[Full-disclosure] Vulnerability/Penetration Testing Tools



All,
I am in the process of researching a wide variety of penetration testing tools and vulnerability assessment tools. I've already researched many of the commercial tools like Coresecurity's Core Impact tool and even know a bit about the new tool that saint is about to come out with. What about open-source tools?


Are there any open source tools like Core Impact that allow you to not only scan a network for vulnerabilities but then allow you to issue attacks against those vulnerabilities? I'm interested in both windows based and *nix based tools. Yes I am aware of nessus, exploit tree, metaspoloit etc... but none of those really have the "identify then attack" type of structure... they are either "identify" or "attack".

-simon



________________________________________________________________________
Check Out the new free AIM(R) Mail -- 2 GB of storage and industry-leading spam and email virus protection.


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • [Full-disclosure] Multiple directory traversal vulnerabilities in Claroline ... NOT
    ... I claimed that it was Claroline that was vulnerable. ... I was researching a different product that uses Claroline as a backend, ... found the mentioned vulnerabilities in there. ... Robbe De Keyzer ...
    (Full-Disclosure)
  • Re: Pen testing techniques
    ... While Core Impact is a great tool, it is only that a tool. ... My skills were tested against a security tool vendor, which was using their tool as a selling point. ... For example, the tool vendor lost, because it was not designed to identify or find vulnerabilities in SAP web-enabled applications. ... Within the source code I found a username and password that was left over by the development team. ...
    (Pen-Test)
  • Re: Pen testing techniques
    ... Running an automated assessment tool, however expensive, should only ... Tools such as Core Impact will help determine ... Yada yada yada. ... running IIS 6.0.Core Impact did not find any vulnerabilities in the ...
    (Pen-Test)
  • RE: Core Impact Vs Manual Pen Test
    ... I use Core Impact and I have to say... ... But it won't exploit every possible vulnerabilities. ... Cenzic Hailstorm finds vulnerabilities fast. ... Click the link to buy it, try it or download Hailstorm for FREE. ...
    (Pen-Test)
  • Pen testing techniques
    ... pen test for one of our clients.We are doing it through Core ... Impact.Reconnaisance showed only port 80 as open and the web server ... running IIS 6.0.Core Impact did not find any vulnerabilities in the ... My question is what else can we do besides relying on Core Impact for ...
    (Pen-Test)