SSH Shenanigans Part #1: Tips & Tricks
SSH is the Swiss army knife of penetration testing. Beyond basic remote shell access, it handles tunneling, pivoting, file transfer, and SOCKS proxying. This covers practical techniques from both offensive and defensive angles - intended for authorized pentest engagements.
SSH config for connection management
During an engagement with many targets, managing connections by hand is painful. Use ~/.ssh/config:
Host jumpbox
HostName 10.10.14.5
User admin
IdentityFile ~/.ssh/engagement_key
Port 2222
Host internal-db
HostName 172.16.0.20
User dbadmin
ProxyJump jumpbox
Host internal-web
HostName 172.16.0.30
User www-data
ProxyJump jumpbox
Now ssh internal-db automatically hops through the jumpbox. No manual tunnels needed.
Port forwarding
Three modes, each serving a different purpose:
Local forward (-L) - access a remote service through a local port:
# Access internal web app on 172.16.0.30:8080 via localhost:9090
ssh -L 9090:172.16.0.30:8080 admin@jumpbox
Remote forward (-R) - expose your local service to the remote network:
# Make your local listener (4444) accessible on jumpbox:4444
ssh -R 4444:127.0.0.1:4444 admin@jumpbox
Dynamic SOCKS proxy (-D) - route any tool through the SSH tunnel:
# SOCKS5 proxy on localhost:1080
ssh -D 1080 admin@jumpbox
# Use with proxychains
proxychains nmap -sT 172.16.0.0/24
Multi-hop pivoting
Chain through multiple compromised hosts to reach deep network segments:
# Old way: nested tunnels
ssh -L 2222:10.0.1.5:22 user@hop1
ssh -L 3333:10.0.2.10:22 -p 2222 user@localhost
# Better way: ProxyJump (-J)
ssh -J user@hop1,user@hop2 user@final-target
ProxyJump chains are cleaner and easier to manage. Each hop is a comma-separated entry.
Operational considerations
When working on a compromised host during an engagement, minimize your footprint:
# Prepend space to prevent command from being saved to history
# (requires HISTCONTROL=ignorespace, which is default on most distros)
ssh-keygen -t ed25519 -f /tmp/.k -N ""
# Check what logging is configured
ls -la /var/log/auth.log /var/log/secure 2>/dev/null
cat /etc/ssh/sshd_config | grep -i log
# Use SSH ControlMaster to multiplex connections (single auth event)
Host *
ControlMaster auto
ControlPath /tmp/.ssh-%r@%h:%p
ControlPersist 600
Always document your access methods and clean up after authorized engagements. These techniques are for legitimate penetration testing - unauthorized access to computer systems is illegal.