Friday 19 March 2010 - 2825 read - ( Keywords : Configurations checks , Penetration testing & Ethical Hacking , VASTO , Virtualization )

Secure Network is working on the first security assessment toolkit for virtual infrastructures, VASTO, and Criscione announced today the public beta at the Troopers conference.
VASTO comes as a set of components for Metasploit, one of the most popular frameworks for penetration testing in the security industry.
VASTO comes as a set of components for Metasploit, one of the most popular frameworks for penetration testing in the security industry. The framework consists of tools, libraries, modules, and user interfaces. The basic function of the framework is a module launcher, allowing the user to configure an exploit module and launch it at a target system. If the exploit succeeds, the payload is executed on the target and the user is provided with a shell to interact with the payload. Hundreds of exploits and dozens of payload options are available.
What Secure Network released today is a number of open source modules that perform a number of different attacks: from hijacking a connection to the virtual infrastructures web-based management consoles (against VMware VI/vSphere, Server 1.x, Converter and even Citrix XenCenter) to password bruteforcing (against VMware and Xen platforms), up to a path traversal attack (against VMware ESX, ESXi and Server web interfaces).
The toolkit even includes an attack against VMware Studio.
The framework has been presented at Troopers 10.
POSTSCRIPTUM
COMPLIANCE MANDATES
Penetration testing & Ethical Hacking : PCI DSS 11.3, SOX A13.3, GLBA 16 CFR Part 314.4 (c), HIPAA 164.308(a)(8), FISMA RA-5, SI-2, ISO 27001/27002 12.6, 15.2.2
RELATED ARTICLES
Configurations checks,
Penetration testing & Ethical Hacking,
VASTO,
Virtualization,
19 March 2010 : VASTO The First Virtualization Assessment Toolkit released
Security Dashboard
Security vDNA







