Ligolo

Server (proxy)

choose a common port (3389, 25, 123) - default 11601

Victim (agent) - single pivot

Server after victim joining

in same 192.168.w.0/24 subnet, victim has access to 192.168.x.0/24

Victim 2 (2nd agent) - double pivot

Server after victim joining

the machine in 192.168.x.0/24 has access to 192.168.y.0/24 subnet

able to switch tunnel simply by start in the 2nd session and choose to close the 1st tunnel via prompt

Port forward in 2nd agent to receive callback from 3rd victim

victim 2 (agent 2) 25 traffics directing to attacker (server) 443 listener

192.168.y.0 subnet machine callback to 192.168.x.0:25 forward to kali at 192.168.w.0:443

Access agent's local port

Last updated