July 31, 2006

The mind of HD Moore

Metasploit creator says criticism comes with turf

HD Moore has a matter-of-fact way of talking that belies his uncanny ability to draw the public eye. In just the past month, the 25-year-old Texan, who started the open source Metasploit Project in 2003, made headlines for promising to release a new bug for the Internet Explorer Web browser each day in July. By the end of July, he was in the news again: releasing a Web-based tool that uses the Google search engine to locate malicious programs.

InfoWorld Senior Editor Paul Roberts caught up with Moore, who is also director of security research at BreakingPoint Systems in Austin, Texas, to talk about Metasploit, project management, and full disclosure.

InfoWorld: Why did you launch Metasploit in the first place?

HD Moore: In 2003 there was … a doldrum in the security area. A lot of the people who were active publishers of information got jobs or decided to do something else. At the same time, private companies started to hoard security information, so people started saying, “Why should I give this information away when I can sell it to iDefense?” Metasploit was about creating a toolkit and a framework for developing new exploits quickly, allowing people to cut through the boilerplate stuff and develop something new.

IW: How did you grow the project to where it is now?

HDM: Knowledge spread mostly by word of mouth. People would say, “That’s cool.” [Metasploit lead developer] Spoonm … e-mailed us and said, “Your software sucks.” And I was like, “OK, why don’t you rewrite it?” So he did. In the exploit community, you’ve got to appeal to ego. Make it a challenge. That’s what they live for. As a project manager, it’s my job to say, “OK. How can we do better?” One reason that Metasploit has done so well is that there’s no holier-than-thou attitude.

IW: What should enterprise IT staff know about Metasploit?

HDM: I’m always wary of recommending Metasploit for use in a company, because your employer may have rules that forbid the use of programs like this. I think it can be a nice way to follow up after a third-party vulnerability assessment. The company you hire should be able to prove that the vulnerabilities they’ve discovered are real. Not just say, “Oh, I found 20 bugs -- fix them.” Tools like Metasploit can verify that, by running an exploit and seeing if it works. Unlike public exploits, you can also be sure that [Metasploit] isn’t installing back doors.

IW: You caught heat for releasing a new IE vulnerability every day in July, as if you were aiding and abetting the enemy.

HDM: That comes with territory. Any time you supply information to anybody, you’ve got to supply it to everybody. We saw this a couple years back, where CERT was allowing some customers to purchase vulnerability information in advance, then someone took that information and generated an exploit from it. Partial disclosure never works. You just end up catering to special groups that you deem trustworthy enough to have access. If I make something public, it’s not just to a group that I consider trustworthy.

IW: You recently unveiled a Google-based malicious code locator, akin to the one security firm Websense said it developed. What was behind that?

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.