SSH is not only a shell; its forwarding features make it a pivoting tool, and an attacker uses them exactly as an administrator would. Local and remote port forwarding bridge a service across a network boundary the attacker cannot otherwise cross. Dynamic forwarding stands up a SOCKS proxy that routes arbitrary tools through the SSH host into networks behind it. Jump-host (ProxyJump) chaining hops through bastions deep into segmented environments. And SSH agent forwarding, when a user forwards their agent to a host the attacker controls, leaves a usable authentication channel to move onward as that user.
# the four building blocks
ssh -L 8080:internal:80 user@pivot # local forward: reach internal:80 via pivot
ssh -R 9001:localhost:9001 user@pivot # remote forward: expose attacker service on pivot
ssh -D 1080 user@pivot # dynamic: SOCKS proxy through pivot
ssh -J user@bastion user@internal # jump through bastion to internal
Subtopics#
- Port forwarding: local and remote forwarding across boundaries.
- SOCKS proxy: dynamic forwarding for arbitrary onward access.
- Jump host abuse: chaining through bastions into segmented networks.
- Agent hijacking: reusing a forwarded SSH agent.