John the Ripper password cracker is latest open source security project to feel Rapid7's love

John-the-Ripper which is the standard in the security/password cracking world, is part of Openwall. There are actually quite a number of open source security projects under the Openwall umbrella. Openwall itself is the granddaddy of security Linux distributions. Many of today’s “secure” Linux distributions like SELinux and EnGarde have some of the Openwall DNA. But in addition, Openwall also handles things like crypt blowfish, the popular password hashing algorithm and many other open source security projects.
The news of Rapid7’s support was also announced on the Rapid7 community boards last week as well. Rapid7 has developed a history of supporting open source security projects. It gave a home to HD Moore and the Metasploit team about 2 years ago. Since then Rapid7 has also begun to sell the Metasploit Pro commercial product based on the open source Metasploit project. To their credit they have also continued to develop and distribute a robust open source version of the product as well.
In addition to Metasploit, about a year ago Rapid7 announced a sponsorship of the W3AF (web application, attack and audit framework) open source project which I reported on in July 2010. Where the Metasploit relationship was more like an acquisition, the W3AF deal was a sponsorship. Rapid7 actually pays for developers to work on the framework.
In the John-the-Ripper case Rapid7 is taking a similar tact. They have been paying for developers to work on the brute force research on the DES algorithms. This has resulted in a 17% performance increase in the latest release. Rapid7 will continue to support the project. To be fair it should be noted that John-the-Ripper will be integrated with Metasploit, so Rapid7 certainly gets something out of it.
But lets be clear, to date Rapid7 has been a text book example of a commercial company that is a “good citizen” in the open source community and has put its money where its mouth is in support of open source security projects. The best part of it is that it appears to be paying off for them, as word on the security street is that they are doing very well. Open source can pay off!




