Pivot, Tunneling and Port Forwarding
SSH
Local port forwarding
ssh -L 1234:localhost:3306 ubuntu@10.129.202.64$ nmap -v -sV -p1234 localhost
PORT STATE SERVICE VERSION
1234/tcp open mysql MySQL 8.0.28-0ubuntu0.20.04.3Web server listening on localhost
user@box:~$ netstat -tulpn
(Not all processes could be identified, non-owned process info
will not be shown, you would have to be root to see it all.)
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
tcp 0 0 127.0.0.1:3306 0.0.0.0:* LISTEN -
tcp 0 0 127.0.0.1:8080 0.0.0.0:* LISTEN -
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN -
tcp 0 0 127.0.0.1:33060 0.0.0.0:* LISTEN -
tcp 0 0 0.0.0.0:80 0.0.0.0:* LISTEN -
tcp 0 0 127.0.0.1:33209 0.0.0.0:* LISTEN -
tcp 0 0 127.0.0.1:37285 0.0.0.0:* LISTEN -
tcp 0 0 127.0.0.53:53 0.0.0.0:* LISTEN -
tcp 0 0 127.0.0.1:3000 0.0.0.0:* LISTEN -
tcp 0 0 127.0.0.1:43765 0.0.0.0:* LISTEN -
tcp6 0 0 :::22 :::* LISTEN -
tcp6 0 0 :::21 :::* LISTEN -
udp 0 0 127.0.0.53:53 0.0.0.0:* -
udp 0 0 0.0.0.0:68 0.0.0.0:* - 
Forwarding multiple ports
Dynamic Port Forwarding with SSH
- sT
Remote / reverse port forward

WinSSH
Metasploit
MSF's SOCKS Proxy
Autoroute
Listing autoroute
MSF local port forward
Meterpreter Reverse Port Forwarding
Resources
Proxychains
tun2socks
Chisel
Socks4
Socks5
Socat
Socat Reverse shell
Socat Bind shell
Plink

SSHuttle
Rpivot
Netsh

DNScat2


ICMP Tunneling
SocksOverRDP




Ligolo-ng - The best tool
References
Double Pivot (and more)


Reverse shell - File Transfer
Tunnel to localhost
Bore
Ngrock
Last updated
