Lateral Movement & Pivoting

Navigate through isolated network segments using advanced pivoting techniques. Master SSH tunneling, dynamic port forwarding with Proxychains, and Metasploit autorouting to reach internal targets.

Cybersecurity EngineerCybersecurityKali LinuxLinux

Introduction

Pivoting uses a reachable host as the path to services on a network that the operator cannot contact directly. This course develops that concept through SSH local, remote, and dynamic forwarding; Proxychains; and Metasploit autorouting across isolated Docker networks.

You will build working tunnels to prepared internal web services, route curl and Nmap through SOCKS proxies, and compare an SSH pivot with a Meterpreter-aware Metasploit route. The final challenge asks you to construct the SSH/Proxychains path independently, enumerate an internal Redis service, and retrieve staged data.

What You Will Learn

  • Interpret a simulated bastion, local service, and private-network topology.
  • Configure SSH local forwarding to make an internal service available on a loopback port.
  • Configure SSH remote forwarding to expose a local service from the bastion side.
  • Create an SSH dynamic SOCKS5 proxy and route curl through it with Proxychains.
  • Adapt Nmap to a SOCKS path by using TCP Connect scanning and disabling ping discovery.
  • Establish a local Meterpreter session, add Metasploit autoroutes, and expose them through a SOCKS4a proxy.
  • Build a custom Proxychains configuration and query a prepared internal Redis key in the final challenge.

Who This Course Is For

This intermediate course is for security learners who understand SSH, TCP services, and basic network segmentation and want hands-on pivoting practice. It suits aspiring penetration testers, red team learners, and defenders who need to reason about tunnels, proxy-aware tools, dual-homed footholds, and hidden service exposure.

Prerequisites: Comfort with a Linux terminal, SSH keys and port-forwarding syntax, IP addresses, subnets and TCP ports, curl and Nmap, plus basic Metasploit and Meterpreter session concepts.

Learning environment: An Ubuntu 22.04 terminal with Docker-based bastion and internal-service containers, a provided SSH private key, Proxychains, Nmap, Redis CLI, and Metasploit. The lab uses private container networks and loopback ports; several exercises require two terminal tabs and background tunnels.

Frequently Asked Questions

Are the bastion and internal targets separate real machines?

They are separate Docker containers and private container networks inside the lab environment. This provides working routing boundaries and hidden services without connecting to an external corporate network.

Why does Nmap require -sT -Pn through Proxychains?

SOCKS proxies carry full TCP connections, not raw SYN packets or ICMP echo requests. -sT uses TCP Connect scanning, and -Pn prevents failed ping discovery from incorrectly marking the target as down.

How does Metasploit autorouting differ from SSH dynamic forwarding?

SSH -D creates a SOCKS proxy through an SSH server. Metasploit autoroute associates internal subnets with an active Meterpreter session; a separate Metasploit SOCKS module makes that session-aware route available to external tools.

Does the final challenge exploit a Redis software vulnerability?

No. You discover a prepared Redis service on port 6379 and use redis-cli through the pivot to read the secret_flag key. The security issue demonstrated is an unauthenticated internal database exposed behind network-only trust.

Teacher

labby
Labby
Labby is the LabEx teacher.