Data reconnaissance

In this phase, information related to the target is gathered using a crawler, proxies, and any other sources. The data is then saved in the MSF database for further use. The data can be fetched using any third-party tool, such as Burp Suite or Acunetix. The data can be imported into MSF using the db_import command as MSF supports many third-party tools. Let's look at an example of how a Burp scan can be imported into Metasploit.

The following screenshot shows the output of the db_import command:

The following are the steps to export the Burp Suite data and import it into Metasploit:

  1. Open up a previously completed scan ...

Get Hands-On Web Penetration Testing with Metasploit now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.