Skip to content

Lab 2.5 : Bonus! More Pivoting

Objectives

  • Use SSH to access a network
  • Create an SSH forward tunnel to access an internal resource
  • Use socat to translate traffic
  • Chain SSH connections to traverse network segments

This lab will focus on the use of pivoting and redirection to route traffic through hosts. On the Slingshot Linux VM there is a miniature network created with Docker. You will access the network with SSH and then create tunnels to access resources in different network segments.

TTPs Emulated in this Lab

On Your Own

  1. SSH to the bastion host
  2. Steal the SSH key from 10.212.243.13
  3. Use the SSH key to access 10.112.3.12
  4. Review SSH configuration file
  5. Use socat on hosts that do not allow SSH tunnels
  6. Scan the SNMP service on 10.24.13.161:161
  7. Request the web page on 2a02:1b8:b010:9010:1::86
  8. Review the walkthrough

Walkthrough

Note

If you just completed Lab 2.3 then you can skip to step 5, otherwise steps 1-4 are a good refresher.

SSH to Bastion

1. First we need access to the network, access is protected with a bastion host. In certain network configurations, the bastion host is hardened and available on the public internet. The key is to configure this host to have as little attack surface as possible, resiliency to internet traffic, and to perform authentication on incoming connections.

Open up three terminal windows and change directories to the lab folder in each one.

cd /labs/sec-2/pivoting

You will now ssh with the following information:

  • Host: pivotclub
  • Port: 2222
  • User: bastion
  • Password: bastion
ssh -p 2222 bastion@pivotclub

2. Read the Message of the Day (motd) and write down your new credentials. Exit your ssh session with the command exit or Ctrl+d.

  • Host: 10.199.2.120
  • User: tyler
  • Password: fightclub

First Double Pivot

3. Challenge 3: You will use the bastion host to communicate with a jumphost or an intermediary host. In the first method we will use a forward tunnel to the second ssh host in order to connect.

Please issue the following command before performing any of the other steps: cd /labs/sec-2/pivoting

Reset your environment by exiting all previous ssh sessions and tunnels. Run the following ssh command from your host to set up an ssh session with the bastion and a port forward to host 10.212.243.13. Do not try to ssh from the bastion host, ssh has been disabled.

From your host ssh with the following:

  • Host: pivotclub
  • Port: 2222
  • User: bastion
  • Password: bastion
  • Arguments: -L2223:10.212.243.13:22
ssh -p 2222 bastion@pivotclub -L2223:10.212.243.13:22

In the second terminal window run the following to connect to the pivot. The password is fightclub.

ssh -p 2223 tyler@localhost

Note

When you are ready to tear down the ssh sessions and tunnels, you'll want to start from the inner most tunnel. If you try to kill your initial bastion connection, ssh will leave the exit in a pending status until inner tunnels/sessions have had a chance to exit.

4. Before you exit the ssh session in your first terminal window, run ifconfig and take note of the two network adapters.

Steal the SSH Key

5. Challenge 5: You will now ssh to the bastion, set up a forward tunnel, then ssh through the tunnel to the first pivot. On the second SSH session we will set up a socks proxy with -D. Once we establish this socks proxy we can use proxy chains to proxy our scanning and ftp traffic into the internal network.

Reset your environment by exiting all previous SSH sessions and tunnels. Run the following SSH command from your host to set up an SSH session with the bastion and a port forward to host 10.212.243.13. Do not try to SSH from the bastion host, SSH has been disabled.

ssh -p 2222 bastion@pivotclub -L2223:10.212.243.13:22

Now lets set up a new SSH session with dynamic port forwarding through the forward tunnel we just created with -L2223:10.212.243.13:22. tyler's password is fightclub.

ssh -p 2223 tyler@localhost -D9050

6. Once we have socks proxy from the -D9050 argument in the second SSH session, we can direct traffic through that proxy with proxychains. In Lab 2.2 we learned that the ftp server is on port 53121. Connect to the ftp server and download the SSH key named id_ed25519. The ftp username is tyler and password is squanderedpotential. Run the following command in your third terminal window.

proxychains ftp 10.112.3.207 53121

Log in and then set the mode to passive, we must use passive data transfer because we are using tunnels. Passive mode was created to avoid issues with client firewalls. With passive mode the client (your system) will initiate a new data connection to the ftp server. In active mode the server would connect to a port that the client opens. This would fail because we don't have a reverse tunnel back to our host.

passive
ls
get id_ed25519
quit
chmod 600 id_ed25519

Now you have the SSH key to SSH into pivot-2

Triple Pivot

7. Challenge 6: You were able to steal the SSH key for user paulson, now lets create a forward tunnel from pivot-1 to pivot-2. The SSH key also works for the bastion and tyler users on the previous servers.

Reset your environment by exiting all previous SSH sessions and tunnels. Run the following SSH command from your host to set up an SSH session with the bastion and a port forward to host 10.212.243.13. Do not try to SSH from the bastion host, SSH has been disabled.

Connect to the bastion host and port forward in one terminal window.

ssh -p 2222 -i id_ed25519 bastion@pivotclub -L2223:10.212.243.13:22

Connect to pivot-1 and port forward in another terminal window.

ssh -p 2223 -i id_ed25519 tyler@localhost -L2224:10.112.3.12:22

Connect to pivot-2 in a third terminal window.

ssh -p 2224 -i id_ed25519 paulson@localhost

You now have a session on a new internal LAN segment!

SSH Configuration Files

8. An SSH configuration file allows you to set options specific to each server you connect to. By default, the SSH configuration file for a user is located at ~/.ssh/config. Here is an example of a configuration file for the three servers in the Pivot Club network. This configuration file is located at /labs/sec-2/pivoting/backup/config.

Copy the config into the pivoting folder that you are working out of.

cd /labs/sec-2/pivoting
cp backup/config .
Host *
    # Send keep alive packets and stop after n failures
    ServerAliveCountMax 4
    # Send a keep alive packet to avoid a time out
    ServerAliveInterval 15
    # Keys in your local machine are used across hops
    ForwardAgent yes

Host bastion pivotclub localhost
    # SSH hostname or up address
    HostName 127.0.0.1
    # SSH key for the user
    User bastion
    # Specify the port
    Port 2222
    # SSH key for the user
    IdentityFile id_ed25519
    # Port forward to web-1
    LocalForward 127.0.0.1:8081 10.199.2.120:80
    # Don't check ssh server signatures
    StrictHostKeyChecking no
    # Don't reference or save ssh server signatures
    UserKnownHostsFile /dev/null

Host pivot-1
    # SSH hostname or up address
    HostName 10.212.243.13
    # SSH key for the user
    User tyler
    # Specify the port
    Port 22
    # SSH key for the user
    IdentityFile id_ed25519
    # Auth to bastion (pivot-club) host first
    ProxyJump pivot-club
    # Reverse tunnel to catch beacon from support-1
    RemoteForward 10.112.3.199:58671 127.0.0.1:58671
    # Socks proxy into the network segment
    DynamicForward 127.0.0.1:9050
    # Don't check ssh server signatures
    StrictHostKeyChecking no
    # Don't reference or save ssh server signatures
    UserKnownHostsFile /dev/null

Host pivot-2
    # SSH hostname or up address
    HostName 10.112.3.12
    # SSH key for the user
    User paulson
    # Specify the port
    port 22
    # SSH key for the user
    IdentityFile id_ed25519
    # Auth to pivot-1 host first
    ProxyJump pivot-1
    # Don't check ssh server signatures
    StrictHostKeyChecking no
    # Don't reference or save ssh server signatures
    UserKnownHostsFile /dev/null

If you do not want to use the default location you can use -F in the SSH command to specify a configuration file.

ssh -F config pivot-2

Further reading

man ssh_config

SNMP with Socat Redirection

9. Challenge 7: Pivot-2 is an interesting host, the SSH daemon configuration is specifically set to disallow tunneling.

GatewayPorts no
AllowTcpForwarding no
PermitTunnel no

First you will ssh to pivot-1 and create a forward tunnel to pivot-2 listening on port 9161 and sending to port 9161. Run the following command in your first terminal window.

ssh -F config pivot-1 -L9161:10.112.3.12:9161

In your second terminal window ssh to pivot-2 and then run the socat command on pivot-2. The socat command will listen on TCP port 9161 and send that to the SNMP server at 10.24.13.161 on UDP port 161

ssh -F config pivot-2
socat TCP4-LISTEN:9161,reuseaddr,fork UDP:10.24.13.161:161

In you third terminal window run the following command on your host. The first socat command will listen on port 161 locally, then send that traffic to the opening of our first tunnel on TCP port 9161.

sudo socat -T15 udp4-recvfrom:161,reuseaddr,fork tcp:localhost:9161 &

Now we are ready to communicate with SNMP to get information from the SNMP service running on host 10.24.13.161.

snmpwalk -v 2c -c public localhost

IPv6

10. Challenge 8: For our last challenge we will use socat to translate traffic between IPv4 and IPv6 in order to access a web server in the furthest network segment that only speaks IPv6.

First you will ssh to pivot-1 and create a forward tunnel to pivot-2 listening on port 8082 and sending to port 8082. Run the following command in your first terminal window.

ssh -F config pivot-1 -L8082:10.112.3.12:8082

In your second terminal window ssh to pivot-2 and then run the socat command on pivot-2. The socat command will listen on TCP port 8082 and send to 2a02:1b8:b010:9010:1::86 on port 80

ssh -F config pivot-2
socat TCP-LISTEN:8082,reuseaddr,fork TCP6:[2a02:1b8:b010:9010:1::86]:80

In you third terminal window run the following command on your host. We can now request the website on the IPv6 host.

curl 127.0.0.1:8082

Conclusion

In this bonus lab we were able to get more practice tunneling through multiple hosts. We used an SNMP tool through our tunnels and supported the traffic flow by using socat to translate traffic.