Windows: Chisel
Last updated
Last updated
Chisel is an awesome tool which can be used to quickly and easily set up a tunnelled proxy or port forward through a compromised system, regardless of whether you have SSH access or not. It's written in Golang and can be easily compiled for any system (with static release binaries for Linux and Windows provided). In many ways it provides the same functionality as the standard SSH proxying / port forwarding we covered earlier; however, the fact it doesn't require SSH access on the compromised target is a big bonus.
Download the latest release and gunzip it:
You must have an appropriate copy of the chisel binary on both the attacking machine and the compromised server. Copy the file to the remote server with your choice of file transfer method.
On Kali, append the following line to /etc/proxychains4.conf
:
On Kali, set up a Chisel server on port 8000:
Transfer chisel.exe
to the compromised Windows machine. On that machine, create a SOCKS5 reverse proxy:
At this stage, we can reach our target by prepending proxychains -q
to every command. For instance: