browsing and manual exploitation. Metasploit Community is included in the main installer. Gandhinagar Institute Of technology 8
  • 9. 3. Metasploit Express • In April 2010, Rapid7 released Metasploit Express, an open-core commercial edition for security teams who need to verify vulnerabilities. It offers a graphical user interface, integrates nmap for discovery, and adds smart brute forcing as well as automated evidence collection. 4. Metasploit Pro 3. In October 2010, Rapid7 added Metasploit Pro, an open-core commercial Metasploit edition for penetration testers. Metasploit Pro adds onto Metasploit Express with features such as Quick Start Wizards/Meta Modules, building and managing social engineering campaigns, web application testing, an advanced Pro Console, dynamic payloads for anti-virus evasion, integration with Nexpose for ad-hoc vulnerability scans, and VPN pivoting. Gandhinagar Institute Of technology 9
  • 10. 5. Armitage • Armitage is a graphical cyber attack management tool for the Metasploit Project that visualizes targets and recommends exploits. It is a free and open source network security tool notable for its contributions to red team collaboration allowing for shared sessions, data, and communication through a single Metasploit instance.[11] 6. Cobalt Strike • Cobalt Strike is a collection of threat emulation tools provided by Strategic Cyber LLC (https://cobaltstrike.com/) to work with the Metasploit Framework. Cobalt Strike includes all features of Armitage and adds post-exploitation tools, in addition to report generation features. Gandhinagar Institute Of technology 10
  • 11. Gandhinagar Institute Of technology 11