Talk With an Expert

Tunneling, Pivoting, and Web Application Penetration Testing

Tunneling, Pivoting, and Web Application Penetration Testing (PDF, 2.83MB)Published: 03 Aug, 2015
Created by
Gordon Fraser

When conducting a web application penetration test there are times when you want to be able to pivot through a system to which you have gained access, to other systems in order to continue testing. There are many channels that can be used as avenues for pivoting. This paper examines five commonly used channels for pivoting: Netcat relays, SSH local port forwarding, SSH dynamic port forwarding (SOCKS proxy), Meterpreter sessions. and Ncat HTTP proxy; within the context of using them with key tools in the penetration tester's arsenal including: Nmap, the Burp Suite, w3af, Nikto, Iceweasel, and Metasploit.