Tuesday, March 22, 2011

Metasploit framework, VxWorks

I decided to give the Metasploit framework a go today. It is used as a tool for penetration testing of servers, I'm going to run it against vanilla Ubuntu installations and post the results here. Should be interesting.

Also, has anybody out there ever tried to run VxWorks in a Xen VM? I presume there would be lots of difficulties - I suspect network support will be the first. VxWorks is a very interesting little OS, it is used for instance to run the Mars Exploration Rovers 'Spirit' and 'Opportunity', the BMW Idrive system, the Apache Longbow helicopter and Boeing airliners.

Update:  Ubuntu seems to be fine security-wise. None of the exploits I attempted gained root or, for that matter, even a user account on the server. But there are loads of them in Metasploit. To test them all would take an eternity.

