Pre-auth Remote Code Execution Vulnerability in Metasploit
github.com
github.com
Overall it's highly likely that most if not all security testing tools are vulnerable to some attacks, and I have a pretty strong suspicion that governments do work on movie like "counter hacks" by identifying RCE vulnerabilities in common network/port scanners, vulnerability scanners, and other enumeration tools.
In this case, this is a bug in the web interface, so you'd have to be on the same network as this person, or have access to their interface for exploiting this to be practical.
I'm more curious to know if anyone has ever been able to 'counter-hack' a scanner by sending an unexpected response back.
Anyone ever heard of anything like this?
You can fuz scanners and the setup honeypots that would exploit any vulnerability you found nothing in here is specifically complicated, you can also tailor your honeypot to specific subset of tools you want to target.
http://security.stackexchange.com/questions/3630/how-to-find...
This is however more in relation to intrusion detection not active countermeasures.
You have to love things like this.
The right title is the boring one, "Pre-auth Remote Code Execution Vulnerability in Metasploit".
The rule on HN is, if you want to put your own spin on a story, like "This bug will delight irony lovers everywhere", you put that in a comment like everyone else. Submitters don't own the stories and don't get to editorialize their titles.
That title is plenty interesting to me. If I run a product, I would normally not expect it to have security issues (unless it's from Adobe or something really old). Take Wireshark: I've seen them fix stuff like this so, yeah, I do expect Wireshark to be fine to run on untrusted networks as long as I'm not trying to wiretap the NSA's traffic. Similarly with Metasploit, I expect to be able to run that without being sploited myself.