Penetration testing tool uses Cisco holes to gain access to the network
endif; ?>Rapid 7 is now including exploits of Cisco gear in Metasploit. The tool can now automatically use authentication holes on Cisco devices that allow attackers to gain access to the network. As new vulnerabilities on Cisco become known, they too will be included in the penetration testing tool.
UPDATED: The inclusion of Cisco is part of the rollout of Metasploit 3.5.1. “Metasploit 3.5.1 focuses on [Cisco] routers and switches, as well as Pix and ASA platforms. Previous versions of Metasploit already addressed Cisco wireless access points (and, therefore, included in this new version),” explains Metasploit founder and lead developer, HD Moore.
Explains Christian Kirsch on the Rapid 7 Security blog:
“The new Metasploit version 3.5.1 adds a lot of features to audit your network’s password security on many levels. Metasploit has always offered a broad range of brute forcing capabilities. Since version 3.5.1, it now also downloads the configuration files of Cisco routers and extracts their passwords. HD’s team has also added brute forcing of UNIX “r” services, such as rshell, rlogin and rexec, as well as VNC and SNMP services. Metasploit can also now import pcap network traffic logs to find clear text passwords, and to discover hosts and services. Metasploit has also become stealthier than ever: It now flies under the radar of intrusion detection (IDS) and intrusion prevention systems (IPS). An enhanced anti-virus evasion ensures that exploits are not stopped by end-point defenses.”
Metasploit is a two-edged sword for security professionals. It is a beloved tool that helps security pros find and fix security holes — leveling the playing field by giving security pros easy access to the exploits the bad guys can find. But it also serves as a sort of informal deadline on how much time an enterprise has to patch its wares. Once an exploit is included in the tool, the blackhats have easy access to it, too, and Metasploit prides itself on adding exploits as soon as they go public.
Automated exploits against Cisco devices are, for now, only included in the two paid versions of the tool, Metasploit Express and Metasploit Pro, and not in the free open source version, Metasploit Framework.
The new 3.5.1 release has also become the engine of the FOSS tool. A few months ago, when I talked to HD Moore, he promised that the company wouldn’t hamper the FOSS tool by leaving out exploits. At the time, he said: “The 3.3.0 release, 3.3.3, 3.3.1, all those releases were under Rapid7. We haven’t changed the licensing, registration, or delayed access to exploits.” It seems that promise has gone by the wayside with support for Cisco exploits — so if you want automated access to all the known holes via Metasploit, you’ll have to pay for that in money, not in contributed code.
In addition to brute force attacks against Cisco, the 3.5.1 version also can attach malicious PDF and MP3 files to emails. Plus it can run attacks against SAP BusinessObjects, Novell NetWare servers (any of those still around?), Microsoft Internet Explorer and browser plugins such as Adobe Flash and Oracle Java.




