GUI makes Metasploit easier for everyone

In addition to the new community edition, Moore pointed out in his discussion with me that since Rapid7 acquired Metasploit the code base of the framework has grown by 156%. This represents a tremendous amount of work in just about every area of the program. With so much available in the open source framework, Moore and his team did a study of who is actually using Metasploit. Their research showed that Metasploit users divided into two groups. One were power users like Moore himself, who are very comfortable using the framework from a command line. Another group was not getting the most of Metasploit without some sort of GUI to manage it with. For this group several Java front ends and others had popped up. Moore while grateful that the community was responding to the needs of this segment of users felt that a more comprehensive GUI was needed. Since Rapid7 had already developed the interface for the commercial edition, the decision was made to bring it to everyone.
“The best way to tackle the increasing information security challenge is to share knowledge between practitioners, open source projects and commercial vendors,” said HD Moore, Rapid7 CSO and Metasploit chief architect. “With that in mind, we’ve combined the Metasploit Framework with Rapid7’s commercial development to bring together the best of both worlds – the collaboration of security researchers around the world with quality-tested and stable commercial features. The new Metasploit Community Edition will greatly help security professionals seeking to understand risk and improve their security programs without needing to increase budgets.
“Metasploit Framework users fall into two camps: first, there are security researchers and developers who want a powerful platform to build custom tools and processes. The command-line interface works very well for them today, and we continue to invest in this interface. Second, Metasploit Framework is used by security and IT professionals to verify vulnerabilities and to conduct security assessments. For this group of users, the command-line console may not be the best fit. Metasploit Community Edition provides a much more accessible solution for this group – for free,” added Moore.”
Using the GUI users can not only run Metasploit but can also import vulnerability scan data from several 3rd party tools including Rapid7’s own Nexpose scanner. Additionally, Metasploit Community Edition users can initiate scans via Nexpose if they also happen to be Nexpose customers. For those who say that it gives Rapid7 and unfair advantage, that type of integration between the tools from the same company should be expected.
The Community Edition will be a welcome addition to the pen tester’s tool kit. However, there will be some who say that this is a move away from open source. While it is free, the community edition is not open source. It is a slippery slope that other open source tools security tools have slipped on before. I asked Moore exactly this question using Snort and Nessus as examples. Moore said that Metasploit is different (what did you expect him to say), in that they are not separating out signatures or new exploits or a feed of them and making them not open. What is not open here is the GUI, but underneath that GUI the Metasploit framework running is the same open source version that remains open.
This will make it easier for Rapid7 and the Metasploit team to keep the different versions of the product in sync. All in all, after two years Rapid7 continues to do a good job with Metasploit keeping it a premier tool for pen testers all over the world and keeping a thriving, growing community happy. Much of that is due to HD Moore himself who keeps the pulse of the community close to his heart. Congratulations to Rapid7 and Metasploit, here is to many more good years of providing great open source and security solutions.




