Which TWO of the following steps are required to properly configure a multi-handler exploit listener for a reverse TCP payload?
Trap 1: Set RHOST to the target IP address
In a reverse TCP listener, the handler acts as a server waiting for an incoming connection, so setting RHOST is irrelevant. RHOST is typically used in exploit modules to define the destination target, but the handler module only needs to know where to bind locally for incoming connections.
Trap 2: Execute the exploit with the -e flag
The -e flag is not a standard command for the handler module. While encoding is a feature in Metasploit, it is handled during the payload generation phase, not by the handler listener. Adding this flag will cause the command to fail because the handler module does not recognize it.
Trap 3: Set the TARGET architecture to x64 only
While architecture is important, forcing x64 is not a requirement for a handler. The handler can accept connections from various architectures depending on the payload chosen. Restricting it to x64 would prevent successful connections from x86 targets, leading to failed exploitation attempts and unnecessary troubleshooting during the engagement.
- A
Set PAYLOAD to match the target architecture
The handler must be configured with the exact payload type used by the target's exploit to successfully stage the connection. If the payload in the handler does not match the payload executed on the target, the connection will be dropped immediately due to protocol mismatches during the staging phase.
- B
Set RHOST to the target IP address
Why it fails: In a reverse TCP listener, the handler acts as a server waiting for an incoming connection, so setting RHOST is irrelevant. RHOST is typically used in exploit modules to define the destination target, but the handler module only needs to know where to bind locally for incoming connections.
- C
Set LHOST and LPORT appropriately
LHOST defines the interface the handler will bind to, and LPORT defines the port to listen on. These must match the settings configured in the initial exploit payload sent to the victim. Incorrect settings here will cause the callback to fail because the target machine will attempt to connect elsewhere.
- D
Execute the exploit with the -e flag
Why it fails: The -e flag is not a standard command for the handler module. While encoding is a feature in Metasploit, it is handled during the payload generation phase, not by the handler listener. Adding this flag will cause the command to fail because the handler module does not recognize it.
- E
Set the TARGET architecture to x64 only
Why it fails: While architecture is important, forcing x64 is not a requirement for a handler. The handler can accept connections from various architectures depending on the payload chosen. Restricting it to x64 would prevent successful connections from x86 targets, leading to failed exploitation attempts and unnecessary troubleshooting during the engagement.