ZeroBox

Pivoting and Tunneling: practice machines and key commands

Pivoting uses a compromised host as a relay into networks you cannot reach directly. The simplest tool is SSH: -L forwards a local port to an internal service, -R exposes a port from the target back to you, and -D creates a SOCKS proxy that proxychains can use for scanners. When SSH is not available, Chisel and Ligolo-ng provide reverse tunnels over a single outbound connection, and Windows hosts can use netsh portproxy. Scan through the tunnel with full connect scans, since SYN scans do not traverse SOCKS. Map the internal subnets with ip a and arp, then repeat enumeration on each new segment. Keep a diagram of which tunnel leads where. The boxes listed require reaching a second network.

Key commands

Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.

SSH Dynamic Port Forwarding (SOCKS5)

Open a local SOCKS5 proxy on port 1080 routed through target SSH host.

ssh -D 1080 -f -C -q -N {USER}@{TARGET_IP}

SSH Local Port Forwarding (-L)

Forward target internal port (e.g. 8443) to local port 9999 on attacker machine.

ssh -L 9999:127.0.0.1:8443 {USER}@{TARGET_IP} -N

SSH Reverse Remote Forwarding (-R)

Expose local port or listener on compromised host back to attacker machine.

ssh -R {LPORT}:127.0.0.1:80 {USER}@{LHOST} -N

Chisel Attacker Reverse Tunnel Server

Start Chisel reverse tunnel listener on attacker machine on port 8000.

./chisel server -p 8000 --reverse

Chisel Victim Reverse Socks Pivot

Connect back to attacker server and open socks5 proxy port 1080 to access internal network.

./chisel client {LHOST}:8000 R:socks

Ligolo-ng High-Performance TUN Interface Pivot

Fast userland tunnel creating real system tun adapter for seamless Nmap/Metasploit routing.

# On Attacker:
sudo ip tuntap add user $(whoami) mode tun ligolo
sudo ip link set ligolo up
./proxy -selfcert -laddr 0.0.0.0:11601

# On Compromised Host:
./agent -connect {LHOST}:11601 -ignore-cert

# Add route on Attacker:
sudo ip route add 172.16.1.0/24 dev ligolo

Proxychains TCP Full Connect Nmap Scan

Route Nmap port scan through SOCKS proxy tunnel to scan internal networks.

proxychains4 -q nmap -sT -Pn -p 21,22,80,445,3389,8080 172.16.1.10

Keep going

Pivoting and Tunneling machines (25)

Machines are matched by their technique tags. 20 Linux, 5 Windows.

Very Easy (1)

MachinePlatformOSTags
FunnelHTBLinuxSSH, Port Forwarding, PostgreSQL, Tunneling

Easy (7)

MachinePlatformOSTags
AlertHTBLinuxCPTS, Markdown XSS, LFI, Port Forwarding
BuffHTBWindowsBuffer-Overflow, HTB, Port-Forwarding, Unauthenticated-RCE
ChemistryHTBLinuxCPTS, CIF Parser, Python, Pivoting
HorizontallHTBLinuxCVE-2019-18818, CVE-2019-19609, CVE-2021-3129, HTB
PCHTBLinuxCPTS, gRPC, SQL Injection, Pivoting
SeaHTBLinuxCPTS, SeaCMS, XSS, Pivoting
SightlessHTBLinuxCPTS, SQLPad, Chrome DevTools, Pivoting

Medium (8)

MachinePlatformOSTags
BagelHTBLinuxCPTS, LFI, Spring Boot, .NET Deserialization
FlightHTBWindowsCPTS, Active Directory, Pivoting, Responder
FormatHTBLinuxCPTS, LFI, Nginx Traversal, Redis
Lateral Movement and PivotingTHMWindowsActive Directory, Pivoting, Lateral Movement, WMI
Only4YouHTBLinuxCPTS, Cypher Injection, Neo4j, Pivoting
SandwormHTBLinuxCPTS, SSTI, Sandbox Escape, Firejail
SharedHTBLinuxCVE-2022-0543, CVE-2022-21699, HTB, Port-forwarding
SurveillanceHTBLinuxCPTS, Craft CMS, ZoneMinder, Pivoting

Hard (8)

MachinePlatformOSTags
BorderlandsTHMLinuxPivoting, API, Docker
ForwardSlashHTBLinuxBash-Scripting, Blind-XXE, HTB, Pivoting
InternalTHMLinuxWordPress, Tunneling, Jenkins, Docker-Breakout
RainyDayHTBLinuxDocker/Host-shared-PIDs, HTB, Python, Tunneling
ThrowbackTHMWindowsActive Directory, Red Team, Network, C2
VulnNet: InternalTHMLinuxSMB, Redis, TeamCity, Tunneling
WreathTHMWindowsActive Directory, Pivoting, Chisel, Empire
Year of the FoxTHMLinuxCommand-Injection, Port-Forwarding

Insane (1)

MachinePlatformOSTags
ReddishHTBLinuxHTB, Tunneling

Related techniques

Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox