ssh-tunneling

Installation
SKILL.md

ssh-tunneling (and sshuttle)

Goal: Exploit authorized or compromised SSH access to route attack traffic into internal subnets, bypassing firewalls and NAT without needing external binaries like Chisel.

Cognitive Stance

SSH is the quintessential "Living off the Land" pivoting tool on Unix systems.

  • If you need to access multiple internal subnets dynamically, use Sshuttle (if Python is present on the target) or Dynamic Port Forwarding (-D).
  • If you only need to expose one internal port to your attacker machine, use Local Port Forwarding (-L).
  • If you need your attacker machine to receive callbacks from the internal network (e.g. reverse shells), use Remote Port Forwarding (-R).

1. Dynamic Port Forwarding (SOCKS4 / SOCKS5)

# Creates a SOCKS proxy on your attacker machine at 127.0.0.1:1080 
# -f: go to background, -N: do not execute remote command
ssh -fN -D 1080 user@<COMPROMISED_HOST>

Setup: Ensure /etc/proxychains4.conf has socks4 127.0.0.1 1080 (or socks5). You can now run proxychains4 nmap -sT ... to scan the internal network safely. TCP only.

Installs
4
GitHub Stars
22
First Seen
Sep 5, 2026
ssh-tunneling — aeondave/malskill