CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementMedium

A penetration tester has successfully compromised an initial host within a segmented network. To reach a high-value target in a different, isolated segment, the tester needs to establish a proxy. The compromised host has access to both segments, but direct routing between segments is blocked for the tester's attacking machine. Which 'nmap' feature, combined with an appropriate tool, can be used to scan the isolated segment through the compromised host?

  1. APerforming a 'nmap -Pn -F <target_segment_IP_range>' scan from the compromised host itself.
  2. BUsing 'nmap -sS -p- <target_segment_IP_range>' directly from the attacking machine.
  3. CSetting up a SOCKS proxy on the compromised host and using 'nmap --proxy SOCKS5://<proxy_IP>:<proxy_port> <target_segment_IP_range>'.
  4. DEmploying 'nmap --data-string <payload> <target_segment_IP_range>' for a raw packet scan.
Show answer & explanation

Correct answer: C. Setting up a SOCKS proxy on the compromised host and using 'nmap --proxy SOCKS5://<proxy_IP>:<proxy_port> <target_segment_IP_range>'.

Setting up a SOCKS proxy on the compromised host (e.g., with SSH dynamic forwarding or a dedicated SOCKS proxy tool) allows 'nmap' to tunnel its traffic through that proxy, effectively enabling scans of the isolated segment that would otherwise be unreachable from the attacking machine.

Why the other options are wrong

  • A. Scanning from the compromised host itself is an option, but the question implies scanning from the *tester's attacking machine* through the compromised host, which requires a proxy setup for 'nmap'.
  • B. Direct 'nmap' scan from the attacking machine will fail due to network segmentation/firewall rules.
  • D. '--data-string' is for appending data to packets and is not a proxy or pivoting mechanism.

Nmap Scanning via SOCKS Proxy

Using 'nmap' to scan target networks that are not directly reachable from the attacker's machine by routing 'nmap' traffic through a SOCKS proxy established on a compromised host.

  • Requires a SOCKS proxy to be active on the compromised host.
  • Uses the '--proxy' option in 'nmap' to specify the proxy server.
  • Enables network discovery and vulnerability scanning in segmented environments.

Memory trick: Nmap can weave through networks using a proxy thread.

More Post-exploitation and Lateral Movement questions