cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3402
Views
9
Helpful
6
Replies

IPS testing with metasploit

josephium
Level 1
Level 1

Hi,

can anyone give a sample or a detailed example on how to test IPS with metasploit, no exploit is really working or triggering anything.

thanks

6 Replies 6

mhellman
Level 7
Level 7

I would focus on creating an environment where metasploit actually works (i.e. you can exploit an unpatched box). Then you can focus on IDS.

yes, but can anyone give a sample or a detailed example on how IPS stops a working exploit with metasploit or any other software

easiest is to reverse engineer the signature details and craft packets based on the Sig RegEx for example.

For example, if a SIG is inspecting packets for "DNS" in traffic over 53/tcp, crafting a packet with this info will trigger the IPS...

I have used metasploit to trigger alarms in promiscuous mode, but not inline. It's pretty much the same though. Get metasploit working. go through the list of available metasploit exploits and choose one that is:

1) exploitable on the test machine

2) detected by Cisco IPS

Test the exploit without IPS. One you have verified that it is working(during my test, I was creating a local user on a Windows box), test the exploit with IPS.

 

Hi buddy,

 

what type of Cisco Systems Cisco Intrusion Prevention System (IPS) do you want to exploit?

 

So, about what IDS you are talking about? Cisco MARS or just Ettercap NG filters?   

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card