pivot.nix (1853B)
1 # modules/features/pentest/pivot.nix — getting onto the next subnet. 2 # 3 # ligolo-ng is the one to reach for first: it gives a real TUN interface, so 4 # every tool works unmodified instead of being wrapped in proxychains. 5 # `ligolo-proxy` runs here, `ligolo-agent` goes on the target ($PAYLOADS has it 6 # built for Windows, Linux and macOS — see payloads.nix). 7 { lib, ... }: 8 (import ./_sets.nix { inherit lib; }) { 9 name = "pivot"; 10 description = "tunnelling, port forwarding and proxying"; 11 12 packages = pkgs: with pkgs; [ 13 ligolo-ng # ligolo-proxy, ligolo-agent 14 chisel 15 socat 16 # Must be `proxychains`, matching programs.proxychains.package's default: 17 # pkgs.proxychains and pkgs.proxychains-ng BOTH ship bin/proxychains4, and 18 # two different paths owning one name is a profile collision. Listed here 19 # as well as enabled below so the category check can see the binary. 20 proxychains 21 sshuttle 22 gost 23 frp # frpc, frps 24 iodine 25 pingtunnel 26 stunnel 27 wireguard-tools # wg 28 openvpn 29 ]; 30 31 expectedBins = [ 32 "ligolo-proxy" "ligolo-agent" "chisel" "socat" "sshuttle" 33 "gost" "frpc" "frps" "iodine" "stunnel" "wg" "openvpn" 34 "proxychains4" # from programs.proxychains below 35 ]; 36 37 extraConfig = { ... }: { 38 # /etc is read-only on NixOS, so the Kali habit of editing 39 # /etc/proxychains.conf by hand does not work. This option is what makes 40 # proxychains usable at all: it generates the file from Nix. 41 programs.proxychains = { 42 enable = true; 43 proxyDNS = true; 44 quietMode = false; 45 # ligolo-ng needs no proxy at all; this default is for the chisel/ssh -D 46 # case, where 1080 is the conventional local SOCKS port. 47 proxies.socks = { 48 enable = true; 49 type = "socks5"; 50 host = "127.0.0.1"; 51 port = 1080; 52 }; 53 }; 54 }; 55 }