Port forwarding is a technique that allows us to redirect a communication request from one port to another. Port forwarding uses TCP as the primary communication layer to provide interactive communication for the forwarded port. However, different application layer protocols such as SSH or even SOCKS (non-application layer) can be used to encapsulate the forwarded traffic. This can be effective in bypassing firewalls and using existing services on your compromised host to pivot to other networks.

nmap -sT -p22,3306 10.129.202.64
Starting Nmap 7.92 ( <https://nmap.org> ) at 2022-02-24 12:12 EST
Nmap scan report for 10.129.202.64
Host is up (0.12s latency).
PORT STATE SERVICE
22/tcp open ssh
3306/tcp closed mysql
to make port forwarding
ssh -L 1234:localhost:3306 [email protected]
now we can nmap this service from our machine like
nmap -sC -sV -p1234 localhost
Forwarding Multiple Ports
SSH -L 1234:localhost:3308 -L 1235:locahhost:8080 -L 1236:localhost:21 ubuntu@IP
Dynamic Port Forwaring
if the Host i compromised see two Network, one of them i can access but the other i cant
so we will make Dynamic Port Forwarding to Forward any traffic
so,
In my Own Machine
SSH -D 9050 ubuntu@IP
and change ProxyChains from /etc/proxychains.conf & add 1270.0.0.1 9050 in the last line
Now if we want use any tool we use proxychains first like
Proxychain nmap -sS -V 172.6.5.1-200
Enumerating the Windows Target through Proxychains

Using Metasploit with Proxychains
proxychains msfconsole
#then use Using rdp_scanner Module
