• XSS.stack #1 – первый литературный журнал от юзеров форума

Pivoting Cobalt Strike Socks4 > Terminal

notactive

HDD-drive
Пользователь
Регистрация
08.11.2022
Сообщения
26
Реакции
8
I've been experimenting with a lot Cobalt Strike, but I've found that it's not always as effective as I'd like. I'm more accustomed to using terminal-based pentesting tools, and I'm exploring ways to integrate them for better results.

I came across some posts suggesting the setup of a SOCKS proxy on a target within Cobalt Strike. The idea is to configure my pentesting machine to connect through this proxy using the 'socks4 <CS_IP> <Socks_Number>' command. However, despite following these steps, I haven't been able to make it work. I'm curious if there are any approaches or ideas that could achieve this outcome effectively.

Example:

Setting up the Socks on my targets host.
1708790385624.png


Adding the Proxychains with:

Protocol: Socks4
C2_SRV_IP: My C2 Server IP
Port: Socks Port
1708790457725.png


After I want to scan the network with nbstscan for example or do any other commands, I get no results back.

Command:
proxychains nbtscan 192.168.1.0/24, no results are returned
 
set sleep to 0 and everything will work outI've been experimenting with a lot Cobalt Strike, but I've found that it's not always as effective as I'd like. I'm more accustomed to using terminal-based pentesting tools, and I'm exploring ways to integrate them for better results.

I came across some posts suggesting the setup of a SOCKS proxy on a target within Cobalt Strike. The idea is to configure my pentesting machine to connect through this proxy using the 'socks4 <CS_IP> <Socks_Number>' command. However, despite following these steps, I haven't been able to make it work. I'm curious if there are any approaches or ideas that could achieve this outcome effectively.

Example:

Setting up the Socks on my targets host.
Посмотреть вложение 77998

Adding the Proxychains with:

Protocol: Socks4
C2_SRV_IP: My C2 Server IP
Port: Socks Port
Посмотреть вложение 77999

After I want to scan the network with nbstscan for example or do any other commands, I get no results back.

Command:
proxychains nbtscan 192.168.1.0/24, no results are returned
Set sleep to 0 and everything will work out
Снимок экрана от 2024-03-05 18-07-13.png
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх