Telnet Pivoting through Meterpreter

In our previous tutorial, we had discussed on SSH pivoting and today we are going to discuss Telnet pivoting.

From Offensive Security

Pivoting is technique to get inside an unreachable network with help of pivot (center point). In simple words it is an attack through which attacker can exploit those system which belongs to different network. For this attack, the attacker needs to exploit the main server that helps the attacker to add himself inside its local network and then attacker will able to target the client system for attack.

Lab Setup requirement:

Attacker machine: Kali Linux

Pivot Machine (client): window operating system with two network interface

Target Machine: Ubuntu server (Allow telnet service)

Exploit pivot machine

Use exploit MS17-010 or multi handler to hack the pivot machine.

From given image you can confirm that I owned pivot machine ( meterpreter session1.

Check network interface through following command:

From given image you can observe two networks interface in pivot’s system 1st for IP through which attacker is connected and 2nd for IP through which telnet server (targets) are connected.

Route Add

Since attacker belongs to interface and target belongs to interface therefore it is not possible to directly make attack on target network until unless the attacker acquires same network connection. In order to achieve network attacker need run the post exploitation “autoroute”.

This Module will perform an ARP scan for a given IP range through a Meterpreter Session.

 Here we found a new IP as shown in given image. Let’s perform TCP port scan for activated services on this machine.

This module Enumerates open TCP services by performing a full TCP connect on each port. This does not need administrative privileges on the source machine, which may be useful if pivoting.

From given you can observe port 23 is open and we know that port 23 is used for telnet service.

Use Telnet login Brute Force Attack

An attacker always tries to make brute force attack for stealing credential for unauthorized access.

This module will test a telnet login on a range of machines and report successful logins. If you have loaded a database plugin and connected to a database this module will record successful logins and hosts so you can track your access.

Now type following command to Brute force TELNET login:

From given image you can observe that TELNET server is not secure against brute force attack because it is showing matching combination of username: aarti and password: 123 for login simultaneously it has opened victims command shell as session 2

Let’s count the number of victim sessions we have hold using following command:

From given image you can observe there are two sessions 1st as meterpreter session of windows system and 2nd as command shell of telnet server.

Now attacker is command shell of server, let’s verify through network configuration.

From given you can observe the network IP is

 Author: AArti Singh is a Researcher and Technical Writer at Hacking Articles an Information Security Consultant Social Media Lover and Gadgets. Contact here

Leave a Reply

Your email address will not be published. Required fields are marked *