One Foothold Is Never the Goal
You exploited a box. You caught a shell.
Feels like the finish line. It isn’t.
The machine you landed on can see places you can’t.
It has a second network card facing an internal network, one your attacking machine has no path to.
The database. The domain controller. The file server with the actual loot.
All of it lives back there.
The first machine you compromise is rarely the target. It’s the door to the target.
Turning that door into a road is called pivoting.
Networks Are Not Flat
A flat network lets every device talk to every other device.
Pop one host and you reach them all. Convenient for you, which is exactly why real networks aren’t built that way.
Instead, networks are segmented. Chopped into subnets, with firewalls deciding what crosses between them.
| Zone | What lives there | Can you reach it? |
|---|---|---|
| Edge | public web and mail servers | yes, your way in |
| Internal | databases, shares, domain controllers | no, walled off |
One special kind of machine sits on both at once. One foot in each network.
It straddles the boundary.
That machine is your prize.
Look at what the animation shows:
- You can reach the pivot. That’s how you compromised it.
- You cannot reach the target. There’s no route. Your packets have nowhere to go.
- The pivot can reach the target, because it sits on that network.
So the move is obvious once you see it.
Stop trying to reach the target yourself. Send your traffic through the pivot and let it do the reaching.
Pivoting means using a machine you control as a relay into a network you can’t otherwise touch.
The Insight That Runs This Whole Chapter
Here is the part that decides how every pivoting tool is built.
Firewalls treat the two directions of traffic completely differently.
- Inbound (someone outside connecting in) is guarded hard. This is where attacks come from, so almost everything is blocked.
- Outbound (a machine inside connecting out) is usually wide open. Businesses need their machines to reach the internet.
This asymmetry is everything.
You usually cannot connect to a port you open on the pivot. The firewall swats it down.
But the pivot can happily connect out to you.
So the pattern flips.
Instead of you reaching in, the pivot dials home.
You wait with a listener. The agent on the compromised host connects back to it. Then your traffic flows backwards down that outbound connection.
This is why the pivot always connects to you, never the reverse. Same reason a reverse shell beats a bind shell: outbound gets through, inbound doesn’t.
Keep this picture in your head and the tooling stops feeling like magic.
Every good pivoting tool is just a clean way to build that one outbound connection and push your traffic through it.
A Word on the Old Way
Pivoting isn’t new. There’s a whole museum of tools for it.
| Tool | What it does |
|---|---|
| socat | relays a single port |
SSH -L / -D / -R | local, dynamic, and remote forwards |
| chisel | builds a SOCKS proxy |
They all work. And they all share one headache.
They hand you a SOCKS proxy.
Which means wrapping every single tool in proxychains, and watching your scans slow to a crawl.
We’re going to skip most of that.
There’s a modern tool that makes the internal network behave like it’s plugged straight into your machine. No proxychains. No per-tool fiddling. Fast enough to actually run nmap through.
It’s called ligolo-ng, and it’s what the next note is entirely about.
You now know the why: segmented networks, the firewall’s inbound and outbound blind spot, and the pivot-as-relay idea. Next we turn that idea into a working tunnel.