Exploitation with Metasploit Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Exploitation with Metasploit flashcards as text
Which Metasploit auxiliary module is commonly used to perform a TCP port scan?
Answer: auxiliary/scanner/portscan/tcp
auxiliary/scanner/portscan/tcp performs a full TCP connect scan against specified hosts and port ranges.
What is a 'staged' payload in Metasploit?
Answer: A small first-stage stager that downloads the larger payload from the attacker
Staged payloads use a small stager component to connect back and download the full payload (stage), reducing initial shellcode size.
Which msfvenom encoder is commonly used to obfuscate payloads for basic AV evasion?
Answer: x86/shikata_ga_nai
x86/shikata_ga_nai is a polymorphic XOR additive feedback encoder widely used to encode Metasploit payloads.
What Meterpreter command shows information about the current user on the compromised target?
Answer: getuid
'getuid' returns the user account that the Meterpreter session is running as on the target system.
In Metasploit, what does RHOSTS refer to when configuring an exploit?
Answer: The target host(s) to exploit
RHOSTS specifies the remote (target) host or hosts that the exploit or auxiliary module will run against.
Which post-exploitation Meterpreter command can be used to record keystrokes on the target?
Answer: keyscan_start
'keyscan_start' begins a keylogger on the target and 'keyscan_dump' retrieves the captured keystrokes.
What is the function of the Metasploit module 'exploit/multi/handler'?
Answer: Listens for incoming connections from reverse payloads
exploit/multi/handler is a generic listener that catches reverse shell callbacks from any payload executed on a target.