Skip to content

Lab 2.3 : Pivoting and Redirection

Objectives

  • Use SSH to access a network
  • Create an SSH forward tunnel to access an internal resource
  • Use dynamic port forwarding to create a SOCKS server
  • Create an SSH reverse tunnel to listen for a connection
  • Chain SSH connections to traverse network segments

This lab will focus on the use of pivoting and redirection to route traffic through hosts. On the Slingshot Linux VM there is a miniature network created with Docker. You will access the network with SSH and then create tunnels to access resources in different network segments.

TTPs Emulated in this Lab

On Your Own

  1. SSH to the bastion host
  2. Request the website at 10.199.2.120 through the bastion host
  3. Pivot to 10.212.243.13 through the bastion with a forward tunnel to port 22
  4. Catch the beacon on pivot-1 on port 58671
  5. Find the port for the FTP Server on 10.212.243.13
  6. Review the walkthrough

Walkthrough

SSH to Bastion

1. First we need access to the network, access is protected with a bastion host. In certain network configurations, the bastion host is hardened and available on the public internet. The key is to configure this host to have as little attack surface as possible, resiliency to internet traffic, and to perform authentication on incoming connections.

Open up three terminal windows and change directories to the lab folder in each one.

cd /labs/sec-2/pivoting

Restart the docker service, we are forcing a restart of the docker service because it may get out of sync on a vm that has been paused.

systemctl restart docker

You will now SSH with the following information:

  • Host: pivotclub
  • Port: 2222
  • User: bastion
  • Password: bastion
ssh -p 2222 bastion@pivotclub

2. Read the Message of the Day (motd) and write down your new credentials. Exit your SSH session with the command exit or Ctrl+d.

  • Host: 10.199.2.120
  • User: tyler
  • Password: fightclub

HTTP Beyond Bastion

3. Challenge 2: The first challenge is to make a web request against a private web server that is located behind the bastion host. The web server is at the IP address 10.199.2.120. You must pivot through the bastion host because it is the only route to the web server. You can not connect directly to the web server.

Reset your environment by exiting all previous SSH sessions and tunnels. Let's create a forward SSH tunnel with the syntax -L<local_port>:<remote_host>:<remote_port>.

From your host SSH with the following:

  • Host: pivotclub
  • Port: 2222
  • User: bastion
  • Password: bastion
  • Arguments: -L5080:10.199.2.120:80
ssh -p 2222 bastion@pivotclub -L0.0.0.0:5080:10.199.2.120:80

4. On your host, open a browser to 127.0.0.1:5080.

5. Let's accomplish the same objective but this time with a socks proxy. By using the -D 9000 argument we instruct SSH to listen on port 9000 for incoming connections and then proxy them through the host that we have an SSH connection on. This is useful if you are connecting to more that one host. Reset your environment by exiting all previous SSH sessions and tunnels.

From your host SSH with the following:

  • Host: pivotclub
  • Port: 2222
  • User: bastion
  • Password: bastion
  • Arguments: -D9000
ssh -p 2222 bastion@pivotclub -D9000

6. Run this curl command on your host in another terminal window:

curl -x socks5h://localhost:9000 http://10.199.2.120

Double Pivot

7. Challenge 3: You will use the bastion host to communicate with a jumphost or an intermediary host. In the first method we will use a forward tunnel to the second SSH host in order to connect.

Reset your environment by exiting all previous SSH sessions and tunnels. Run the following SSH command from your host to set up an SSH session with the bastion and a port forward to host 10.212.243.13. Do not try to SSH from the bastion host, SSH has been disabled.

From your host SSH with the following:

  • Host: pivotclub
  • Port: 2222
  • User: bastion
  • Password: bastion
  • Arguments: -L2223:10.212.243.13:22
ssh -p 2222 bastion@pivotclub -L2223:10.212.243.13:22

In the second terminal window run the following to connect to the pivot. The password is fightclub.

ssh -p 2223 tyler@localhost

8. Another technique is to set a jump host. This tells SSH that you will first connect to a host and then proxy to another host. This will all take place in one terminal window. Notice that you will supply two passwords after running the command. The red arrows in the screenshot below show that you are SSH'ing to two different hosts.

Warning

Warning, you may get a message that states: REMOTE HOST IDENTIFICATION HAS CHANGED! If you do, then edit your known hosts file (~/.ssh/known_hosts) and remove the captured signature of the previous host.

From your host SSH with the following:

  • Host: pivotclub
  • Port: 2222
  • User: bastion
  • Password: bastion
  • Arguments: -L2223:10.212.243.13:22
ssh tyler@10.212.243.13 -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -J bastion@pivotclub:2222

Note

When you are ready to tear down the SSH sessions and tunnels, you'll want to start from the inner most tunnel. If you try to kill your initial bastion connection, SSH will leave the exit in a pending status until inner tunnels/sessions have had a chance to exit.

9. Before you exit the SSH session in your first terminal window, run ifconfig and take note of the two network adapters.

Catch a Beacon

10. Challenge 4: You will now SSH to the first pivot but this time you will establish a reverse tunnel on port 58671 to catch the beacon. You will also reference the secondary network interface in your reverse tunnel or else you SSH reverse tunnel will be bound to the primary adapter.

Reset your environment by exiting all previous SSH sessions and tunnels. Run the following SSH command from your host to set up an SSH session with the bastion and a port forward to pivot-1 10.212.243.13. Do not try to SSH from the bastion host, SSH has been disabled.

ssh -p 2222 bastion@pivotclub -L2223:10.212.243.13:22

Now we will set up a reverse tunnel by running the following on your host in your second terminal window.

ssh -p 2223 tyler@localhost -R10.112.3.199:58671:127.0.0.1:58671

11. In your third terminal window, create a netcat listener on your host to catch the beacon.

nc -klvp 58671

Note

If you see an error message connect_to 127.0.0.1 port 58671: failed. on pivot-1, that might mean that you didn't have a listener on your host.

Find the FTP Server

12. Challenge 5: You will now SSH to the bastion, set up a forward tunnel, then SSH through the tunnel to the first pivot. On the second SSH session we will set up a socks proxy with -D. Once we establish this socks proxy we can use proxy chains to proxy our scanning and ftp traffic into the internal network.

Reset your environment by exiting all previous SSH sessions and tunnels. Run the following SSH command from your host to set up an SSH session with the bastion and a port forward to host 10.212.243.13. Do not try to SSH from the bastion host, SSH has been disabled.

ssh -p 2222 bastion@pivotclub -L2223:10.212.243.13:22

Now lets set up a new SSH session with dynamic port forwarding through the forward tunnel we just created with -L2223:10.212.243.13:22. tyler's password is fightclub.

ssh -p 2223 tyler@localhost -D9050

13. Once we have socks proxy from the -D9050 argument in the second SSH sessions, we can direct traffic through that proxy with proxychains. Scan for the ftp server on host 10.112.3.207 by scanning all ports. This may take a few minutes and a lot of text will scroll across the terminal window as all 65,535 ports are scanned. If you look at the default configuration file for proxychains at /etc/proxychains.conf you will see that the port has been set to 9050.

proxychains nmap -Pn -sT -p- 10.112.3.207

You will see that something is listening on port 53121. Run an nmap service scan with the following command.

proxychains nmap -Pn -sT -p 53121 -sV 10.112.3.207

You've found the FTP server! We will stop here for the in-class lab but there is more to explore in the bonus lab at the end of section 2.

Conclusion

In this lab you created multiple SSH tunnels to pivot through network segments to access resources that were not publicly available. You were able to send traffic into a network segment using forward tunnels and receive traffic with reverse tunnels. The dynamic port forwarding set up a socks proxy that took traffic destined to another network and proxied traffic back and forth through the SSH connections.