Port Forwarding in Context

Port forwarding is a technique that allows us to redirect a communication request from one port to another. Port forwarding uses TCP as the primary communication layer to provide interactive communication for the forwarded port. However, different application layer protocols such as SSH or even SOCKS (non-application layer) can be used to encapsulate the forwarded traffic. This can be effective in bypassing firewalls and using existing services on your compromised host to pivot to other networks.

image.png

nmap -sT -p22,3306 10.129.202.64

Starting Nmap 7.92 ( <https://nmap.org> ) at 2022-02-24 12:12 EST
Nmap scan report for 10.129.202.64
Host is up (0.12s latency).

PORT     STATE  SERVICE
22/tcp   open   ssh
3306/tcp closed mysql

to make port forwarding

 ssh -L 1234:localhost:3306 [email protected]

now we can nmap this service from our machine like

nmap -sC -sV -p1234 localhost

Forwarding Multiple Ports

SSH -L 1234:localhost:3308 -L 1235:locahhost:8080 -L 1236:localhost:21 ubuntu@IP

Dynamic Port Forwaring

if the Host i compromised see two Network, one of them i can access but the other i cant
so we will make Dynamic Port Forwarding to Forward any traffic
so, 

In my Own Machine 
SSH -D 9050 ubuntu@IP 
and change ProxyChains from /etc/proxychains.conf & add 1270.0.0.1 9050 in the last line

Now if we want use any tool we use proxychains first like 
Proxychain nmap -sS -V 172.6.5.1-200

Enumerating the Windows Target through Proxychains

image.png

Using Metasploit with Proxychains

proxychains msfconsole 

#then use Using rdp_scanner Module

image.png