Rapid7 Vulnerability & Exploit Database

CarotDAV credential gatherer

Back to Search

CarotDAV credential gatherer



PackRat is a post-exploitation module that gathers file and information artifacts from end users' systems. PackRat searches for and downloads files of interest (such as config files, and received and deleted emails) and extracts information (such as contacts and usernames and passwords), using regexp, JSON, XML, and SQLite queries. Further details can be found in the module documentation. This is a module that searches for credentials stored on CarotDAV FTP Client in a windows remote host.


  • Jacob Tierney
  • Kazuyoshi Maruta
  • Daniel Hallsworth
  • Barwar Salim M
  • Z. Cliffe Schreuders




Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':

Time is precious, so I don’t want to do something manually that I can automate. Leveraging the Metasploit Framework when automating any task keeps us from having to re-create the wheel as we can use the existing libraries and focus our efforts where it matters.

– Jim O’Gorman | President, Offensive Security