CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium

A penetration tester is conducting an internal network assessment. They identify a critical server that is not patched against the 'EternalBlue' vulnerability (CVE-2017-0144). The tester decides to use Metasploit to exploit this vulnerability. Which Metasploit module would be the most appropriate to use for gaining initial access to the vulnerable server?

  1. Apost/windows/gather/enum_logged_on_users
  2. Bexploit/multi/handler
  3. Cauxiliary/scanner/smb/smb_ms17_010
  4. Dexploit/windows/smb/ms17_010_eternalblue
Show answer & explanation

Correct answer: D. exploit/windows/smb/ms17_010_eternalblue

The `exploit/windows/smb/ms17_010_eternalblue` module is specifically designed to exploit the EternalBlue vulnerability (MS17-010) on Windows systems via SMB, making it the most appropriate choice for gaining initial access.

Why the other options are wrong

  • A. `post/windows/gather/enum_logged_on_users` is a post-exploitation module used for information gathering after initial access has been established.
  • B. `exploit/multi/handler` is a generic handler for receiving reverse shell connections, not an exploit module itself.
  • C. `auxiliary/scanner/smb/smb_ms17_010` is a scanner module used to check for the vulnerability, not to exploit it.

Metasploit Exploit Modules

Metasploit Framework modules designed to take advantage of specific vulnerabilities in target systems to gain unauthorized access or execute code.

  • Categorized by target OS and service (e.g., windows/smb).
  • Used for initial access and privilege escalation.
  • Often paired with payloads to define post-exploitation actions.

Memory trick: Exploits attack, auxiliaries assist, payloads perform, and posts process.

More Attacks and Exploits questions