mirror of
https://github.com/Harrison-Wells-Cyber/PS-Proxy
synced 2026-07-26 08:06:34 +00:00
Update README for clarity and accuracy
Clarified instructions and fixed port references in the README.
This commit is contained in:
committed by
GitHub
parent
83d5f99b26
commit
3109ebe005
@@ -3,7 +3,7 @@
|
|||||||
PS-Proxy is a route-based TCP pivot for operators who need to reach internal
|
PS-Proxy is a route-based TCP pivot for operators who need to reach internal
|
||||||
network services from a Linux VPS through a Windows host that can access those
|
network services from a Linux VPS through a Windows host that can access those
|
||||||
services. It is built for TCP-heavy tooling such as Impacket, NetExec,
|
services. It is built for TCP-heavy tooling such as Impacket, NetExec,
|
||||||
RustHound, `ldapsearch`, and TCP-connect `nmap` without proxychains and without
|
and TCP-connect `nmap` without proxychains and without
|
||||||
requiring local administrator privileges on the Windows agent host.
|
requiring local administrator privileges on the Windows agent host.
|
||||||
|
|
||||||
The tool has two parts:
|
The tool has two parts:
|
||||||
@@ -31,7 +31,7 @@ The tool has two parts:
|
|||||||
original destination and asks the agent to open that target from the Windows
|
original destination and asks the agent to open that target from the Windows
|
||||||
side.
|
side.
|
||||||
|
|
||||||
The Windows agent does not intentionally write the managed payload DLL to disk.
|
The Windows agent does not intentionally write the managed payload DLL to disk, maintaining stealth.
|
||||||
Release agents load the embedded assembly with
|
Release agents load the embedded assembly with
|
||||||
`[System.Reflection.Assembly]::Load(byte[])`.
|
`[System.Reflection.Assembly]::Load(byte[])`.
|
||||||
|
|
||||||
@@ -99,8 +99,7 @@ sudo ./psproxy-server \
|
|||||||
```
|
```
|
||||||
|
|
||||||
By default, PS-Proxy listens on `0.0.0.0:443`. If another service already uses
|
By default, PS-Proxy listens on `0.0.0.0:443`. If another service already uses
|
||||||
port 443, set `--listen` or `--port`, or place PS-Proxy behind a fronting load
|
port 443, set `--listen` or `--port`
|
||||||
balancer or reverse proxy that forwards to its own backend port.
|
|
||||||
|
|
||||||
### Run the Windows agent
|
### Run the Windows agent
|
||||||
|
|
||||||
@@ -114,13 +113,15 @@ Run that command in Windows PowerShell 5.1 on the Windows host that can reach th
|
|||||||
internal network. After the agent enrolls, keep the PowerShell session running
|
internal network. After the agent enrolls, keep the PowerShell session running
|
||||||
for as long as you need the tunnel.
|
for as long as you need the tunnel.
|
||||||
|
|
||||||
|
Alternatively, if you don't want to use the irm | iex workflow, the agent can be downloaded
|
||||||
|
from the provided link and ran with . .\agent.ps1
|
||||||
|
|
||||||
### Use your tools
|
### Use your tools
|
||||||
|
|
||||||
From the Linux server, connect to hosts in the routed CIDR directly. For example:
|
From the Linux server, connect to hosts in the routed CIDR directly. For example:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
ldapsearch -x -H ldap://10.10.10.10 -b 'DC=example,DC=local' '(objectClass=domain)'
|
nxc smb 10.10.10.219 -u user -p password -d pwned.local
|
||||||
nmap -sT -Pn -p 445 10.10.10.10
|
|
||||||
```
|
```
|
||||||
|
|
||||||
With `--redirect`, matching TCP connections to `--route` networks are redirected
|
With `--redirect`, matching TCP connections to `--route` networks are redirected
|
||||||
@@ -136,12 +137,12 @@ sudo ./psproxy-server \
|
|||||||
--domain c2.example.com \
|
--domain c2.example.com \
|
||||||
--route 10.10.10.0/24 \
|
--route 10.10.10.0/24 \
|
||||||
--redirect \
|
--redirect \
|
||||||
--dns-listen 127.0.0.1:5353 \
|
--dns-listen 127.0.0.1:53 \
|
||||||
--dns-target 10.10.10.10:53
|
--dns-target 10.10.10.10:53
|
||||||
```
|
```
|
||||||
|
|
||||||
Then point DNS-capable tools at `127.0.0.1:5353` when they support a custom DNS
|
Then point DNS-capable tools at `127.0.0.1:53` when they support a custom DNS
|
||||||
server and port.
|
server.
|
||||||
|
|
||||||
### Optional fixed-target TCP relay
|
### Optional fixed-target TCP relay
|
||||||
|
|
||||||
@@ -173,7 +174,7 @@ ldapsearch -x -H ldap://127.0.0.1:1389 -b 'DC=example,DC=local' '(objectClass=do
|
|||||||
## Build from source
|
## Build from source
|
||||||
|
|
||||||
Use this path if you cloned the repository and want to produce the server binary
|
Use this path if you cloned the repository and want to produce the server binary
|
||||||
and packaged agent assets yourself.
|
and packaged agent assets yourself. (Or don't trust that the base64 blob is clean lol)
|
||||||
|
|
||||||
### Requirements
|
### Requirements
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user