A penetration tester's initial exploitation attempts using a staged Meterpreter payload consistently fail because the target network's firewall terminates outbound connections before the second stage can be downloaded. Which type of payload should the tester select to overcome this issue?
- AA staged payload such as windows/meterpreter/reverse_tcp
- BA NOP generator payload
- CA stageless payload such as windows/meterpreter_reverse_tcp
- DAn auxiliary scanner module
Show answer & explanationAnswer & explanation
Correct answer: C. A stageless payload such as windows/meterpreter_reverse_tcp
Stageless (single) payloads, denoted with an underscore in Metasploit naming (e.g., windows/meterpreter_reverse_tcp), embed the entire payload in one package so no second-stage download is required, making them resilient to firewalls that block staged transfers. Staged payloads rely on downloading a second component, which fails under this restriction; auxiliary modules and NOP generators are unrelated to this problem.
Why the other options are wrong
- A. This is the staged payload that is failing due to the firewall blocking the second stage.
- B. NOP generators are used for buffer padding in exploit development, not payload delivery reliability.
- D. Auxiliary modules perform scanning/enumeration, not code execution delivery.
Staged vs. Stageless Metasploit Payloads
Staged payloads send a small stager that downloads the full payload afterward (slash notation), while stageless payloads deliver the entire payload in a single package (underscore notation).
- Staged: windows/meterpreter/reverse_tcp
- Stageless: windows/meterpreter_reverse_tcp
- Stageless payloads are larger but more firewall-resilient
Memory trick: Underscore = 'Un-staged' — one solid package, no second delivery truck