3 min
Events
Metasploit Open Source Office Hours: Vegas 2019
The Metasploit crew at Rapid7 is headed out to Las Vegas for DEF CON 27,
bringing a new incarnation of the Open Source Security Meetup (OSSM) with us! We
will have a Metasploit Suite at Bally’s this year, where we’ll be hosting “Open
Source Office Hours” (OSOH). If you’ll be out in Vegas for DEF CON 27, take a
moment and ask yourself:
* Are you currently working on a Metasploit module/payload and could use some
guidance?
* Are you modifying Framework and you’d like to discuss?
* Are you w
2 min
Events
Rapid7’s Partner Summit 2019: Thank You to Our Partners in EMEA!
We recently hosted our hugely successful EMEA Partner Summit 2019 in Portugal, meeting with over 85 partners from over 27 countries all around Europe, the Middle East, and Africa.
3 min
Vulnerability Disclosure
R7-2019-01: CircuitWerkes Sicon-8 Client-Side Authentication Read-Only Bypass (CVE-2019-5616)
The Sicon-8 ships with a web-based front-end controller and implements an authentication mechanism in JavaScript that is run in the context of a user’s web browser.
4 min
AWS
Seeing Security Scale: Rapid7’s Recap of AWS re:Invent 2018
In this post, I will detail my time at AWS re:Invent and provide observations about how security plays a role in our cloud journey.
2 min
Metasploit
Congrats to the 2018 Metasploit Community CTF Winners
After three days of fierce competition, we have the winners of this year's
Metasploit community CTF
[https://www.rapid7.com/blog/post/2018/11/05/announcing-the-2018-metasploit-community-ctf/]
. We've included some high-level stats from the game below; check out the
scoreboard. If you played the CTF this weekend and want to let the Metasploit
team know which challenges you found exhilarating, interesting, or infuriating
(in a good way, of course).
Congratulations to everyone who teamed up with
2 min
Metasploit Weekly Wrapup
Metasploit Wrapup: 9/28/18
Trevor Forget: Metasploit Town Hall @ Derbycon
Metasploit’s Brent Cook [/author/brent-cook], Adam Cammack
[/author/adam-cammack], Aaron Soto [/author/aaron], and Cody Pierce are offering
themselves up to the crowds at this year’s fourth annual Metasploit Town Hall at
Derbycon [https://www.derbycon.com/]. Heading to bourbon country next weekend?
Block off your 5 PM hour on Saturday, October 6 to join the team as they unveil
some new hotness in Metasploit Framework and take questions and requests
4 min
Events
A Tale of Security Summer Camp: Rapid7's 2018 Recap of Black Hat and Beyond
From conference talks and business hall exhibitions to security trainings and personal conversations, the big takeaway from the past week was undeniable. Our industry is at an inflection point, and everyone is focused on a common theme: unification.
4 min
Events
UNITED Summit: Day 2
After a jam-packed day one of Rapid7’s UNITED Summit
[/2017/09/13/united-summit-day-1/], the UNITED running club started the day
bright and early yet again.
The rest of us opened UNITED [https://unitedsummit.org/index.php] day two with a
fireside chat hosted by Jen Ellis [/author/jen-ellis], Rapid7 VP of Community
and Public Affairs, and a slew of prominent security commentators: Lares founder
Chris Nickerson [https://twitter.com/indi303], Mach37 Cyber’s
[https://twitter.com/MACH37cyber] man
2 min
Events
Rapid7 Rapid Fire at UNITED Summit: A Spirited Debate
Rapid Fire returned for the third time to the UNITED Security Summit and once
again brought together the infosec community to join the spirited debates. With
great questions and participation from the audience, the Rapid7 team would like
to first thank everyone who attended this evening – from our customers and
UNITED attendees, to the Boston infosec community.
Our panel this year featured:
* Josh Corman @joshcorman [https://twitter.com/joshcorman] (Founder, I am The
Cavalry)
* David Kenn
13 min
Vulnerability Disclosure
Multiple Disclosures for Multiple Network Management Systems, Part 2
As you may recall, back in December Rapid7 disclosed six vulnerabilities
[/2015/12/16/multiple-disclosures-for-multiple-network-management-systems] that
affect four different Network Management System (NMS) products, discovered by
Deral Heiland [https://twitter.com/percent_x] of Rapid7 and independent
researcher Matthew Kienow [https://twitter.com/hacksforprofit]. In March, Deral
followed up with another pair of vulnerabilities
[/2016/03/17/r7-2016-02-multiple-vulnerabilities-in-mangeengine-opu
6 min
Events
Rapid7 Takes Las Vegas: Black Hat, BSidesLV & DEF CON ... Talks, Parties & Giveaways... phew!
First things first:
You must be registered & confirmed to be able to attend our 2015 Black Hat
party. [http://bit.ly/Rapid7BH15]
I can't emphasize this enough: Unlike previous years, we are not doing any kind
of at-the-door registration for our party this year.
If your plan was to live in the spirit of utter spontaneity, roll up to the club
and see if you can happen to get in without registering beforehand -- you're
going to be disappointed, and we really don't want to see that happen! While w
4 min
Events
The Black Hat Attendee Guide Part 5a - The Magic of People
Joining us for the first time? This post is part of a series that starts right
here [/2015/07/13/the-black-hat-attendee-guide-part-1].
So this post is a bit of a bonus. I've asked my dear friend Quinton Jones
[https://www.linkedin.com/in/quintonjones] to share some wisdom and inspiration
on how he injects passion and energy into his introductions. He's simply
unforgettable, one of the greatest customer champions and business development
folks I know, thanks to his passion for people. Please enj
3 min
Metasploit Weekly Wrapup
Weekly Metasploit Wrapup: T-Shirts, T-Shirts, & Some Modules
Black Hat T-Shirts!
Well, it's a week or so until DEF CON 23, and since you're all busy prepping all
your demos and presentations and panels and things, I figured I should remind
you that among all your gear, you should probably toss some clothes in your bag
before you head out the door. In case this slips your mind, though, don't sweat,
we have you covered.
Pictured at right is the winning design from the annual Metasploit T-Shirt
contest, submitted by LewisFX
[https://99designs.com/t-shirt-
5 min
Events
The Black Hat Attendee Guide Part 7a: Electronic Survival
If you're just joining us, this post is part of a Black Hat Attendee Guide
series that starts right here [/2015/07/13/the-black-hat-attendee-guide-part-1]
.**
When traveling to industry conferences, most people prepare their electronic
companions (laptops, cell phones, etc) by asking: “Did I pack the right charger
in my carry on?”
The premier gathering of the world's best and brightest hackers might be a great
opportunity for you to up your travel security game. This post serves as a quick
gui
5 min
Events
The Black Hat Attendee Guide Part 7: Your Survival Kit
Joining us for the first time? This post is part seven of a series that starts
right here [/2015/07/13/the-black-hat-attendee-guide-part-1].
Hacker Summer Camp is no joke, and you've got to have a game plan when you head
for Vegas. If you don't travel frequently, this is for you.
Ignoring sartorial conundrums and basic hygiene, this post is focused on keeping
your body operating at peak… or at least somewhat operational.
Vegas: It's nothing like home for most of us. Desert allergens, low humi