wiki created
This commit is contained in:
@@ -0,0 +1,61 @@
|
||||
# rpfwd - Reverse Port Forwarding
|
||||
|
||||
Start or stop reverse port forwarding (RPFWD).
|
||||
|
||||
## Description
|
||||
|
||||
The `rpfwd` command starts or stops reverse port forwarding (RPFWD). When started, the agent listens on a local port on the target system. Connections to this local port are forwarded through the agent to Mythic, which then connects to a remote destination.
|
||||
|
||||
## Syntax
|
||||
|
||||
```
|
||||
rpfwd {"action":"start","port":8080,"remote_host":"127.0.0.1","remote_port":80}
|
||||
rpfwd {"action":"stop","port":8080}
|
||||
```
|
||||
|
||||
## Parameters
|
||||
|
||||
- `action` (required): Either `"start"` or `"stop"`
|
||||
- `port` (required for start): Local port on the agent to listen on (default: 8080)
|
||||
- `remote_host` (required for start): Remote host to forward connections to
|
||||
- `remote_port` (required for start): Remote port to forward connections to
|
||||
|
||||
## Examples
|
||||
|
||||
```
|
||||
rpfwd {"action":"start","port":8080,"remote_host":"192.168.1.100","remote_port":80}
|
||||
rpfwd {"action":"start","port":3306,"remote_host":"10.0.0.50","remote_port":3306}
|
||||
rpfwd {"action":"stop","port":8080}
|
||||
```
|
||||
|
||||
## Features
|
||||
|
||||
- When started, the agent listens on a local port on the target system
|
||||
- Connections to this local port are forwarded through the agent to Mythic, which then connects to a remote destination (remote_host:remote_port)
|
||||
- Default local port: 8080
|
||||
- Useful for accessing services on the target network that are not directly reachable from Mythic (e.g., internal services, databases, management interfaces)
|
||||
- WARNING: Reverse port forwarding creates persistent network connections and may be detected by network monitoring, firewall logging, NIDS, and EDR/XDR network monitoring
|
||||
- Avoid using privileged ports (<1024) which require elevated privileges
|
||||
|
||||
## Output
|
||||
|
||||
```
|
||||
[rpfwd] Reverse port forwarding started on port 8080
|
||||
[rpfwd] Forwarding connections to: 192.168.1.100:80
|
||||
```
|
||||
|
||||
## OPSEC Considerations
|
||||
|
||||
- Reverse port forwarding creates persistent network connections
|
||||
- May be detected by network monitoring, firewall logging, NIDS, and EDR/XDR network monitoring
|
||||
- Avoid using privileged ports (<1024) which require elevated privileges
|
||||
- Consider the operational impact before starting
|
||||
|
||||
## Related
|
||||
|
||||
[Reverse Port Forwarding Support](../../../features.md#reverse-port-forwarding-rpfwd-support), [Usage Examples](../../../examples.md#reverse-port-forwarding-example)
|
||||
|
||||
---
|
||||
|
||||
**Command Category:** Network Tunneling
|
||||
**Requires Admin:** No
|
||||
Reference in New Issue
Block a user