NixDaemon

NixOS pentest workstation as one flake — IceBreaker's successor
git clone https://git.daemon-sec.xyz/NixDaemon.git
Log | Files | Refs | README

pivot.nix (1853B)


      1 # modules/features/pentest/pivot.nix — getting onto the next subnet.
      2 #
      3 # ligolo-ng is the one to reach for first: it gives a real TUN interface, so
      4 # every tool works unmodified instead of being wrapped in proxychains.
      5 # `ligolo-proxy` runs here, `ligolo-agent` goes on the target ($PAYLOADS has it
      6 # built for Windows, Linux and macOS — see payloads.nix).
      7 { lib, ... }:
      8 (import ./_sets.nix { inherit lib; }) {
      9   name = "pivot";
     10   description = "tunnelling, port forwarding and proxying";
     11 
     12   packages = pkgs: with pkgs; [
     13     ligolo-ng # ligolo-proxy, ligolo-agent
     14     chisel
     15     socat
     16     # Must be `proxychains`, matching programs.proxychains.package's default:
     17     # pkgs.proxychains and pkgs.proxychains-ng BOTH ship bin/proxychains4, and
     18     # two different paths owning one name is a profile collision. Listed here
     19     # as well as enabled below so the category check can see the binary.
     20     proxychains
     21     sshuttle
     22     gost
     23     frp # frpc, frps
     24     iodine
     25     pingtunnel
     26     stunnel
     27     wireguard-tools # wg
     28     openvpn
     29   ];
     30 
     31   expectedBins = [
     32     "ligolo-proxy" "ligolo-agent" "chisel" "socat" "sshuttle"
     33     "gost" "frpc" "frps" "iodine" "stunnel" "wg" "openvpn"
     34     "proxychains4" # from programs.proxychains below
     35   ];
     36 
     37   extraConfig = { ... }: {
     38     # /etc is read-only on NixOS, so the Kali habit of editing
     39     # /etc/proxychains.conf by hand does not work. This option is what makes
     40     # proxychains usable at all: it generates the file from Nix.
     41     programs.proxychains = {
     42       enable = true;
     43       proxyDNS = true;
     44       quietMode = false;
     45       # ligolo-ng needs no proxy at all; this default is for the chisel/ssh -D
     46       # case, where 1080 is the conventional local SOCKS port.
     47       proxies.socks = {
     48         enable = true;
     49         type = "socks5";
     50         host = "127.0.0.1";
     51         port = 1080;
     52       };
     53     };
     54   };
     55 }