Article 3ETM8 Threat or menace? “Autosploit” tool sparks fears of empowered “script kiddies”

Threat or menace? “Autosploit” tool sparks fears of empowered “script kiddies”

by
Sean Gallagher
from Ars Technica - All content on (#3ETM8)
GettyImages-179270334-800x492.jpg

Enlarge (credit: Kirillm / Getty Images)

The tools used by security researchers, penetration testers, and "red teams" often spark controversy because they package together, and automate, attacks to a degree that make some uncomfortable-and often, those tools end up getting folded into the kits of those with less noble pursuits. AutoSploit, a new tool released by a "cyber security enthusiast" has done more than spark controversy, however, by combining two well-known tools into an automatic hunting and hacking machine-in much the same way people already could with an hour or two of copy-pasting scripts together.

Malicious parties have weaponized scanning utilities, network commands, and security tools with various forms of automation before. By "stress testing" tools such as "Low-orbit Ion Cannon" (LOIC), High Orbit Ion Cannon (written in RealBasic!), and the Lizard Squad's stresser site powered by hacked Wi-Fi routers, they took exploits known well to security pros and turned them into political and economic weapons. The Mirai botnet did the same with Internet of Things devices, building a self-spreading attack tool based on well-documented vulnerabilities in connected devices.

AutoSploit is slightly more sophisticated but only because it leverages two popular, well-supported security tools. "As the name might suggest," its author wrote on the tool's GitHub page, "AutoSploit attempts to automate the exploitation of remote hosts." To do that, the Python script uses command line interfaces and text files to extract data from the Shodan database, which is a search engine that taps into scan data on millions of Internet-connected systems. AutoSploit then runs shell commands to execute the Metasploit penetration testing framework.

Read 16 remaining paragraphs | Comments

index?i=b6hg_VYeAFk:Zn-LBkL5gc0:V_sGLiPB index?i=b6hg_VYeAFk:Zn-LBkL5gc0:F7zBnMyn index?d=qj6IDK7rITs index?d=yIl2AUoC8zA
External Content
Source RSS or Atom Feed
Feed Location http://feeds.arstechnica.com/arstechnica/index
Feed Title Ars Technica - All content
Feed Link https://arstechnica.com/
Reply 0 comments