About InfoWorld : Advertise : Subscribe : Contact Us : Awards : Events : Store
InfoWorld HomeNewsTest CenterOpinionsProduct GuideTechIndex
PRODUCT REVIEWS GUIDE    REVIEWS    ANALYSES    SPECIAL REPORTS 
 

TEST CENTER

 
Core makes an Impact

By Mandy Andress
June 14, 2002


PENETRATION TESTING is a standard method for evaluating an organization's network security posture. These assessments can be performed from the standpoint of a malicious insider on the corporate network or a malicious outsider trying to compromise systems from the Internet. Some organizations perform these tests internally, but most hire outside consulting firms.

   ADVERTISEMENT
  

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

RELATED LINKS
»  IE 7 bug reopens debate over patch responsibilities
»  Woman ordered to pay for file-sharing will appeal
»  McAfee to buy SafeBoot for $350M
»  Security RSS feed 

IDG ENTERPRISE NETWORK
Research Reports  (CIO)
Ask the Expert  (CIO)

TOP NEWS 


IT SOLUTION SEARCH
In either case, because there is no standard method of performing a penetration test, the quality of the results depends to a great extent on the knowledge and skill of the penetration testers on the job that day. Core Security Technologies has addressed this problem with Impact, a penetration testing framework that allows organizations to share knowledge and provide consistency across testing engagements. Its ease of use, innovation, and flexibility earned it a Deploy rating in our tests.

Core Impact tackles penetration tests in seven steps: information gathering, information analysis and planning, vulnerability detection, target penetration, attack/privilege escalation, analysis and reporting, and cleanup. Impact provides a framework for performing each of these steps in a consistent, organized fashion while logging and recording every action taken at every step.

Penetration tests are performed by launching agents and modules against target systems from the Impact Console, where you can also view detailed information about target systems, a record of all activity and module output, and the results of attacks.

Agents -- the small programs you install on compromised systems and use to advance an attack -- are the core component of Impact. Agents come in several levels of capability, ranging from Level 0 agents that can execute only a single basic function call at a time to Level 2 agents providing full multitasking support, a secure communication channel, a Python Virtual Machine (for remote execution of modules), and database connectivity.

Modules are sets of operations that can be launched against target systems, and include OS fingerprinting, port scanning, and targeted exploits. Modules come in two types: native modules that are compiled directly into the agent's machine language, and Python modules that run over a Python Virtual Machine. The ability to develop custom modules is one of the strengths of Impact. Organizations can use these modules to share the knowledge of their best penetration testers across the entire testing group.

We installed Impact on a Windows 2000 Professional system and started an assessment against our test network, which was comprised of Linux and Windows systems as well as a few other network devices, such as Cisco routers, print servers, and firewalls. The Impact Console is very intuitive, using point-and-click and drag-and-drop functionality to execute the testing modules. First, we ran the network discovery module on our test network to identify active systems. We then ran the port scanner module to identify open ports on active systems.

Next, we ran the OS stack fingerprinting module to identify the operating systems running on our systems. The OS fingerprinting module is not very extensive out of the box, but you can easily add your own OS signatures to the os_id database. Until we added our own signatures, the module correctly identified only about half of the systems on our test network.

All this information gathering took less than five minutes, and afterward we had a detailed log of which modules were executed, when they were executed, and the results of those executions. We identified a Windows 2000 Server running IIS, so we decided to launch the IIS Unicode exploit, one of the exploit modules included with Impact. The exploit was successful (since we were running an unpatched IIS server) and we now had a compromised system running a Level 0 Agent. This entire process occurred in less than a minute with a single drag-and-drop action.

One of the greatest features of Impact is the ability to pivot, or move your target launch point. So far, we had been executing modules from our Console system. With a simple mouse selection, we changed the source of our attacks from our Console system to our newly compromised Windows 2000 Server. Running the RevertToSelf local exploit module, we gained full control of the Windows 2000 Server and used it as the launch point to compromise one of our Linux servers with the wuftpd format string vulnerability. To clean everything up at the end of our assessment, we simply uninstalled the agents and left no trace of ever being there.

For follow-up analysis, Impact creates two main reports: history and findings. The history report details all the actions taken during the assessment. The findings report details all the information for identified systems, such as name, IP address, OS, open ports, vulnerabilities exploited on the system, and agents installed on the system. Reports are available in HTML or XML.

Impact is a revolutionary product that could be just what network managers need to formalize penetration tests, providing exploit code, detailed logging and reporting, as well as easy cleanup. Any organization consistently performing penetration tests should consider using this product.




  BOTTOM LINE
Core Impact 1.0
BUSINESS CASE
This penetration testing framework brings quality and consistency to network security assessments.

TECHNOLOGY CASE
The ability to customize exploit modules allows users to test for the latest network security threats.

PROS
+ Modular design
+ Supports custom exploit modules
+ Detailed logging and reporting

CONS
- Limited number of exploit modules out-of-the-box
- Console runs on Windows 2000 only

COST
Annual license starts $50,000 for five users

PLATFORMS
Windows 2000

COMPANY
Core Security Technologies, http://www.corest.com

Deploy
Ease of use
Implementation
Innovation
Interoperability
Scalability
Security
Suitability
Support
Training
Value
Deploy



RELATED SUBJECTS

Security
Networking


SPONSORED WHITE PAPERS
EMC - Lower costs and improve reliability-Get the EMC CLARiiON white paper!
Ciphertrust - Are you ready for Sobig.G? Learn how to protect your email systems.
CDW - Personal attention. CDW. The Right Technology. Right Away.
EMC - Explore key performance features and capabilities of EMC ControlCenter 5.1.1.
Intel - Free Intel white paper shows you how to deploy a secure wireless LAN
Cisco - FREE WHITE PAPER: BLUEPRINT to design and implement secure VPNs
Verity, Inc. - "Mass Consolidation Hits the Web-Search Market"
McDATA - Download a FREE storage consolidation white paper from McDATA(R).
Lucent Technologies - Overcoming Common Firewall Limitations
Lucent Technologies - Leverage Your Mobile High Speed Data Access. Download Free White Paper!
Nokia - Get the scoop! Mobilizing business white papers & case studies.
BMC Software - Maximize the Potential of Enterprise Data: Free white paper!
Network Associates - Free white paper - Strategies for Optimizing Network Costs and Benefits
Entrust - Manage identities across applications. Improve productivity.
Stalker Software - CommuniGate Pro - Transform your Email and Calendaring
Remedy - A NEW Gartner Research Note:Producing Quality IT Services

Search the IDG White Paper Library:


SPONSORED LINKS

INFOWORLD MARKETPLACE


» IT Compliance Conference: Nov. 5-7 in San Diego
Best Practices, Peer Experiences, & Expert Advice for Building a Defensible IT Compliance Program
» FREE Sophos Threat Detection Test
Is your AV catching everything it should? Free virus, spyware and adware scan.
» IT Audit Checklists
Prepare for your next internal IT audit. Checklists cover security, risk management, PCI, and more.
» FREE White Paper: Mitigating Rock Phish Attacks
Standard anti-phishing methods cannot defeat complex Rock Phish attacks. Learn how to fight back...
» Apply BPM and ITIL at your IT Help Desk
ServiceWise brings BPM to complete IT service while eliminating integration cost. Learn more here.




 HOME  NEWS  TEST CENTER  OPINIONS  PRODUCT GUIDE  TECHINDEX   About : Advertise : Subscribe : Contact Us : Awards : Events 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy

All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses, phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

Computerworld :: Network World :: CIO :: PC World :: Darwin :: CMO :: CSO
IT Careers :: JavaWorld :: Macworld :: Mac Central :: Playlist :: GamePro :: GameStar :: Gamerhelp
ITWorld Canada :: Computerwoche :: Techworld UK :: tecChannel :: IDG.se :: IDG.no