All the latest UK technology news, reviews and analysis

'Hack in a box' tool emerges at Def Con

by James Middleton

17 Jul 2001

Be the first to comment

  • Tweet this

Argentinian security firm Core-SDI created a storm of controversy when it unveiled an 'intelligent' hacking tool which automates system penetration.

The as yet unnamed tool, showcased at the Def Con and Black Hat conference in Las Vegas, is capable of scanning the target, mapping networks, finding vulnerabilities and scripting and compiling customised code to exploit those flaws before systematically trying to gain higher levels of access.

Core-SDI boasted that before the arrival of its 'hack in a box' tool, security professionals and penetration testers had to make do with a patchwork toolbox built up of scripts pulled off the web or developed by the pen testers themselves along with commercial port scanners and a multitude of other tools.

The offering would include this entire toolbox in one package, but uses agents to break further into target networks. These agents attempt to break into a certain area or machine and, once successful, would deploy another agent to run the next stage of the hack.

Core-SDI claimed that the tool would be smarter than some script kiddies, pulling hacking techniques from a huge database before generating a full security report highlighting any weaknesses.

The company argued - somewhat unconvincingly - that to deter script kiddies from using the tool, it was attaching a hefty price tag so that it would only fall into the hands of security professionals. It should be available by the end of the year.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

25%

1%

11%

63%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Helpdesk/Service Analyst x3

Helpdesk/Service Analyst x 3 3 Month Contract...

2nd/3rd line Technical support EMEA (FRENCH SPEAKING)

French Technical support Specialist (2/3rd Line) CCNA...

ECM Project Manager - CMS, Document Management, Web 2.0

ECM Project Manager - CMS, "Document Management", Web...

PRESALES CONSULTANT/TECHNICAL CONSULTANT (CCNA, MCITP)

Skills - Presales, Consultant / Consultancy, Technical...

To send to more than one email address, simply separate each address with a comma.