The Double Pivot

One Pivot Runs Out

You built a tunnel. You routed the internal network. You can breathe.

Then you scan it, and the real target isn’t there.

It’s one more network deeper, behind a machine you just found. A subnet only that machine can see.

Your first pivot got you into network B. The goal is in network C, and only pivot 2 can reach it.

You need to pivot through your pivot. That’s a double pivot.


The Catch

Here’s what makes it tricky.

Your second machine, pivot 2, is buried inside network B.

It can talk to its neighbours in B. It cannot talk to your Kali box out on the internet.

It has no route home.


So if you just run a second agent on pivot 2 and point it at Kali, the connection dies at the perimeter. Same wall, same lesson as before:

Pivot 2 can’t dial you directly. But it can reach pivot 1, which already has a tunnel home.

The trick is to make pivot 1 pass the connection along.


Watch the chain build in the animation:

  • Pivot 2 falls, but its bid to reach Kali slams into the first firewall.
  • Pivot 1 opens a relay, a door inside network B that quietly forwards back to your proxy.
  • Agent 2 dials pivot 1, rides tunnel 1 home, and tunnel 2 forms.
  • A second interface routes network C, and your traffic bores two layers deep to the target.

Same recipe as one pivot, just stacked.


Step 1: Relay the Proxy Port

On pivot 1’s session, open a listener that forwards ligolo’s own port straight back to your proxy:

[Agent : pivot1@target] » listener_add --addr 0.0.0.0:11601 --to 127.0.0.1:11601 --tcp

Now anything that hits pivot 1 on 11601 gets carried back through tunnel 1 to your Kali proxy.

You’ve placed a door to your proxy inside network B.


Step 2: Point Agent 2 at Pivot 1

From your foothold on pivot 2, run a second agent. Aim it at pivot 1’s internal IP, not at Kali:

$ ./agent -connect 172.16.5.20:11601 -ignore-cert

The connection reaches pivot 1, rides tunnel 1 home, and lands on your proxy.

A second session appears in your console. Pivot 2 just phoned home, without ever being able to see you.


Step 3: A Second Interface and Route

Each pivot needs its own virtual card. Build a second one:

$ sudo ip tuntap add user kali mode tun ligolo2$ sudo ip link set ligolo2 up

Select the new session, start its tunnel on that interface, and route network C down it:

[Agent : pivot2@target] » start --tun ligolo2
$ sudo ip route add 10.10.30.0/24 dev ligolo2

That’s it. Network C is now routable from your Kali box, three networks away, and your tools still have no idea any of this is happening.


The Pattern Generalizes

Look at what each layer needed:

IngredientWhy
a relay listener on the previous pivotgives the next agent a door home
a fresh agent pointed at that pivotrides the existing tunnels back
a fresh interface (ligolo2, ligolo3, …)keeps each hop’s traffic separate
a fresh routetells Kali which subnet lives on which card

Triple pivot? Quadruple? It’s the same four steps, over and over. Chain as deep as the network goes.


Don’t Forget the Extra Cleanup

A double pivot leaves two of everything behind.

When you’re done, tear down both interfaces and both routes, and close the relay listener you opened on pivot 1:

$ sudo ip route del 10.10.30.0/24 dev ligolo2$ sudo ip link set ligolo2 down

Every card you raise and every door you open is one more thing to close. Leave the network the way you found it.


Practice Boxes

  • Reddish - HackTheBox. A hard, multi-layered box where the whole challenge is chaining pivots inward. The best double-pivot workout there is.
  • Wreath - TryHackMe. Its final hop is a real second pivot, gentler than Reddish and made for learning.