Pivoting and Lateral Movement Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Pivoting and Lateral Movement flashcards as text
You have a Meterpreter session on a compromised host with IP 10.10.10.5 that can reach the internal subnet 192.168.1.0/24. Which Metasploit command adds a route so subsequent modules can reach that internal subnet through this session?
Answer: route add 192.168.1.0/24 [session_id]
The `route add` command in Metasploit tells the framework to route traffic destined for the specified subnet through an existing session.
When using proxychains for pivoting, which configuration file must be edited to specify the SOCKS proxy address and port?
Answer: /etc/proxychains.conf
Proxychains reads its proxy chain configuration (type, address, port) from /etc/proxychains.conf by default.
Which SSH command syntax creates a dynamic SOCKS proxy on local port 1080 through a remote SSH server at jump.example.com?
Answer: ssh -D 1080 user@jump.example.com
The -D flag in SSH creates a dynamic application-level port forward (SOCKS proxy) on the specified local port.
After setting up a Metasploit SOCKS proxy module (auxiliary/server/socks_proxy), what tool is typically used on the attacker machine to route other tools' traffic through it?
Answer: proxychains
Proxychains wraps any tool's TCP connections and routes them through a configured SOCKS proxy, enabling tools like nmap to reach internal networks.
A pentester compromises a dual-homed Linux host at 10.0.0.5 (eth0) and 172.16.0.5 (eth1). To scan the 172.16.0.0/24 network from their Kali machine, they set up a SOCKS5 proxy and prepend 'proxychains' before which tool?
Answer: nmap
Proxychains can wrap nmap so that TCP scans are routed through the SOCKS proxy to reach otherwise unreachable internal segments.
Which Metasploit auxiliary module creates a SOCKS proxy that allows external tools to pivot into internal networks via an active session?
Answer: auxiliary/server/socks_proxy
The auxiliary/server/socks_proxy module starts a SOCKS server that forwards traffic from the attacker machine through Metasploit's active session routes.
In the context of eJPT pivoting labs, what does a 'dual-homed' host mean?
Answer: A host connected to two different network segments
A dual-homed host has network interfaces on two separate subnets, making it the ideal pivot point to reach otherwise isolated network segments.