Rapid7 Expands Its Support Of Open Source Security Projects

Analysis
Jun 27, 20113 mins

John the Ripper password cracker is latest open source security project to feel Rapid7's love

I was talking last week to my friend HD Moore who founded and leads the development team for Metasploit at Rapid7. He told me about yet another open source project that Rapid7 has been supporting with financial and engineering support. The venerable John-the-Ripper password cracking project has been the receipient of support from Rapid7 for about a year now, culminating in the latest release which was recently announced.

John-the-Ripper which is the standard in the security/password cracking world, is part of Openwall. There are actually quite a number of open source security projects under the Openwall umbrella. Openwall itself is the granddaddy of security Linux distributions. Many of today’s “secure” Linux distributions like SELinux and EnGarde have some of the Openwall DNA.  But in addition, Openwall also handles things like crypt blowfish, the popular password hashing algorithm and many other open source security projects.

The news of Rapid7’s support was also announced on the Rapid7 community boards last week as well.  Rapid7 has developed a history of supporting open source security projects. It gave a home to HD Moore and the Metasploit team about 2 years ago. Since then Rapid7 has also begun to sell the Metasploit Pro commercial product based on the open source Metasploit project. To their credit they have also continued to develop and distribute a robust open source version of the product as well.  

In addition to Metasploit, about a year ago Rapid7 announced a sponsorship of the W3AF (web application, attack and audit framework) open source project which I reported on in July 2010. Where the Metasploit relationship was more like an acquisition, the W3AF deal was a sponsorship. Rapid7 actually pays for developers to work on the framework.

In the John-the-Ripper case Rapid7 is taking a similar tact. They have been paying for developers to work on the brute force research on the DES algorithms. This has resulted in a 17% performance increase in the latest release. Rapid7 will continue to support the project. To be fair it should be noted that John-the-Ripper will be integrated with Metasploit, so Rapid7 certainly gets something out of it.

But lets be clear, to date Rapid7 has been a text book example of a commercial company that is a “good citizen” in the open source community and has put its money where its mouth is in support of open source security projects. The best part of it is that it appears to be paying off for them, as word on the security street is that they are doing very well. Open source can pay off!