当前位置:网站首页>Portmap port forwarding
Portmap port forwarding
2022-07-24 17:09:00 【ailx10】
We have learned before ssh Port forwarding 、 Firewall port forwarding 、rinetd Port forwarding 、nc Port forwarding 、socat Port forwarding , Today we are going to study portmap Port forwarding ,portmap yes Linux Under the LCX, Naturally, let's review it first windows Under the LCX:「ailx10:Lcx Port forwarding 」, This experiment really cost a lot of effort at the beginning , It's really not easy , Now review , It's very simple , I'm afraid this is called growth , There are colored eggs at the end of the article ~
Experimental environment :
- macos:192.168.199.206
- kali:192.168.199.247
- centos:192.168.199.236
- win7:192.168.199.233
Experiment 1 : Borrow the springboard kali, Visit the intranet centos Of 22 port
stay kali Up operation , take kali Of 7777 The port points to centos Of 22 port
./portmap -m 1 -p1 7777 -h2 192.168.199.236 -p2 22stay macos Up operation , Access the springboard machine kali Of 7777 port , Is to visit the intranet centos Of 22 port
ssh 192.168.199.247 -p 7777
It's simple , experiment 2 And experiments 3 In fact, it is similar to the experiment 1 For the same purpose , To verify portmap In the help document 3 Patterns , You don't have to look at
Socket data transport tool
by Sofia(www.vuln.cn)
Usage:./portmap -m method [-h1 host1] -p1 port1 [-h2 host2] -p2 port2 [-v] [-log filename]
-v: version
-h1: host1
-h2: host2
-p1: port1
-p2: port2
-log: log the data
-m: the action method for this tool
1: listen on PORT1 and connect to HOST2:PORT2
2: listen on PORT1 and PORT2
3: connect to HOST1:PORT1 and HOST2:PORT2
Let me exit...all overd
Experiment two : Borrow the springboard centos, Visit the intranet kali Of 22 port
stay centos Run command on , open 6666 Port and 7777 port ,6666 The port is connected to the intranet kali signal communication ,7777 Ports are with hackers macos signal communication
./portmap -m 2 -p1 6666 -h2 192.168.199.236 -p2 7777stay kali Run command on , Put the intranet kali Of 22 Port and springboard centos Of 6666 Port for bundling
./portmap -m 3 -h1 127.0.0.1 -p1 22 -h2 192.168.199.236 -p2 6666stay macos Run command on , Connecting springboard machine centos Of 7777 port , It will pass through the springboard centos Of 6666 port , Flow into Intranet kali Of 22 port
ssh 192.168.199.236 -p 7777
Experiment three : Borrow the springboard centos、win7 Of 3389 port , Visit the intranet kali Of 22 port
stay centos Run command on ,6666 Port to and kali signal communication ,3389 Port to and macos signal communication
./portmap -m 2 -p1 6666 -h2 192.168.199.233 -p2 3389
stay kali Run command on
./portmap -m 3 -h1 127.0.0.1 -p1 22 -h2 192.168.199.236 -p2 6666stay macos Run command on
ssh 192.168.199.236 -p 3389Finally, inexplicably, it also succeeded

Bag grabbing discovery ,macos and win7 There is no communication

And we set up win7 Of 3389 port , Here it becomes the source port , yes macos and centos Communication between , It's amazing

Network security has a long way to go , Wash and sleep ~

Colored eggs :LCX Experiment review
Bear in mind : step 1、2 The order cannot be reversed , Otherwise, the experiment will not succeed
1、 Run on the intranet host , Put the springboard machine 4444 Port and intranet 3389 Ports are bound together
Lcx.exe -slave 192.168.160.139 4444 127.0.0.1 33892、 At the springboard (192.168.160.139) Up operation ,4444 Port and Intranet communication ,5555 Port communicates with hackers
Lcx.exe -listen 4444 55553、 Run on the attacker , thank @whywelive stay 2021 year 7 Monthly reminder
Lcx.exe -tran 6666 192.168.160.139 55554、 Attackers access their own 6666 port , You can access the intranet 3389 port

actually , step 3 You can ignore , Go straight to step 4, Visit the springboard 5555 port , You can access the intranet 3389 port

边栏推荐
- Cann training camp learns the animation stylization and AOE ATC tuning of the second season of 2022 model series
- 自定义类型:枚举
- Navicate connects Alibaba cloud (explanation of two methods and principles)
- The latest Zhejiang construction safety officer simulation question bank and answers in 2022
- 数字化转型一定要有数字化思想
- Shardingsphere database read / write separation
- Coldplay weekly issue 10
- Interview question 01.02. determine whether it is character rearrangement
- Problems encountered in upgrading chrome to version 80 - solutions to system login failure
- Pull and load more on wechat applet list rendering
猜你喜欢

安全:如何为行人提供更多保护

JSP custom tag library --foreach

Notebook computer purchase guide (specific brand and model are not recommended)

Meeting OA project progress (I)

量化框架backtrader之一文读懂Indicator指标

Still developing games with unity? Then you're out. Try unity to build an answer system

Kyligence attended the Huawei global smart finance summit to accelerate the expansion of the global market

opencv自带颜色操作

Template method mode

socat 端口转发
随机推荐
QT graphical interface beginner project - unmanned aerial vehicle group combat simulation
socat 端口转发
The latest Zhejiang construction safety officer simulation question bank and answers in 2022
GDB online debugging of work notes
Yolopose practice: one-stage human posture estimation with hands + code interpretation
Safety: how to provide more protection for pedestrians
The differences of several deletions in SQL
OS Experiment 5 process switching based on kernel stack switching
别再到处乱放配置文件了!试试我司使用 7 年的这套解决方案,稳的一秕
Exception handling - a small case that takes you to solve NullPointerException
Is it safe for Mr. qiniu to open a securities account? Can I drive it?
Bring 120W goods in 15 seconds. You can also shoot such a popular video
nc 端口转发
DBF menu driver: librarydatabaseproject
One article of quantitative framework backtrader: understand indicator indicators
Digital transformation must have digital thinking
What should we pay attention to in the resume of software testing?
[数组]NC143 矩阵乘法-简单
Method of querying comma separated strings in a field by MySQL
CDN (content delivery network) content distribution network from entry to practice