1
Create TUN interface (attacker, one-time setup)
Run once on your attack box to create the kernel tunnel interface.
2
Start the proxy listener (attacker)
3
Deploy and run the agent (target)
Drop the agent binary on the compromised host and connect back to your proxy.
4
Select session and start tunnel (Ligolo console)
In the interactive Ligolo shell, select the connected session then start routing.
5
Add route for the internal subnet (attacker)
Route the target’s internal network through the ligolo interface so your tools reach it directly.
Reaching the Agent’s Localhost
240.0.0.1 is the ligolo-ng magic IP: traffic to it is routed to 127.0.0.1 on the agent host. Use it to hit services bound only to loopback on the compromised machine (local admin panels, databases, unauthenticated internal APIs).
240.0.0.0/4 (Class E) block, so it never clashes with a real internal subnet. Requires the tunnel to be started (start); very old ligolo-ng builds don’t support it.