daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

local-network-and-socket-triage.md (10903B)


      1 ---
      2 title: "Local Network and Socket Triage"
      3 section: "Linux"
      4 sectionSlug: "linux-hardening"
      5 sourcePath: "src/linux-hardening/network-information/local-network-and-socket-triage.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/linux-hardening/network-information/local-network-and-socket-triage.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Local Network and Socket Triage
     14 
     15 After getting a shell on a Linux host, the most useful network targets are often not exposed externally. Loopback-only services, veth networks, Unix sockets, temporary listeners, packet captures, and local firewall rules can expose credentials or local-only attack surfaces.
     16 
     17 This page focuses on practical local post-exploitation techniques, not general remote network pentesting.
     18 
     19 ## Loopback and Local Service Enumeration
     20 
     21 Start by identifying listening services, their bind addresses, and the owning process when permissions allow it.<sup>[[1]](#references)[[2]](#references)</sup>
     22 
     23 ```bash
     24 ss -lntup
     25 ss -lnx
     26 ip addr
     27 ip route
     28 ```
     29 
     30 Important patterns:
     31 
     32 - `127.0.0.1:<port>` or `[::1]:<port>`: reachable only from the host by default.<sup>[[3]](#references)[[4]](#references)</sup>
     33 - `0.0.0.0:<port>`: reachable on all IPv4 interfaces unless filtered.<sup>[[3]](#references)</sup>
     34 - `10.0.0.0/8`, `172.16.0.0/12`, or `192.168.0.0/16` on `veth*`, `docker*`, `br-*`, `cni*`: likely container or local lab networks.<sup>[[23]](#references)[[24]](#references)</sup>
     35 - Unix sockets under `/run`, `/var/run`, `/tmp`, or application directories: local IPC surfaces.<sup>[[5]](#references)</sup>
     36 
     37 Map local ports with lightweight probes.<sup>[[6]](#references)[[7]](#references)</sup>
     38 
     39 ```bash
     40 for p in 80 443 8000 8080 8081 9000 5000; do
     41   timeout 1 bash -c "echo >/dev/tcp/127.0.0.1/$p" 2>/dev/null && echo "open: $p"
     42 done
     43 ```
     44 
     45 Use `nmap` locally when available.<sup>[[8]](#references)[[9]](#references)[[10]](#references)</sup>
     46 
     47 ```bash
     48 nmap -sT -Pn -p- 127.0.0.1
     49 nmap -sT -Pn --open 127.0.0.1
     50 ```
     51 
     52 ## Hidden veth and Container Subnets
     53 
     54 Containerized or lab environments often expose services only on a bridge or veth subnet. Enumerate interfaces and routes before assuming a service is unreachable.<sup>[[2]](#references)</sup>
     55 
     56 ```bash
     57 ip -br addr
     58 ip route
     59 ip neigh
     60 ```
     61 
     62 Find likely local subnets.<sup>[[2]](#references)</sup>
     63 
     64 ```bash
     65 ip -o -4 addr show | awk '{print $2, $4}'
     66 ```
     67 
     68 Probe a discovered subnet carefully.<sup>[[8]](#references)[[9]](#references)[[10]](#references)</sup>
     69 
     70 ```bash
     71 nmap -sT -Pn --open 172.17.0.0/24
     72 nmap -sT -Pn -p 80,443,8000,8080,9000 172.17.0.0/24
     73 ```
     74 
     75 The technique is useful when a web panel, debug endpoint, or helper service is hidden from external scans but reachable from the compromised host or container network.
     76 
     77 ## Local Pivot With socat or SSH
     78 
     79 If a service is bound to loopback, expose it through an allowed channel instead of changing the service itself.
     80 
     81 Forward a local-only HTTP service with SSH.<sup>[[11]](#references)</sup>
     82 
     83 ```bash
     84 ssh -L 8080:127.0.0.1:8080 user@target
     85 ```
     86 
     87 Bridge a local port with `socat` when you already have shell access.<sup>[[12]](#references)</sup>
     88 
     89 ```bash
     90 socat TCP-LISTEN:18080,fork,reuseaddr TCP:127.0.0.1:8080
     91 ```
     92 
     93 Forward a Unix socket to TCP for local testing.<sup>[[5]](#references)[[12]](#references)</sup>
     94 
     95 ```bash
     96 socat TCP-LISTEN:18081,fork,reuseaddr UNIX-CONNECT:/run/app/app.sock
     97 ```
     98 
     99 This does not exploit anything by itself. It makes a local-only surface reachable from your tooling so you can interact with it like a normal service.
    100 
    101 ## Banner Grabbing and Simple Protocols
    102 
    103 Not every service is HTTP. Many local services leak enough information through a banner or one-line protocol.
    104 
    105 Basic probes.<sup>[[13]](#references)</sup>
    106 
    107 ```bash
    108 nc -nv 127.0.0.1 9000
    109 printf 'help\n' | nc -nv 127.0.0.1 9000
    110 printf 'version\n' | nc -nv 127.0.0.1 9000
    111 ```
    112 
    113 HTTP check without a browser.<sup>[[13]](#references)[[14]](#references)</sup>
    114 
    115 ```bash
    116 printf 'GET / HTTP/1.1\r\nHost: 127.0.0.1\r\nConnection: close\r\n\r\n' | nc -nv 127.0.0.1 8080
    117 curl -i http://127.0.0.1:8080/
    118 ```
    119 
    120 For TLS.<sup>[[14]](#references)[[15]](#references)</sup>
    121 
    122 ```bash
    123 openssl s_client -connect 127.0.0.1:8443 -servername localhost
    124 curl -k -i https://127.0.0.1:8443/
    125 ```
    126 
    127 The goal is to identify the protocol, authentication scheme, version, and whether the service trusts local clients.
    128 
    129 ## Capturing Loopback Traffic
    130 
    131 Local traffic can expose headers, bearer tokens, Basic Auth credentials, or application-specific secrets.<sup>[[17]](#references)[[25]](#references)</sup> Capture only in authorized environments.
    132 
    133 Capture loopback HTTP traffic.<sup>[[16]](#references)</sup>
    134 
    135 ```bash
    136 sudo tcpdump -i lo -A -s0 'tcp port 80 or tcp port 8080'
    137 ```
    138 
    139 Capture a specific local service.<sup>[[16]](#references)</sup>
    140 
    141 ```bash
    142 sudo tcpdump -i lo -w /tmp/loopback.pcap 'tcp port 8080'
    143 ```
    144 
    145 Decode Basic Auth from a captured or logged header.<sup>[[17]](#references)[[18]](#references)</sup>
    146 
    147 ```bash
    148 printf '%s' 'dXNlcjpwYXNz' | base64 -d
    149 ```
    150 
    151 Useful strings to look for in text captures:
    152 
    153 ```bash
    154 grep -Ei 'Authorization:|Cookie:|Bearer|Basic|token|api[_-]?key|password' /tmp/capture.txt
    155 ```
    156 
    157 ## TLS Key Logging
    158 
    159 If you can control the client process environment in a lab, `SSLKEYLOGFILE` can make TLS sessions decryptable in Wireshark or compatible tooling.<sup>[[19]](#references)[[20]](#references)</sup> This is useful for understanding local HTTPS traffic without attacking TLS itself.
    160 
    161 Run a client with key logging enabled.<sup>[[19]](#references)[[20]](#references)</sup>
    162 
    163 ```bash
    164 export SSLKEYLOGFILE=/tmp/sslkeys.log
    165 curl -k https://127.0.0.1:8443/
    166 ls -l /tmp/sslkeys.log
    167 ```
    168 
    169 Capture the traffic at the same time.<sup>[[16]](#references)</sup>
    170 
    171 ```bash
    172 sudo tcpdump -i lo -w /tmp/tls.pcap 'tcp port 8443'
    173 ```
    174 
    175 Then load `/tmp/tls.pcap` and `/tmp/sslkeys.log` into Wireshark. This only works when the client library supports NSS-style key logging and you can set the environment before the connection is made.<sup>[[20]](#references)[[21]](#references)</sup>
    176 
    177 ## Unix Socket Interaction and Command Injection
    178 
    179 Unix sockets are local IPC endpoints.<sup>[[5]](#references)</sup> They may expose HTTP APIs, custom protocols, or unsafe command handlers.<sup>[[12]](#references)[[14]](#references)</sup>
    180 
    181 Find sockets.<sup>[[1]](#references)[[5]](#references)</sup>
    182 
    183 ```bash
    184 ss -lnx
    185 find /run /var/run /tmp -type s -ls 2>/dev/null
    186 ```
    187 
    188 Interact with HTTP over a Unix socket.<sup>[[14]](#references)</sup>
    189 
    190 ```bash
    191 curl --unix-socket /run/app/app.sock http://localhost/
    192 curl --unix-socket /run/app/app.sock -i http://localhost/admin
    193 ```
    194 
    195 Interact with a raw socket.<sup>[[12]](#references)[[13]](#references)</sup>
    196 
    197 ```bash
    198 printf 'status\n' | socat - UNIX-CONNECT:/run/app/app.sock
    199 printf 'help\n' | nc -U /run/app/app.sock
    200 ```
    201 
    202 If user-controlled socket input is passed to a shell or privileged helper, it can become command injection.<sup>[[26]](#references)</sup> For a focused example, see [Socket Command Injection](/hacktricks/linux-hardening/network-information/socket-command-injection).
    203 
    204 ## nftables Review and Authorized Rule Changes
    205 
    206 Local firewall rules may explain why a service is visible locally but blocked remotely, or why a high port appears unreachable from one interface.<sup>[[22]](#references)</sup>
    207 
    208 Review rules.<sup>[[22]](#references)</sup>
    209 
    210 ```bash
    211 sudo nft list ruleset
    212 sudo nft list tables
    213 sudo nft list chains
    214 ```
    215 
    216 Look for drops affecting a target port.<sup>[[22]](#references)</sup>
    217 
    218 ```bash
    219 sudo nft list ruleset | grep -Ei 'drop|reject|dport|tcp|udp'
    220 ```
    221 
    222 In an authorized lab, remove a specific blocking rule by handle.<sup>[[22]](#references)</sup>
    223 
    224 ```bash
    225 sudo nft -a list chain inet filter input
    226 sudo nft delete rule inet filter input handle <handle>
    227 ```
    228 
    229 Prefer deleting the exact handle over flushing full tables. The technique is to identify the precise filter causing the behavior and change only that rule.<sup>[[22]](#references)</sup>
    230 
    231 ## Quick Workflow
    232 
    233 ```bash
    234 ss -lntup
    235 ss -lnx
    236 ip -br addr
    237 ip route
    238 nmap -sT -Pn --open 127.0.0.1
    239 find /run /var/run /tmp -type s -ls 2>/dev/null
    240 sudo nft list ruleset 2>/dev/null | head -n 80
    241 ```
    242 
    243 Prioritize services that are local-only, run as a more privileged user, expose admin/debug functions, or trust loopback/container-network clients.
    244 
    245 ## References
    246 
    247 - [1] [ss(8) — Linux manual page](https://man7.org/linux/man-pages/man8/ss.8.html)
    248 - [2] [ip(8) — Linux manual page](https://man7.org/linux/man-pages/man8/ip.8.html)
    249 - [3] [ip(7) — Linux manual page](https://man7.org/linux/man-pages/man7/ip.7.html)
    250 - [4] [RFC 4291: IP Version 6 Addressing Architecture](https://www.rfc-editor.org/info/rfc4291/)
    251 - [5] [unix(7) — Linux manual page](https://man7.org/linux/man-pages/man7/unix.7.html)
    252 - [6] [Redirections (Bash Reference Manual)](https://www.gnu.org/s/bash/manual/html_node/Redirections.html)
    253 - [7] [timeout invocation (GNU Coreutils)](https://www.gnu.org/s/coreutils/timeout)
    254 - [8] [Port Scanning Techniques (Nmap Reference Guide)](https://nmap.org/book/man-port-scanning-techniques.html)
    255 - [9] [Host Discovery (Nmap Reference Guide)](https://nmap.org/book/man-host-discovery.html)
    256 - [10] [Port Specification and Scan Order (Nmap Reference Guide)](https://nmap.org/book/man-port-specification.html)
    257 - [11] [ssh(1) — Linux manual page](https://man7.org/linux/man-pages/man1/ssh.1.html)
    258 - [12] [socat(1) — Linux manual page](https://www.man7.org/linux/man-pages/man1/socat.1.html)
    259 - [13] [nc(1) — OpenBSD manual page](https://man.openbsd.org/nc.1)
    260 - [14] [curl command line tool manual](https://curl.se/docs/manpage.html?category=23)
    261 - [15] [openssl-s_client — OpenSSL Documentation](https://docs.openssl.org/3.0/man1/openssl-s_client/)
    262 - [16] [tcpdump(8) — Linux manual page](https://man7.org/linux/man-pages/man8/tcpdump.8.html)
    263 - [17] [RFC 7617: The 'Basic' HTTP Authentication Scheme](https://www.rfc-editor.org/rfc/rfc7617.html)
    264 - [18] [base64 invocation (GNU Coreutils)](https://www.gnu.org/software/coreutils/manual/html_node/base64-invocation.html)
    265 - [19] [openssl-env — OpenSSL Documentation](https://docs.openssl.org/master/man7/openssl-env/)
    266 - [20] [TLS — Wireshark Wiki](https://wiki.wireshark.org/tls)
    267 - [21] [Wireshark User’s Guide](https://www.wireshark.org/docs/wsug_html/)
    268 - [22] [nftables manual](https://netfilter.org/projects/nftables/manpage.html)
    269 - [23] [Address Allocation for Private Internets (RFC 1918)](https://www.rfc-editor.org/rfc/rfc1918.html)
    270 - [24] [ip-link(8) — Linux manual page](https://man7.org/linux/man-pages/man8/ip-link.8.html)
    271 - [25] [The OAuth 2.0 Authorization Framework: Bearer Token Usage (RFC 6750)](https://www.rfc-editor.org/rfc/rfc6750.html)
    272 - [26] [CWE-78: Improper Neutralization of Special Elements used in an OS Command](https://cwe.mitre.org/data/definitions/78.html)