daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

1080-pentesting-socks.md (3731B)


      1 ---
      2 title: "1080 - Pentesting Socks"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/1080-pentesting-socks.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/1080-pentesting-socks.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 1080 - Pentesting Socks
     14 
     15 ## Basic Information
     16 
     17 **SOCKS** relays traffic between a client and a destination through a proxy. SOCKS5 negotiates authentication methods, supports TCP `CONNECT` and `BIND`, and can relay UDP through `UDP ASSOCIATE`. Username/password authentication is a separate optional sub-negotiation. `socks5h` is a client convention that asks the proxy to resolve hostnames, avoiding local DNS resolution.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup>
     18 
     19 **Default Port:** 1080
     20 
     21 ## Enumeration
     22 
     23 ### Authentication Check
     24 
     25 ```bash
     26 nmap -p 1080 <ip> --script socks-auth-info
     27 ```
     28 
     29 The Nmap script reports the SOCKS5 authentication methods offered by the server.<sup>[[3]](#references)</sup>
     30 
     31 ### Brute Force
     32 
     33 #### Basic usage
     34 
     35 ```bash
     36 nmap --script socks-brute -p 1080 <ip>
     37 ```
     38 
     39 #### Advanced usage
     40 
     41 ```bash
     42 nmap  --script socks-brute --script-args userdb=users.txt,passdb=rockyou.txt,unpwdb.timelimit=30m -p 1080 <ip>
     43 ```
     44 
     45 #### Output
     46 
     47 ```text
     48 PORT     STATE SERVICE
     49 1080/tcp open  socks
     50 | socks-brute:
     51 |   Accounts
     52 |     patrik:12345 - Valid credentials
     53 |   Statistics
     54 |_    Performed 1921 guesses in 6 seconds, average tps: 320
     55 ```
     56 
     57 #### Hydra module
     58 
     59 ```bash
     60 hydra -L users.txt -P passwords.txt -s 1080 -t 16 -V <ip> socks5
     61 ```
     62 
     63 ### Method & open-proxy enumeration
     64 
     65 ```bash
     66 nmap -sV --script socks-methods,socks-open-proxy -p 1080 <ip>
     67 ```
     68 
     69 `socks-methods` asks the server about supported authentication types, while `socks-open-proxy` attempts an outbound connection to confirm whether the service can be abused as a relay.<sup>[[3]](#references)</sup><sup>[[4]](#references)</sup>
     70 
     71 #### Raw handshake check
     72 
     73 ```bash
     74 printf '\x05\x01\x00' | nc -nv <ip> 1080
     75 ```
     76 
     77 The three-byte request is `VER=05`, `NMETHODS=01`, `METHOD=00`. A successful two-byte reply of `\x05\x00` selects no authentication; `\x05\x02` selects username/password; `\x05\xff` means no offered method is acceptable.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup>
     78 
     79 ### Quick egress validation
     80 
     81 ```bash
     82 curl --socks5-hostname <ip>:1080 https://ifconfig.me
     83 curl --socks5-hostname user:pass@<ip>:1080 http://internal.target
     84 ```
     85 
     86 Use `--socks5-hostname` (or `socks5h://` URLs) so DNS resolution happens remotely. Pair it with `proxychains4 -q nmap -sT -Pn --top-ports 200 <internal-host>` to verify whether the proxy truly provides internal reach.
     87 
     88 ### Internet-wide discovery / fingerprinting
     89 
     90 ```bash
     91 masscan 0.0.0.0/0 -p1080 --banners --rate 100000 -oX socks.xml
     92 ```
     93 
     94 Feed results back into NSE, `zgrab2`, or custom python scripts to prioritize promising hosts (e.g., banner strings like `3proxy`, `Dante`, `MikroTik`).
     95 
     96 
     97 ## Tunneling and Port Forwarding
     98 
     99 For info about tunneling and post forwarding check the page: [Tunneling and Port Forwarding](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/tunneling-and-port-forwarding.md)
    100 
    101 ## References
    102 
    103 - [1] [RFC 1928 - SOCKS Protocol Version 5](https://www.rfc-editor.org/rfc/rfc1928)
    104 - [2] [RFC 1929 - Username/Password Authentication for SOCKS V5](https://www.rfc-editor.org/rfc/rfc1929)
    105 - [3] [Nmap - `socks-auth-info`](https://nmap.org/nsedoc/scripts/socks-auth-info.html)
    106 - [4] [Nmap - `socks-open-proxy`](https://nmap.org/nsedoc/scripts/socks-open-proxy.html)