<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Automated Penetration Testing with the Metasploit Framework</title>
	<atom:link href="http://www.spylogic.net/2008/03/automated-penetration-testing-with-the-metasploit-framework/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.spylogic.net/2008/03/automated-penetration-testing-with-the-metasploit-framework/</link>
	<description></description>
	<lastBuildDate>Sun, 18 Sep 2011 21:48:21 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Tom</title>
		<link>http://www.spylogic.net/2008/03/automated-penetration-testing-with-the-metasploit-framework/comment-page-1/#comment-22</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Fri, 21 Mar 2008 14:27:46 +0000</pubDate>
		<guid isPermaLink="false">#comment-22</guid>
		<description>CG, thanks for the comments.  Totally agree with you that running any automated tool like Core and autopwn can lead to irresponsibility by a pen tester.  I have used autopwn only on a limited number of hosts and only to verify that these hosts could be exploited...mostly to supplement the manual testing that was also being done.  Unfortunately we are sometimes limited with the time (and staff) we have to verify hosts that can be exploited.  Tools like Core and autopwn can assist with this.  I always mention in my talks that automated testing should never replace manual, detailed testing....use these tools sparingly to supplement your toolkit! :)</description>
		<content:encoded><![CDATA[<p>CG, thanks for the comments.  Totally agree with you that running any automated tool like Core and autopwn can lead to irresponsibility by a pen tester.  I have used autopwn only on a limited number of hosts and only to verify that these hosts could be exploited&#8230;mostly to supplement the manual testing that was also being done.  Unfortunately we are sometimes limited with the time (and staff) we have to verify hosts that can be exploited.  Tools like Core and autopwn can assist with this.  I always mention in my talks that automated testing should never replace manual, detailed testing&#8230;.use these tools sparingly to supplement your toolkit! <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CG</title>
		<link>http://www.spylogic.net/2008/03/automated-penetration-testing-with-the-metasploit-framework/comment-page-1/#comment-21</link>
		<dc:creator>CG</dc:creator>
		<pubDate>Fri, 21 Mar 2008 14:03:24 +0000</pubDate>
		<guid isPermaLink="false">#comment-21</guid>
		<description>I have the same comment about db_autopwn that i did about Core RPT.  limited usefulness IMO, especially on a pentest.  &lt;br /&gt;
&lt;br /&gt;
running that also lends a bit towards irresponsibility as well.  if a tester doesnt have the skill to scan, enumerate, and pick exploits in a methodological manner, that &quot;should&quot; work based on version identification then i&#039;m not sure i&#039;d want them on a team with me.&lt;br /&gt;
&lt;br /&gt;
not to say that it isnt &quot;neat&quot;  that tools can do that.&lt;br /&gt;
&lt;br /&gt;
pulled down the slides, looks like you are talking about good things in that local security group</description>
		<content:encoded><![CDATA[<p>I have the same comment about db_autopwn that i did about Core RPT.  limited usefulness IMO, especially on a pentest.  </p>
<p>running that also lends a bit towards irresponsibility as well.  if a tester doesnt have the skill to scan, enumerate, and pick exploits in a methodological manner, that &quot;should&quot; work based on version identification then i&#8217;m not sure i&#8217;d want them on a team with me.</p>
<p>not to say that it isnt &quot;neat&quot;  that tools can do that.</p>
<p>pulled down the slides, looks like you are talking about good things in that local security group</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom</title>
		<link>http://www.spylogic.net/2008/03/automated-penetration-testing-with-the-metasploit-framework/comment-page-1/#comment-20</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Fri, 21 Mar 2008 09:25:55 +0000</pubDate>
		<guid isPermaLink="false">#comment-20</guid>
		<description>Sorry about that.  Please try downloading the file again.</description>
		<content:encoded><![CDATA[<p>Sorry about that.  Please try downloading the file again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anthony Williams</title>
		<link>http://www.spylogic.net/2008/03/automated-penetration-testing-with-the-metasploit-framework/comment-page-1/#comment-19</link>
		<dc:creator>Anthony Williams</dc:creator>
		<pubDate>Fri, 21 Mar 2008 04:55:34 +0000</pubDate>
		<guid isPermaLink="false">#comment-19</guid>
		<description>Tom,&lt;br /&gt;
&lt;br /&gt;
Nice post!  I have attempted to download the .PDF of your presentation and keep getting &quot;file damaged and can&#039;t be repaired errors&quot;.  I seem to be able to open up other .PDF files just fine.  Can you please verify your file?&lt;br /&gt;
&lt;br /&gt;
Thanks!&lt;br /&gt;
&lt;br /&gt;
-AW</description>
		<content:encoded><![CDATA[<p>Tom,</p>
<p>Nice post!  I have attempted to download the .PDF of your presentation and keep getting &quot;file damaged and can&#8217;t be repaired errors&quot;.  I seem to be able to open up other .PDF files just fine.  Can you please verify your file?</p>
<p>Thanks!</p>
<p>-AW</p>
]]></content:encoded>
	</item>
</channel>
</rss>

