CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementEasy

A penetration tester has compromised a Linux workstation and plans to establish a reverse shell back to their attacking machine. To blend in with normal network traffic and evade basic firewall rules, which common outbound port should the tester configure their reverse shell to use on the attacking machine?

  1. A21 (FTP)
  2. B3389 (RDP)
  3. C80 (HTTP)
  4. D22 (SSH)
Show answer & explanation

Correct answer: C. 80 (HTTP)

Port 80 (HTTP) is a common outbound port that is almost always allowed through firewalls for web browsing. Using this port for a reverse shell makes the traffic appear legitimate, helping to evade detection.

Why the other options are wrong

  • A. Port 21 (FTP) is often blocked outbound or monitored due to its cleartext nature.
  • B. Port 3389 (RDP) is primarily for inbound remote desktop and is rarely open outbound from internal workstations.
  • D. Port 22 (SSH) outbound is sometimes restricted or monitored, as internal hosts typically don't initiate many outbound SSH connections.

Reverse Shell Port Selection

Choosing a common, allowed outbound network port for a reverse shell connection to evade firewalls and blend with legitimate network traffic.

  • Aims to mimic normal user activity (e.g., web browsing).
  • Common choices include 80, 443, 53.
  • Helps bypass egress filtering and basic IDS/IPS rules.

Memory trick: To connect secretly, pick a port that's always open for traffic.

More Post-exploitation and Lateral Movement questions