Nepenthes: Netpens With Less Pain

Presented at ToorCon San Diego 16 (2014), Oct. 25, 2014, 11 a.m. (50 minutes)

Nepenthes is an open-source tool for managing network penetration tests, with a focus on external tests with large numbers of hosts; in particular web-heavy networks. Nepenthes can manage different network based scans in parallel; anything from grabbing SSL information and taking screenshots to standard nmap scans. It uses a queueing and scheduling system to allow off-hours scans, scheduled from anywhere around the world. Scans can be performed from as many hosts as desired, including using public clouds. With a web frontend, Nepenthes makes it easy for multiple team members to collaborate on a test, allowing for easy extraction of desired information. A flexible worker system and easy Rails extensibility make Nepenthes easy to modify, as has been done for several tests at Matasano. These features are usually included in future tests to make the experience even better. This presentation will be a tour of the reasons for Nepenthes’ existence (the need for a high-capacity scanner and a workflow that combines data from different tools), its features, a demonstration, and information on how to get, install, and extend Nepenthes. The talk will assume some familiarity with external network penetration tests and tools, but no specific knowledge is strictly necessary.


Presenters:

  • Andy Schmitz
    Andy is currently a security consultant with Matasano. He has years of experience in secure software development, research, protocol design/analysis, and system design/administration. Before Matasano, Andy has worked with groups from large organizations like Motorola to small startups, developing applications and performing tests. He completed Bachelor’s degrees in Mathematics and Computer Science with a specialization in Security at the University of Illinois in Urbana-Champaign. Andy has over a decade of development experience, including desktop and web applications.

Similar Presentations: