Navigation

Entries by Carlos Perez (157)

Thursday
Nov262009

Happy Thanksgiving

Well it is that time of year where we celebrate before Christmas and give thanks for what we have, last December I decided to get back on the security horse and contribute and it has been one of the best experiences of my life. I decided to contribute with tools, information and get again involved with security and it has been a blast the main point for whish I'm so greatly grateful for have been:

  • Becoming part of the Pauldotcom Crew
  • Presenting and attending on my first Defcon
  • Becoming a Developer in the Metasploit Framework
  • Working with the Offensive-Security.org guys
  • The feedback on my tools and this Blog

I do have to say this year has been a blast, some downfall but on what I proposed to my self it has been way way more than what I expected to achieve. Guys hard work does pay off, happy thanksgiving and have fun.

Saturday
Nov212009

I'm Still Alive

Sorry for nost posting in a long while I have been very busy lately. I'm working on new material, update existing and will be posting on a regular basis soon.

Wednesday
Oct212009

Opinions of a Contributor to Metasploit about the sale to Rapid7

Let me start by saying that this are the opinions of a contributor. To this day I have contributed to the project 3 Auxiliary Modules and 16 Meterpreter scripts to the project and I had the honor and privilege to present with HD in Defcon 17 in the Metasploit Trac. I was initially in shock when I saw the news on my iPhone while stuck in traffic, when I saw the news I could not believe it, I thought it was a joke. When I got to my office I quickly checked the web pages and listen to the Risky Business Podcast where they interviewed about the acquisition and read all of the tweets of people in favor and against it, their worries, rants and comments. After all of this I mentioned,I came to the conclusion that this is a great thing for the project for a lot of time this project has been the labor of love of the members of the Metasploit project, with very few active committers and summiteers other than a handful, each putting of their own free time, sacrificing long nights, family time and money to work on the project. Some wrote code to scratch their own itch and solve problems they had others just did it for the same motivation that have pushed hackers everywhere to write code, the fun of creating something and learning how stuff works. In my case I stopped doing penetration tests and security audits many years ago and in December of last year decided to get back in to the game by sharing stuff in my blog, forums and turning a lot of the stuff I knew in to tools and scripts, in that process I started writing code for Metasploit and I never found in any other project a community so patient and willing to help. HD has given me tips that made me a better coder, he was always patient and cotius with me and other contributors, the members of the team have also always been helpful like Natron, ET, Chris Gates and MC with each piece of code I wrote (which many time was ugly as hell). HD is now a father and as a dad also of little girl I know how hard it is to spend time coding to contribute to a community and sacrifice the precious time one has with something as precious as ones own child, what he did will give him more time to spend with his family and still work on the project he loves as well as for some of the members of the Metasploit team. Here is a list of the advantages I see:

  • Code will have dedicated dev team to work on it.
  • More stable code base since more resources for testing will be available.
  • More exploits and features to come faster since there will be a dedicated team.
  • The side effect that other projects like Canvas, Core Impact and others will have a stronger competitor thus making them better their products even more.
  • Support for pentester and others that use the framework.

The fears I have seen express by many have been:

  • The code going private and closed source.
  • That many of the cool features and exploits will be charged for by Rapid7
  • That the community will disappear.

To this  I answer, HD has put long hours and money to fund this project by himself, he has expressed that he will continue to keep the project open source as well as support the community and to this I say he has more than earned our support and trust. I trust HD and keep him to his word. The project is under BSD license so the same community that has made Metasploit grow can fork it and keep it going, but for now my trust is on HD and the Dev team. So lets keep supporting the project by contributing, testing the code, reporting bugs and make this and even better framework. I do say I envy HD and Egyp7 from the team, they are now working full time on what they love so I say to them and the rest of the Metasploit team congratulations and my best wishes.

Tuesday
Sep082009

Tactical Meterpreter Scripting Defcon 17 Presentation Video

Special Thanks to Chris John Riley for getting me the video, the Pauldotcom Crew for their support and to HD for giving me the oportunity to present. I hope you guys enjoy it. My english was very bad it was a bit rushed since Adam Savage from Mythbusters took some time from the Metasploit track allocated time and we had to rush it a bit to be able to present all the material.

Defcon 17 Tactical Meterpreter Scripting from Carlos Perez on Vimeo.

 

Monday
Aug242009

DEFCON 17 Materials

My presentation and sample functions are in presentationsection of the website, take a look and let me know if you like it.