John the Ripper vs. Metasploit

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
John the Ripper
Score 8.0 out of 10
N/A
John the Ripper is a penetration testing tool used to find and crack weak passwords.N/A
Metasploit
Score 9.0 out of 10
N/A
Metasploit is open source network security software described by Rapid7 as the world’s most used penetration testing framework, designed to help security teams do more than just verify vulnerabilities, manage security assessments, and improve security awareness.N/A
Pricing
John the RipperMetasploit
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
John the RipperMetasploit
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
John the RipperMetasploit
Best Alternatives
John the RipperMetasploit
Small Businesses

No answers on this topic

No answers on this topic

Medium-sized Companies
Veracode
Veracode
Score 8.7 out of 10
Veracode
Veracode
Score 8.7 out of 10
Enterprises
Veracode
Veracode
Score 8.7 out of 10
Veracode
Veracode
Score 8.7 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
John the RipperMetasploit
Likelihood to Recommend
9.0
(0 ratings)
10.0
(0 ratings)
Support Rating
-
(0 ratings)
7.0
(0 ratings)
User Testimonials
John the RipperMetasploit
Likelihood to Recommend
It is best suited in those environments where complexity is not the key. We've used it fairly extensively in our UNIX to find weak UNIX passwords and in Windows environments too. It's very easy to get hold of as it is essentially Open Source, although a paid version is now available and we are thinking of looking at this proposition in-depth to see if it is viable. We found it easy to install and deploy across our systems. Patching was fairly regular, so we always had the latest version. It holds its own against DES and Blowfish encryption algorithms among many others.
Read full review
In security of information it's vital to think like a hacker and it's important to know the tools they use for attacks. So this software gives you the exploits that are already in the wild and to the access of everyone. That's very dangerous so you have to be aware of it.
Read full review
Pros
  • Easily finds plantect passwords.
  • Simply detects passwords hashes.
  • Has a fully bespoke cracker that can be modified to users requirements.
  • Excellent for UNIX and Windows usage.
Read full review
  • Scanning our network for new or existing vulnerable systems.
  • Automation of manual tests and exploits to allow what used to be days of effort to be squeezed into hours.
  • Metasploit has become an integral part in our validation of new systems before their inclusion in our production network.
Read full review
Cons
  • It needs to be modified to be able to break SHA 256, 512 and the lastest hashes.
  • Can be slow and wildly against the lastest hashes.
  • Require admin access to set up account.
  • Old and is being superseded by better applications.
Read full review
  • If Metasploit could support payloads written in languages other than Ruby, that would be amazing and could help draw in a larger set of contributors.
Read full review
Support Rating
No answers on this topic
We don't use it.
Read full review
Alternatives Considered
'John the Ripper' being open source was free to use, whereas the others had to be paid for. It was very simple to install and runs against many hundreds of hashes and crypts. It is always developing thanks to large communities on GitHub.
Read full review
Acunetix vulnerability scanner, Netsparker, SQLMap
Read full review
Return on Investment
  • Helped us achieve initial Password Auditor goals and targets.
  • Simple and cheap to deploy, so have saved greatly compared to paid for products.
Read full review
  • We have been able to weed out false positives with a more manual vetting of scanned vulnerabilities.
  • Our teams have become more well versed in penetration testing with Metasploit to understand the vulnerabilities potentially present.
Read full review
ScreenShots