Skip to main content
TUN-based tunneling tool: routes traffic through a compromised host at the kernel level, so tools work natively without proxychains.
1

Create TUN interface (attacker, one-time setup)

Run once on your attack box to create the kernel tunnel interface.
2

Start the proxy listener (attacker)

3

Deploy and run the agent (target)

Drop the agent binary on the compromised host and connect back to your proxy.
4

Select session and start tunnel (Ligolo console)

In the interactive Ligolo shell, select the connected session then start routing.
5

Add route for the internal subnet (attacker)

Route the target’s internal network through the ligolo interface so your tools reach it directly.

Reaching the Agent’s Localhost

240.0.0.1 is the ligolo-ng magic IP: traffic to it is routed to 127.0.0.1 on the agent host. Use it to hit services bound only to loopback on the compromised machine (local admin panels, databases, unauthenticated internal APIs).
It sits in the reserved 240.0.0.0/4 (Class E) block, so it never clashes with a real internal subnet. Requires the tunnel to be started (start); very old ligolo-ng builds don’t support it.