CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium
A tester generates a reverse shell payload using msfvenom targeting a Windows host and configures a listener before delivering the payload. Which Metasploit component must the tester configure to receive the incoming connection once the payload executes?
- Aexploit/multi/handler
- Bpost/windows/gather module
- Cauxiliary/scanner module
- Dencoder module
Show answer & explanationAnswer & explanation
Correct answer: A. exploit/multi/handler
The exploit/multi/handler module is used in Metasploit to set up a listener that matches the payload type, LHOST, and LPORT configured in the msfvenom-generated payload, allowing the tester to catch the reverse connection.
Why the other options are wrong
- B. Post-exploitation gather modules run after a session is established, not to catch the initial connection.
- C. Auxiliary scanner modules are used for reconnaissance, not catching shells.
- D. Encoder modules obfuscate payloads to evade detection, not handle connections.
Metasploit Multi/Handler
A Metasploit module used to set up a listener that matches a standalone payload (e.g., generated by msfvenom) to catch the resulting session.
- Must match payload type, LHOST, and LPORT exactly
- Commonly used with msfvenom-generated standalone payloads
- Run within msfconsole using exploit/multi/handler
Memory trick: Handler is the catcher's mitt waiting for the pitched payload.