Pivoting, Attacking The "Unreachable Network" by plaintext | Hack The Box hacking workshop

Pivoting, Attacking The "Unreachable Network" by plaintext | Hack The Box hacking workshop

Source: YouTube · Hack The Box · published May 26, 2022 · 35:34

Penetration Testing
No ratings yet Log in to rate
Transcript Available
Description

The video features Julio (plaintext) demonstrating how attackers compromise "unreachable" networks by pivoting through compromised hosts like web servers to reach internal assets such as databases and Active Directory 3:38.

Key Takeaways:
• A common network design flaw involves placing a web server in a DMZ with access to an internal database. If the web server is compromised, it acts as a pivot point to reach the internal network, bypassing firewall rules that block direct internet access 7:40.
• To pivot from the web server to the database, the speaker uses Chisel, a TCP/UDP tunnel, to create a reverse port forward. This allows the attacker to route traffic through the compromised web server to reach the internal SQL server 15:24.
• Since the database server cannot connect directly to the attacker due to firewall rules, the speaker uses netsh on the web server to port forward traffic. The database connects to the web server, which then relays the connection back to the attack machine 23:23.
• To access the Active Directory in the deeper internal network, the speaker establishes a SOCKS5 proxy using Chisel and ProxyChains, allowing tools on the attack machine to route traffic through the database server 25:35.

Julio emphasizes the importance of drawing network diagrams and practicing pivoting techniques in lab environments to master these internal network attack strategies 33:17.

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

now we have with us today one of the most um engaging success stories of hack the box um so how i met this person i i will love him i don't want to say these things without him in order to see his reactions so the next person that we have with us today is plain text and he's going to say a how we can reach the unreachable networks how how we can pivot inside uh unreachable networks uh so thank you we thank you very much for coming in this presentation so hello julio how are you hello soti i'm doing fine you [Music] how is everything over there in santo domingo santo domingo is really nice so it's like like a paradise in the middle of the caribbean so if you want to go into vacation so you can come to our country the dominican republic will welcome you perfect and i want to share a few word…