CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementEasy
A penetration tester has compromised an endpoint and wants to establish a reverse shell to their C2 server. The target network has strict egress filtering that only allows outbound traffic on ports 80, 443, and 53. To maximize the chances of success while blending in with legitimate traffic, which port should the tester configure their C2 listener to use?
- A21 (FTP)
- B22 (SSH)
- C3389 (RDP)
- D443 (HTTPS)
Show answer & explanationAnswer & explanation
Correct answer: D. 443 (HTTPS)
Port 443 (HTTPS) is a commonly allowed outbound port for legitimate web traffic. While port 80 (HTTP) is also allowed, 443 often has less scrutiny and can carry encrypted traffic, making a reverse shell on this port stealthier and more likely to succeed through egress filters.
Why the other options are wrong
- A. Port 21 is typically blocked by egress filters and is not among the allowed ports.
- B. Port 22 is typically blocked by egress filters and is not among the allowed ports.
- C. Port 3389 is typically blocked by egress filters and is not among the allowed ports.
Reverse Shell Port Selection
Choosing an appropriate port for a reverse shell listener on the C2 server, considering network egress filtering rules and the need to blend in with legitimate traffic.
- Commonly allowed outbound ports include 80, 443, and 53.
- Using a well-known port (like 443) increases the chance of bypassing firewalls.
- Encrypting traffic on allowed ports further enhances stealth.
Memory trick: HTTPS port 443 is the stealthy door to C2.