I recently attended a SANS conference and picked up a cool looking boot CD brandishing the Inguardians logo. I wanted to know more so i hit up my favorite web hacking guru Kevin Johnson, he forwarded the scoop to me from the IG team, neat little disk:

What is redpill/bluepill?

Thanks for your interest in the redpill/bluepill. The redpill/bluepill DVD’s were special projects produced as exclusive gifts for SANS and Shmoocon attendees. Currently we do not have plans to release the images to the general public, but we do have SAMURAI Special Edition CD’s on the way! Also, definitely check out our tools & projects out at http://inguardians.com/tools/ as we often release new items.

Redpill/Bluepill is a dual-sided, bootable linux environment on DVD. The redpill side focuses on attack tools, and the bluepill side picks up the defense. Both sides include numerous tools written by InGuardians agents. The name, of course, is a reference to our corporate obsession with the Matrix.

How was it conceived?

I am not sure of the original idea creator but I believe it was Mike Poor. The first I heard was when we were in New Orleans teaching for SANS. One of the evenings after much good food at Arnaud’s, Mike and I were talking in the lobby about various projects I needed to work on. (Yes Mike is my amazing and wonderful boss (Nudge nudge during review time Mike!)) We started discussing the idea of creating a live environment to show off some great tools and be something we could hand out at cons. This was specifically for Shmoocon that year.

Is it a current project or abandoned?

It is a current project as we create new versions quite often. I actually just submitted the new image to the duplicators a week or so ago.

Redpill says “we’ve added a number of our own attack tools” , can you tell us about any “new hotness” on this distro?

We included a number of tools, some of which were ours. For example most of the tools by Matt Carpenter are included. The exact tool configuration depends on the version you have. the next version will contain Laudanum and Middler.

Is Bluepill fit for incident handling/response?

Yes definitely. We actually use it some of our jobs.

How does it compare to say… backtrack 4? Does it include different tools/frameworks/scripts etc?

We haven’t really compared it as it wasn’t designed to be a regularly released project. Backtrack is DEFINITELY better designed and maintained for use during a pen-test. Redpill/bluepill is just a fun cool environment that may meet your needs during a time.

It’s pretty packaging, it’s put together by the best in the industry, do you guys use it yourselves for pentests? Or do you leverage multiple self made distros?

It is one of the distros we use. Depends on the test. For example, web tests we use SamuraiWTF.

Easter eggs huh? What can we expect from the inguardians crew?

Just funky stuff like recipes, goofy pictures and the like. This group of people is one of the most insane yet talented groups of people I have ever worked with. I think it has to do with the amazing knowledge they have built up. ;-) (Of course I am biased.)

Anything else you can let us know about this little gem?

Should I mention that if you boot it, you machine joins the world-wide InGuardians botnet? Nah, lets have that be a surprise. Just kidding. I say let them explore and see what they find. If they try any of the recipes (at their own risk), we would love to hear what they thought of them.

Can anyone join or contribute ideas to the project?

We always accept new ideas. For now, I would prefer that people contribute to the SamuraiWTF project, which needs constant innovation to continue to be on the cutting-edge of web application testing.