local-network-and-socket-triage.md (10903B)
1 --- 2 title: "Local Network and Socket Triage" 3 section: "Linux" 4 sectionSlug: "linux-hardening" 5 sourcePath: "src/linux-hardening/network-information/local-network-and-socket-triage.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/linux-hardening/network-information/local-network-and-socket-triage.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Local Network and Socket Triage 14 15 After getting a shell on a Linux host, the most useful network targets are often not exposed externally. Loopback-only services, veth networks, Unix sockets, temporary listeners, packet captures, and local firewall rules can expose credentials or local-only attack surfaces. 16 17 This page focuses on practical local post-exploitation techniques, not general remote network pentesting. 18 19 ## Loopback and Local Service Enumeration 20 21 Start by identifying listening services, their bind addresses, and the owning process when permissions allow it.<sup>[[1]](#references)[[2]](#references)</sup> 22 23 ```bash 24 ss -lntup 25 ss -lnx 26 ip addr 27 ip route 28 ``` 29 30 Important patterns: 31 32 - `127.0.0.1:<port>` or `[::1]:<port>`: reachable only from the host by default.<sup>[[3]](#references)[[4]](#references)</sup> 33 - `0.0.0.0:<port>`: reachable on all IPv4 interfaces unless filtered.<sup>[[3]](#references)</sup> 34 - `10.0.0.0/8`, `172.16.0.0/12`, or `192.168.0.0/16` on `veth*`, `docker*`, `br-*`, `cni*`: likely container or local lab networks.<sup>[[23]](#references)[[24]](#references)</sup> 35 - Unix sockets under `/run`, `/var/run`, `/tmp`, or application directories: local IPC surfaces.<sup>[[5]](#references)</sup> 36 37 Map local ports with lightweight probes.<sup>[[6]](#references)[[7]](#references)</sup> 38 39 ```bash 40 for p in 80 443 8000 8080 8081 9000 5000; do 41 timeout 1 bash -c "echo >/dev/tcp/127.0.0.1/$p" 2>/dev/null && echo "open: $p" 42 done 43 ``` 44 45 Use `nmap` locally when available.<sup>[[8]](#references)[[9]](#references)[[10]](#references)</sup> 46 47 ```bash 48 nmap -sT -Pn -p- 127.0.0.1 49 nmap -sT -Pn --open 127.0.0.1 50 ``` 51 52 ## Hidden veth and Container Subnets 53 54 Containerized or lab environments often expose services only on a bridge or veth subnet. Enumerate interfaces and routes before assuming a service is unreachable.<sup>[[2]](#references)</sup> 55 56 ```bash 57 ip -br addr 58 ip route 59 ip neigh 60 ``` 61 62 Find likely local subnets.<sup>[[2]](#references)</sup> 63 64 ```bash 65 ip -o -4 addr show | awk '{print $2, $4}' 66 ``` 67 68 Probe a discovered subnet carefully.<sup>[[8]](#references)[[9]](#references)[[10]](#references)</sup> 69 70 ```bash 71 nmap -sT -Pn --open 172.17.0.0/24 72 nmap -sT -Pn -p 80,443,8000,8080,9000 172.17.0.0/24 73 ``` 74 75 The technique is useful when a web panel, debug endpoint, or helper service is hidden from external scans but reachable from the compromised host or container network. 76 77 ## Local Pivot With socat or SSH 78 79 If a service is bound to loopback, expose it through an allowed channel instead of changing the service itself. 80 81 Forward a local-only HTTP service with SSH.<sup>[[11]](#references)</sup> 82 83 ```bash 84 ssh -L 8080:127.0.0.1:8080 user@target 85 ``` 86 87 Bridge a local port with `socat` when you already have shell access.<sup>[[12]](#references)</sup> 88 89 ```bash 90 socat TCP-LISTEN:18080,fork,reuseaddr TCP:127.0.0.1:8080 91 ``` 92 93 Forward a Unix socket to TCP for local testing.<sup>[[5]](#references)[[12]](#references)</sup> 94 95 ```bash 96 socat TCP-LISTEN:18081,fork,reuseaddr UNIX-CONNECT:/run/app/app.sock 97 ``` 98 99 This does not exploit anything by itself. It makes a local-only surface reachable from your tooling so you can interact with it like a normal service. 100 101 ## Banner Grabbing and Simple Protocols 102 103 Not every service is HTTP. Many local services leak enough information through a banner or one-line protocol. 104 105 Basic probes.<sup>[[13]](#references)</sup> 106 107 ```bash 108 nc -nv 127.0.0.1 9000 109 printf 'help\n' | nc -nv 127.0.0.1 9000 110 printf 'version\n' | nc -nv 127.0.0.1 9000 111 ``` 112 113 HTTP check without a browser.<sup>[[13]](#references)[[14]](#references)</sup> 114 115 ```bash 116 printf 'GET / HTTP/1.1\r\nHost: 127.0.0.1\r\nConnection: close\r\n\r\n' | nc -nv 127.0.0.1 8080 117 curl -i http://127.0.0.1:8080/ 118 ``` 119 120 For TLS.<sup>[[14]](#references)[[15]](#references)</sup> 121 122 ```bash 123 openssl s_client -connect 127.0.0.1:8443 -servername localhost 124 curl -k -i https://127.0.0.1:8443/ 125 ``` 126 127 The goal is to identify the protocol, authentication scheme, version, and whether the service trusts local clients. 128 129 ## Capturing Loopback Traffic 130 131 Local traffic can expose headers, bearer tokens, Basic Auth credentials, or application-specific secrets.<sup>[[17]](#references)[[25]](#references)</sup> Capture only in authorized environments. 132 133 Capture loopback HTTP traffic.<sup>[[16]](#references)</sup> 134 135 ```bash 136 sudo tcpdump -i lo -A -s0 'tcp port 80 or tcp port 8080' 137 ``` 138 139 Capture a specific local service.<sup>[[16]](#references)</sup> 140 141 ```bash 142 sudo tcpdump -i lo -w /tmp/loopback.pcap 'tcp port 8080' 143 ``` 144 145 Decode Basic Auth from a captured or logged header.<sup>[[17]](#references)[[18]](#references)</sup> 146 147 ```bash 148 printf '%s' 'dXNlcjpwYXNz' | base64 -d 149 ``` 150 151 Useful strings to look for in text captures: 152 153 ```bash 154 grep -Ei 'Authorization:|Cookie:|Bearer|Basic|token|api[_-]?key|password' /tmp/capture.txt 155 ``` 156 157 ## TLS Key Logging 158 159 If you can control the client process environment in a lab, `SSLKEYLOGFILE` can make TLS sessions decryptable in Wireshark or compatible tooling.<sup>[[19]](#references)[[20]](#references)</sup> This is useful for understanding local HTTPS traffic without attacking TLS itself. 160 161 Run a client with key logging enabled.<sup>[[19]](#references)[[20]](#references)</sup> 162 163 ```bash 164 export SSLKEYLOGFILE=/tmp/sslkeys.log 165 curl -k https://127.0.0.1:8443/ 166 ls -l /tmp/sslkeys.log 167 ``` 168 169 Capture the traffic at the same time.<sup>[[16]](#references)</sup> 170 171 ```bash 172 sudo tcpdump -i lo -w /tmp/tls.pcap 'tcp port 8443' 173 ``` 174 175 Then load `/tmp/tls.pcap` and `/tmp/sslkeys.log` into Wireshark. This only works when the client library supports NSS-style key logging and you can set the environment before the connection is made.<sup>[[20]](#references)[[21]](#references)</sup> 176 177 ## Unix Socket Interaction and Command Injection 178 179 Unix sockets are local IPC endpoints.<sup>[[5]](#references)</sup> They may expose HTTP APIs, custom protocols, or unsafe command handlers.<sup>[[12]](#references)[[14]](#references)</sup> 180 181 Find sockets.<sup>[[1]](#references)[[5]](#references)</sup> 182 183 ```bash 184 ss -lnx 185 find /run /var/run /tmp -type s -ls 2>/dev/null 186 ``` 187 188 Interact with HTTP over a Unix socket.<sup>[[14]](#references)</sup> 189 190 ```bash 191 curl --unix-socket /run/app/app.sock http://localhost/ 192 curl --unix-socket /run/app/app.sock -i http://localhost/admin 193 ``` 194 195 Interact with a raw socket.<sup>[[12]](#references)[[13]](#references)</sup> 196 197 ```bash 198 printf 'status\n' | socat - UNIX-CONNECT:/run/app/app.sock 199 printf 'help\n' | nc -U /run/app/app.sock 200 ``` 201 202 If user-controlled socket input is passed to a shell or privileged helper, it can become command injection.<sup>[[26]](#references)</sup> For a focused example, see [Socket Command Injection](/hacktricks/linux-hardening/network-information/socket-command-injection). 203 204 ## nftables Review and Authorized Rule Changes 205 206 Local firewall rules may explain why a service is visible locally but blocked remotely, or why a high port appears unreachable from one interface.<sup>[[22]](#references)</sup> 207 208 Review rules.<sup>[[22]](#references)</sup> 209 210 ```bash 211 sudo nft list ruleset 212 sudo nft list tables 213 sudo nft list chains 214 ``` 215 216 Look for drops affecting a target port.<sup>[[22]](#references)</sup> 217 218 ```bash 219 sudo nft list ruleset | grep -Ei 'drop|reject|dport|tcp|udp' 220 ``` 221 222 In an authorized lab, remove a specific blocking rule by handle.<sup>[[22]](#references)</sup> 223 224 ```bash 225 sudo nft -a list chain inet filter input 226 sudo nft delete rule inet filter input handle <handle> 227 ``` 228 229 Prefer deleting the exact handle over flushing full tables. The technique is to identify the precise filter causing the behavior and change only that rule.<sup>[[22]](#references)</sup> 230 231 ## Quick Workflow 232 233 ```bash 234 ss -lntup 235 ss -lnx 236 ip -br addr 237 ip route 238 nmap -sT -Pn --open 127.0.0.1 239 find /run /var/run /tmp -type s -ls 2>/dev/null 240 sudo nft list ruleset 2>/dev/null | head -n 80 241 ``` 242 243 Prioritize services that are local-only, run as a more privileged user, expose admin/debug functions, or trust loopback/container-network clients. 244 245 ## References 246 247 - [1] [ss(8) — Linux manual page](https://man7.org/linux/man-pages/man8/ss.8.html) 248 - [2] [ip(8) — Linux manual page](https://man7.org/linux/man-pages/man8/ip.8.html) 249 - [3] [ip(7) — Linux manual page](https://man7.org/linux/man-pages/man7/ip.7.html) 250 - [4] [RFC 4291: IP Version 6 Addressing Architecture](https://www.rfc-editor.org/info/rfc4291/) 251 - [5] [unix(7) — Linux manual page](https://man7.org/linux/man-pages/man7/unix.7.html) 252 - [6] [Redirections (Bash Reference Manual)](https://www.gnu.org/s/bash/manual/html_node/Redirections.html) 253 - [7] [timeout invocation (GNU Coreutils)](https://www.gnu.org/s/coreutils/timeout) 254 - [8] [Port Scanning Techniques (Nmap Reference Guide)](https://nmap.org/book/man-port-scanning-techniques.html) 255 - [9] [Host Discovery (Nmap Reference Guide)](https://nmap.org/book/man-host-discovery.html) 256 - [10] [Port Specification and Scan Order (Nmap Reference Guide)](https://nmap.org/book/man-port-specification.html) 257 - [11] [ssh(1) — Linux manual page](https://man7.org/linux/man-pages/man1/ssh.1.html) 258 - [12] [socat(1) — Linux manual page](https://www.man7.org/linux/man-pages/man1/socat.1.html) 259 - [13] [nc(1) — OpenBSD manual page](https://man.openbsd.org/nc.1) 260 - [14] [curl command line tool manual](https://curl.se/docs/manpage.html?category=23) 261 - [15] [openssl-s_client — OpenSSL Documentation](https://docs.openssl.org/3.0/man1/openssl-s_client/) 262 - [16] [tcpdump(8) — Linux manual page](https://man7.org/linux/man-pages/man8/tcpdump.8.html) 263 - [17] [RFC 7617: The 'Basic' HTTP Authentication Scheme](https://www.rfc-editor.org/rfc/rfc7617.html) 264 - [18] [base64 invocation (GNU Coreutils)](https://www.gnu.org/software/coreutils/manual/html_node/base64-invocation.html) 265 - [19] [openssl-env — OpenSSL Documentation](https://docs.openssl.org/master/man7/openssl-env/) 266 - [20] [TLS — Wireshark Wiki](https://wiki.wireshark.org/tls) 267 - [21] [Wireshark User’s Guide](https://www.wireshark.org/docs/wsug_html/) 268 - [22] [nftables manual](https://netfilter.org/projects/nftables/manpage.html) 269 - [23] [Address Allocation for Private Internets (RFC 1918)](https://www.rfc-editor.org/rfc/rfc1918.html) 270 - [24] [ip-link(8) — Linux manual page](https://man7.org/linux/man-pages/man8/ip-link.8.html) 271 - [25] [The OAuth 2.0 Authorization Framework: Bearer Token Usage (RFC 6750)](https://www.rfc-editor.org/rfc/rfc6750.html) 272 - [26] [CWE-78: Improper Neutralization of Special Elements used in an OS Command](https://cwe.mitre.org/data/definitions/78.html)