HTB – Arctic – FH: Metasploit

Foot-hold: Metasploit module allowing arbitrary file uploads

After quite a bit of enumeration, it looks as though the script used to do the file uploads are run by metasploit. At this time, I am attempting to avoid metasploit completely on these training boxes. The OSCP exam does not allow metasploit, therefore I don’t want to get into a habit of using it.

Moving on to the next box…



