Pivoting and Lateral Movement Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Pivoting and Lateral Movement flashcards as text
A pentester has a shell on a Windows pivot host and wants to enumerate all network interfaces to identify additional subnets. Which command shows this information?
Answer: ipconfig /all
ipconfig /all displays all network adapter configurations including IP addresses, subnets, and gateways, revealing additional network segments.
In a pivoting scenario, a pentester has routed through a compromised host to reach 172.16.0.0/24. Running nmap via proxychains returns only TCP results and misses ICMP-based host discovery. Why?
Answer: SOCKS proxies only support TCP, not ICMP
SOCKS proxies are TCP-only protocols and cannot tunnel ICMP packets, so nmap host discovery using ping (-PE) will not work through proxychains.
After pivoting into a network via Metasploit routes, which nmap flag should be used to disable ICMP ping discovery so host scanning works through the SOCKS proxy?
Answer: -Pn
The -Pn flag tells nmap to skip host discovery (no ping) and treat all hosts as up, which is necessary when scanning through a SOCKS proxy that can't forward ICMP.
A pentester uses SSH local port forwarding: 'ssh -L 8080:192.168.1.10:80 user@pivot'. After this, how does the pentester access the internal web service at 192.168.1.10?
Answer: Browse to http://127.0.0.1:8080 on the attacker machine
Local port forwarding binds the specified port on the local (attacker) machine, so connections to 127.0.0.1:8080 are forwarded through the SSH tunnel to the target.
Which Windows command can a pentester run on a pivot host to discover other machines with open SMB shares in the local subnet (Windows built-in)?
Answer: net view
The `net view` command enumerates computers and shared resources visible on the Windows network, helping identify lateral movement targets.
During an eJPT lab, a pentester needs to upgrade a basic netcat shell on a pivot host to a Meterpreter session for better pivoting capabilities. Which Metasploit post module accomplishes this?
Answer: post/multi/manage/shell_to_meterpreter
The shell_to_meterpreter post module injects a Meterpreter payload into an existing basic shell session, upgrading it to a full Meterpreter session.
What is the primary security risk that makes pivoting possible in a segmented network during a penetration test?
Answer: A compromised dual-homed host that bridges network segments
Pivoting exploits a compromised host that has connectivity to multiple network segments, using it as a relay to reach otherwise isolated internal resources.