{"id":34725,"date":"2019-10-31T22:00:00","date_gmt":"2019-10-31T19:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/pishem-reverse-socks5-proxy-na-powershell-chast-1\/"},"modified":"2019-10-31T22:00:00","modified_gmt":"2019-10-31T19:00:00","slug":"pishem-reverse-socks5-proxy-na-powershell-chast-1","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/pishem-reverse-socks5-proxy-na-powershell-chast-1","title":{"rendered":"Shkruajm\u00eb Reverse socks5 proxy n\u00eb PowerShell. Pjesa 1","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Historia e k\u00ebrkimit dhe zhvillimit n\u00eb 3 pjes\u00eb. Pjesa 1 \u2014 k\u00ebrkimi.<br \/>\nKa shum\u00eb libra \u2014 por edhe m\u00eb shum\u00eb dobi.<\/p>\n<h3>Vendosja e detyr\u00ebs<\/h3>\n<p>\nGjat\u00eb realizimit t\u00eb p\u00ebntest\u00ebve dhe fushatave RedTeam, nuk \u00ebsht\u00eb gjithmon\u00eb e mundur t\u00eb p\u00ebrdoren mjetet standarde t\u00eb Klient\u00ebve, si VPN, RDP, Citrix etj., p\u00ebr t\u00eb hyr\u00eb n\u00eb rrjetin e brendsh\u00ebm. Ndonj\u00ebher\u00eb VPN-i standard punon me MFA dhe si faktor i dyt\u00eb p\u00ebrdoret nj\u00eb token fizik, ndonj\u00ebher\u00eb monitorohet ashp\u00ebr dhe hyrja jon\u00eb p\u00ebrmes VPN-it b\u00ebhet e dukshme menj\u00ebher\u00eb, si\u00e7 thon\u00eb \u2014 me t\u00eb gjitha pasojat, dhe n\u00eb disa raste nuk ka fare k\u00ebto mjete. <\/p>\n<p>N\u00eb raste t\u00eb tilla, \u00ebsht\u00eb e nevojshme t\u00eb krijohen vazhdimisht k\u00ebshtu quajturat \"tuneli t\u00eb kund\u00ebrt\" \u2014 lidhje nga rrjeti i brendsh\u00ebm n\u00eb nj\u00eb burim t\u00eb jasht\u00ebm ose nj\u00eb server t\u00eb kontrolluar nga ne. N\u00eb brend\u00ebsi t\u00eb k\u00ebtij tuneli, mund t\u00eb punojm\u00eb me resurset e brendshme t\u00eb Klient\u00ebve.<\/p>\n<p>Ekzistojn\u00eb disa lloje t\u00eb till\u00eb tunesh t\u00eb kund\u00ebrt. I njohuri \u00ebsht\u00eb, sigurisht, Meterpreter. Po ashtu, shum\u00eb t\u00eb p\u00ebrdorura n\u00eb radh\u00ebt e haker\u00ebve jan\u00eb tunel\u00ebt SSH me port p\u00ebr t\u00eb kund\u00ebrt. Ka shum\u00eb mjete p\u00ebr realizimin e tunelimit t\u00eb kund\u00ebrt dhe shum\u00eb prej tyre jan\u00eb studiuar mir\u00eb dhe jan\u00eb p\u00ebrshkruar.<br \/>\nSigurisht, nga ana e tyre, zhvilluesit e zgjidhjeve mbrojt\u00ebse nuk q\u00ebndrojn\u00eb m\u00ebnjan\u00eb dhe aktivisht detektojn\u00eb veprime t\u00eb tilla.<br \/>\nP\u00ebr shembull, seancat MSF detektohen me sukses nga IPS moderne nga Cisco ose Positive Tech, nd\u00ebrsa nj\u00eb tunel t\u00eb kund\u00ebrt SSH mund t\u00eb zbulohen praktikisht nga \u00e7do firewall normal.<\/p>\n<p>Prandaj, p\u00ebr t\u00eb mbetur t\u00eb paduksh\u00ebm n\u00eb nj\u00eb fushat\u00eb t\u00eb mir\u00eb RedTeam \u2014 ne duhet t\u00eb krijojm\u00eb tunelin e kund\u00ebrt me mjete jo standarde dhe t\u00eb p\u00ebrshtatemi sa m\u00eb af\u00ebr m\u00ebnyr\u00ebs reale t\u00eb pun\u00ebs s\u00eb rrjetit.<\/p>\n<p>Le t\u00eb p\u00ebrpiqemi t\u00eb gjejm\u00eb ose t\u00eb shpikim di\u00e7ka t\u00eb till\u00eb.<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\nPara se t\u00eb shpikim di\u00e7ka, duhet t\u00eb kuptojm\u00eb se \u00e7far\u00eb rezultati duam t\u00eb arrijm\u00eb, cilat funksione duhet t\u00eb plot\u00ebsoj\u00eb zhvillimi yn\u00eb. Cilat do t\u00eb jen\u00eb k\u00ebrkesat p\u00ebr tunelin, q\u00eb ne t\u00eb mund t\u00eb punojm\u00eb n\u00eb nj\u00eb mod maksimumi t\u00eb fsheht\u00eb?<\/p>\n<p>\u00cbsht\u00eb e qart\u00eb se p\u00ebr \u00e7do rast k\u00ebrkesat mund t\u00eb ndryshojn\u00eb ndjesh\u00ebm, por nga p\u00ebrvoja e pun\u00ebs mund t\u00eb identifikojm\u00eb disa k\u00ebrkesa kryesore:<\/p>\n<ul>\n<li> punon n\u00eb sistemet operative Windows-7-10. Sepse n\u00eb shumic\u00ebn e rrjeteve korporative p\u00ebrdoret pik\u00ebrisht Windows;<\/li>\n<li> klienti lidhet me serverin p\u00ebrmes SSL p\u00ebr t\u00eb p\u00ebrjashtuar ndjekjen e thjesht\u00eb nga mjetet ips;<\/li>\n<li> kur lidhja b\u00ebhet, klienti duhet t\u00eb mb\u00ebshtes\u00eb pun\u00ebn p\u00ebrmes nj\u00eb serveri proxy me autorizim, sepse n\u00eb shum\u00eb kompani, dalja n\u00eb internet ndodh p\u00ebrmes proxy. N\u00eb t\u00eb v\u00ebrtet\u00eb, makina klient mund t\u00eb mos e dij\u00eb fare k\u00ebt\u00eb, dhe proxy p\u00ebrdoret n\u00eb mod transparence. Por k\u00ebt\u00eb funksionalitet ne duhet ta parashikojm\u00eb;<\/li>\n<li> pjesa klient duhet t\u00eb jet\u00eb e thjesht\u00eb dhe portable;<br \/>\nSigurisht, p\u00ebr t\u00eb punuar brenda rrjetit t\u00eb Klientit, n\u00eb makin\u00ebn klient mund t\u00eb instalojm\u00eb OpenVPN dhe t\u00eb ngrisim nj\u00eb tunel t\u00eb plot\u00eb deri n\u00eb serverin ton\u00eb (p\u00ebr fat t\u00eb mir\u00eb, klient\u00ebt e openvpn din\u00eb t\u00eb punojn\u00eb p\u00ebrmes proxy). Por, s\u00eb pari, kjo nuk funksionon gjithmon\u00eb, pasi mund t\u00eb mos jemi administrat\u00eb lokale aty, dhe s\u00eb dyti, krijon aq shum\u00eb zhurm\u00eb sa q\u00eb nj\u00eb SIEM i rregullt ose HIPS do t\u00eb 'informoj\u00eb' menj\u00ebher\u00eb p\u00ebr ne. N\u00eb ideal, klienti yn\u00eb duhet t\u00eb jet\u00eb nj\u00eb ekip i quajtur inline, si\u00e7 \u00ebsht\u00eb realizuar n\u00eb shum\u00eb shell-e bash, dhe t\u00eb fillohet p\u00ebrmes komand\u00ebs, p\u00ebr shembull, kur ekzekutohet komandat nga makros nga Word.<\/li>\n<li> tuneli yn\u00eb duhet t\u00eb jet\u00eb shum\u00eb-fibrik dhe t\u00eb mb\u00ebshtes\u00eb shum\u00eb lidhje nj\u00ebkoh\u00ebsisht;<\/li>\n<li> lidhja klient-server duhet t\u00eb ket\u00eb ndonj\u00eb autorizim, n\u00eb m\u00ebnyr\u00eb q\u00eb tuneli t\u00eb vendoset vet\u00ebm p\u00ebr klientin ton\u00eb, dhe jo p\u00ebr t\u00eb gjith\u00eb ata q\u00eb vijn\u00eb n\u00eb serverin ton\u00eb n\u00eb adres\u00ebn dhe portin e caktuar. N\u00eb ideal, p\u00ebr 'p\u00ebrdoruesit e jasht\u00ebm', duhet t\u00eb hapet nj\u00eb faqe n\u00eb t\u00eb cil\u00ebn shfaqen kafsh\u00eb t\u00eb vogla ose tema profesionale t\u00eb lidhura me domainin burim.<br \/>\nP\u00ebr shembull, n\u00ebse Klienti \u00ebsht\u00eb nj\u00eb organizat\u00eb mjek\u00ebsore, at\u00ebher\u00eb p\u00ebr administruesin e siguris\u00eb s\u00eb informacionit, t\u00eb vendosur t\u00eb kontrolloj\u00eb burimin q\u00eb ka vizituar punonj\u00ebsi i klinik\u00ebs, duhet t\u00eb hapet nj\u00eb faqe me produkte farmaceutike, Wikipedia me p\u00ebrshkrimin e diagnoz\u00ebs ose blogu i doktor Komarovskit etj. <\/li>\n<\/ul>\n<p><\/p>\n<h3>Analiza e mjeteve ekzistuese<\/h3>\n<p>\nPara se t\u00eb shpikim bi\u00e7iklet\u00ebn ton\u00eb \u2014 \u00ebsht\u00eb e nevojshme t\u00eb b\u00ebjm\u00eb nj\u00eb analiz\u00eb t\u00eb bi\u00e7ikletave ekzistuese dhe t\u00eb kuptojm\u00eb n\u00ebse p\u00ebr t\u00eb v\u00ebrtet\u00eb na nevojitet dhe ndoshta nuk jemi vet\u00ebm q\u00eb kemi menduar p\u00ebr nevoj\u00ebn e nj\u00eb bi\u00e7iklete funksionale t\u00eb till\u00eb.<\/p>\n<p>K\u00ebrkimi n\u00eb internet (duket se po e b\u00ebjm\u00eb mjaft mir\u00eb), si dhe k\u00ebrkimi n\u00eb GitHub me fjal\u00ebt ky\u00e7e \"reverse socks\" nuk ka dh\u00ebn\u00eb shum\u00eb rezultate. Kryesisht, gjith\u00e7ka ka t\u00eb b\u00ebj\u00eb me nd\u00ebrtimin e tunel\u00ebve ssh me port forwarding t\u00eb kund\u00ebrt dhe gjith\u00e7ka tjet\u00ebr q\u00eb lidhet me t\u00eb. P\u00ebrve\u00e7 tunel\u00ebve SSH, mund t\u00eb ve\u00e7ojm\u00eb disa zgjidhje:<\/p>\n<p><b><noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/klsecservices\/rpivot\">github.com\/klsecservices\/rpivot<\/a><\/noindex><\/b><br \/>\nNj\u00eb implementim i vjet\u00ebr i tunelit t\u00eb kund\u00ebrt nga ekipi i Laboratorit Kaspersky. Nga emri \u00ebsht\u00eb e qart\u00eb p\u00ebr \u00e7far\u00eb \u00ebsht\u00eb krijuar ky skript. \u00cbsht\u00eb realizuar n\u00eb Python 2.7, tuneli punon n\u00eb m\u00ebnyr\u00eb cleartext (si\u00e7 thuhet tani \u2014 p\u00ebrsh\u00ebndetje RKN)<\/p>\n<p><b><noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/tonyseek\/rsocks\">github.com\/tonyseek\/rsocks<\/a><\/noindex><\/b><br \/>\nNj\u00eb tjet\u00ebr implementim n\u00eb Python, gjithashtu n\u00eb cleartext, por me m\u00eb shum\u00eb mund\u00ebsi. \u00cbsht\u00eb shkruar si nj\u00eb modul dhe ka API p\u00ebr integrim n\u00eb projektet e tua.<\/p>\n<p><b><noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/llkat\/rsockstun\">github.com\/llkat\/rsockstun<\/a><\/noindex><\/b><br \/>\n<b><noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/mis-team\/rsockstun\">github.com\/mis-team\/rsockstun<\/a><\/noindex><\/b><br \/>\nLidhja e par\u00eb \u2014 versioni origjinal i implementimit t\u00eb reverse socks n\u00eb Golang (nuk mb\u00ebshtetet nga zhvilluesi).<br \/>\nLidhja e dyt\u00eb \u2014 \u00ebsht\u00eb p\u00ebrmir\u00ebsimi yn\u00eb me karakteristika shtes\u00eb, gjithashtu n\u00eb Golang. N\u00eb versionin ton\u00eb kemi implementuar SSL, pun\u00eb p\u00ebrmes proxy me autorizim NTLM, autorizimin n\u00eb klient, faqe njohjeje n\u00eb rast t\u00eb fjal\u00ebkalimit t\u00eb gabuar (me sakt\u00ebsi \u2014 redirect n\u00eb faqen njoh\u00ebse), modin shum\u00eb-fijor (dmth. disa njer\u00ebz mund t\u00eb punojn\u00eb me tunelin nj\u00ebkoh\u00ebsisht), sistemin e pings p\u00ebr klientin p\u00ebr t\u00eb par\u00eb n\u00ebse \u00ebsht\u00eb aktiv apo jo.<\/p>\n<p><b><noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/jun7th\/tsocks\">github.com\/jun7th\/tsocks<\/a><\/noindex><\/b><br \/>\nImplementimi i reverse socks nga \"miqt\u00eb tan\u00eb kinez\u00eb\" n\u00eb Python. Po ashtu, p\u00ebr ata q\u00eb jan\u00eb t\u00eb lenj, ka nj\u00eb binary t\u00eb gatsh\u00ebm (exe), e p\u00ebrgatitur nga kinez\u00ebt dhe gati p\u00ebr p\u00ebrdorim. K\u00ebtu vet\u00ebm Zoti kinez e di se \u00e7far\u00eb tjet\u00ebr mund t\u00eb ket\u00eb n\u00eb k\u00ebt\u00eb binary, p\u00ebrve\u00e7 funksionalitetit kryesor, prandaj p\u00ebrdorini me kujdes.<\/p>\n<p><b><noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/securesocketfunneling\/ssf\">github.com\/securesocketfunneling\/ssf<\/a><\/noindex><\/b><br \/>\nNj\u00eb projekt mjaft interesant n\u00eb C++ p\u00ebr realizimin e reverse socks dhe jo vet\u00ebm. P\u00ebrve\u00e7 tunelit t\u00eb kund\u00ebrt, ai mund t\u00eb realizoj\u00eb port forwarding, krijimin e shell komandash, etj.<\/p>\n<p><b>MSF meterpreter<\/b><br \/>\nSi\u00e7 thon\u00eb, pa kommentare. T\u00eb gjith\u00eb hacker\u00ebt disi t\u00eb arsimuar jan\u00eb t\u00eb njohur mir\u00eb me k\u00ebt\u00eb gj\u00eb dhe kuptojn\u00eb se sa leht\u00eb zbulohet nga mjetet e mbrojtjes.<\/p>\n<p>T\u00eb gjitha mjetet e p\u00ebrmendura m\u00eb sip\u00ebr punojn\u00eb me nj\u00eb teknologji t\u00eb ngjashme: n\u00eb makin\u00ebn brenda rrjetit ekzekutohet nj\u00eb modul ekzekutues i p\u00ebrgatitur m\u00eb par\u00eb, q\u00eb krijon nj\u00eb lidhje me serverin e jasht\u00ebm. N\u00eb server \u00e7elet nj\u00eb server SOCKS4\/5, q\u00eb pranon lidhjet dhe i transmeton ato te klienti.<\/p>\n<p>Disavantazhi i t\u00eb gjitha mjeteve t\u00eb lartp\u00ebrmendura \u00ebsht\u00eb se ose n\u00eb makin\u00ebn e klientit nevojitet t\u00eb jet\u00eb instaluar Python ose Golang (sa shpesh keni hasur se Python \u00ebsht\u00eb instaluar n\u00eb makinat, p\u00ebr shembull, t\u00eb drejtor\u00ebve t\u00eb kompanive ose punonj\u00ebsve t\u00eb zyr\u00ebs?), ose n\u00eb k\u00ebt\u00eb makin\u00eb duhet t\u00eb \u00e7ojm\u00eb nj\u00eb binary t\u00eb p\u00ebrgatitur m\u00eb par\u00eb (praktikisht python dhe skripti n\u00eb nj\u00eb paket\u00eb) dhe t\u00eb ekzekutojm\u00eb at\u00eb atje. Nd\u00ebrsa shkarkimi i nj\u00eb exe dhe nisim at\u00eb \u2014 \u00ebsht\u00eb nj\u00eb signeature tjet\u00ebr p\u00ebr antivirusin lokal ose HIPS.<\/p>\n<p>N\u00eb p\u00ebrgjith\u00ebsi, p\u00ebrfundimi duket i qart\u00eb \u2014 na nevojitet nj\u00eb zgjidhje n\u00eb PowerShell. Tani do na fluturojn\u00eb domate \u2014 se PowerShell \u00ebsht\u00eb e konsumuar tashm\u00eb, monitorohet, blokohen etj. e.tj. N\u00eb t\u00eb v\u00ebrtet\u00eb \u2014 aspak kudo. E kemi th\u00ebn\u00eb me p\u00ebrgjegj\u00ebsi. P\u00ebr m\u00eb tep\u00ebr, ekzistojn\u00eb shum\u00eb m\u00ebnyra p\u00ebr t\u00eb anashkaluar bllokimet (k\u00ebtu p\u00ebrs\u00ebri fraz\u00eb e njohur p\u00ebr shprehja \"p\u00ebrsh\u00ebndetje RKN \ud83d\ude42\"), q\u00eb fillon me thjesht riem\u00ebrimin e powershell.exe -&gt; cmdd.exe dhe p\u00ebrfundon me powerdll etj.<\/p>\n<h3>Fillojm\u00eb t\u00eb shpikim<\/h3>\n<p>\nE qart\u00eb \u00ebsht\u00eb q\u00eb s\u00eb pari do shikojm\u00eb n\u00eb Google dhe\u2026 nuk do gjejm\u00eb asgj\u00eb n\u00eb lidhje me k\u00ebt\u00eb tem\u00eb (n\u00ebse dikush ka gjetur \u2014 d\u00ebrgoni lidhjet n\u00eb komentet). Ka vet\u00ebm <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/p3nt4\/Invoke-SocksProxy\">implementimi<\/a><\/noindex> Socks5 n\u00eb PowerShell, por ky \u00ebsht\u00eb nj\u00eb \"direkt\" socks i zakonsh\u00ebm, q\u00eb ka nj\u00eb seri t\u00eb metash (p\u00ebr to do flasim m\u00eb von\u00eb). Sigurisht, mund ta shnd\u00ebrrojm\u00eb n\u00eb reverse me nj\u00eb l\u00ebvizje, por kjo do t\u00eb jet\u00eb vet\u00ebm nj\u00eb socks me nj\u00eb fij\u00eb, q\u00eb p\u00ebr ne nuk \u00ebsht\u00eb krejt\u00ebsisht ajo q\u00eb na nevojitet.<\/p>\n<p>Tani, nuk gjet\u00ebm asgj\u00eb t\u00eb gatshme, prandaj do t\u00eb na duhet t\u00eb shpikim bi\u00e7iklet\u00ebn ton\u00eb. Si baz\u00eb p\u00ebr bi\u00e7iklet\u00ebn ton\u00eb, do t\u00eb marrim <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/mis-team\/rsockstun\">zhvillimin ton\u00eb<\/a><\/noindex> t\u00eb reverse socks n\u00eb Golang, dhe do ta realizojm\u00eb klientin e tij n\u00eb PowerShell.<\/p>\n<p><b>RSocksTun<\/b><br \/>\nTani, si funksionon rsockstun?<\/p>\n<p>N\u00eb thelb t\u00eb funksionimit t\u00eb RsocksTun (m\u00eb tej \u2014 rs) q\u00ebndrojn\u00eb dy komponent\u00eb programor\u00eb \u2014 Yamux dhe serveri Socks5. Serveri Socks5 \u00ebsht\u00eb nj\u00eb socks5 lokal normal, q\u00eb niset n\u00eb klient. Dhe shum\u00ebfijor\u00ebsimi i lidhjeve n\u00eb t\u00eb (mos e harroni shum\u00ebfijorin?) sigurohet nga yamux (<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/hashicorp\/yamux\/\">yet another multiplexer<\/a><\/noindex>). Ky skem\u00eb lejon q\u00eb t\u00eb nisin disa server\u00eb socks5 klient\u00ebsh dhe t\u00eb shp\u00ebrndajn\u00eb lidhjet e jashtme te ata, duke i kaluar ato p\u00ebrmes nj\u00eb lidhjeje t\u00eb vetme TCP (gati si n\u00eb meterpreter) nga klienti n\u00eb server, duke realizuar k\u00ebshtu nj\u00eb mod shum\u00ebfijor, pa t\u00eb cilin nuk do t\u00eb mund t\u00eb punojm\u00eb plot\u00ebsisht n\u00eb rrjetin e brendsh\u00ebm.<\/p>\n<p>The essence of yamux's operation lies in the fact that it introduces an additional network layer of streams, implementing it as a 12-byte header for each packet. (Here we intentionally use the word \"stream\" instead of \"\u043f\u043e\u0442\u043e\u043a\" to avoid confusing the reader with the programming thread concept \u2014 which we will also use in this article). Inside the yamux header are the stream number, flags for setting up\/terminating the stream, the number of bytes being transferred, and the window size.<\/p>\n<p><img decoding=\"async\" alt=\"Shkruajm\u00eb Reverse socks5 proxy n\u00eb PowerShell. Pjesa 1\" src=\"\/wp-content\/uploads\/2019\/05\/3a1bc23bdc90176f7cd37f112a8a1a6c.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nIn addition to setting up\/terminating streams, yamux implements a keepalive mechanism that allows monitoring the operability of the established communication channel. The operation of the keepalive message mechanism is configured when creating a Yamux session. Essentially, there are only two parameters in the settings: enable\/disable and the frequency of packet sending in seconds. The keepalive messages can be sent by the yamux server as well as the yamux client. Upon receiving a keepalive message, the remote side must respond with a packet containing the exact same message identifier (in fact \u2014 a number) that it received. In general, keepalive is just like a ping, but specifically for yamux.<\/p>\n<p>The detailed workings of the multiplexer: packet types, flags for establishing and terminating connections, and the data transmission mechanism are described in <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/hashicorp\/yamux\/blob\/master\/spec.md\">specifikacioni<\/a><\/noindex> the yamux. <\/p>\n<h3>Conclusion to the first part<\/h3>\n<p>\nSo, in the first part of the article, we got acquainted with some tools for organizing reverse tunnels, examined their advantages and disadvantages, studied the operation mechanism of the Yamux multiplexer, and outlined the main requirements for the newly created PowerShell module. In the next part, we will tackle the module's development from scratch. Stay tuned \ud83d\ude42<br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/453870\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0442\u043e\u0440\u0438\u044f \u043e\u0431 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u0438 \u0438 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0432 3-\u0445 \u0447\u0430\u0441\u0442\u044f\u0445. \u0427\u0430\u0441\u0442\u044c 1 \u2014 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c\u0441\u043a\u0430\u044f. \u0411\u0443\u043a\u043e\u0432 \u043c\u043d\u043e\u0433\u043e \u2014 \u043f\u043e\u043b\u044c\u0437\u044b \u0435\u0449\u0435 \u0431\u043e\u043b\u044c\u0448\u0435. \u041f\u043e\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 \u0437\u0430\u0434\u0430\u0447\u0438 \u0412 \u0445\u043e\u0434\u0435 \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043f\u0435\u043d\u0442\u0435\u0441\u0442\u043e\u0432 \u0438 RedTeam \u043a\u0430\u043c\u043f\u0430\u043d\u0438\u0439 \u043d\u0435 \u0432\u0441\u0435\u0433\u0434\u0430 \u0443\u0434\u0430\u0435\u0442\u0441\u044f \u0432\u043e\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0448\u0442\u0430\u0442\u043d\u044b\u043c\u0438 \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430\u043c\u0438 \u0417\u0430\u043a\u0430\u0437\u0447\u0438\u043a\u043e\u0432, \u0442\u0430\u043a\u0438\u043c\u0438 \u043a\u0430\u043a VPN, RDP, Citrix \u0438 \u0442.\u0434. \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0437\u0430\u043a\u0440\u0435\u043f\u043b\u0435\u043d\u0438\u044f \u0434\u043b\u044f \u0437\u0430\u0445\u043e\u0434\u0430 \u0432\u043e \u0432\u043d\u0443\u0442\u0440\u0435\u043d\u043d\u044e\u044e \u0441\u0435\u0442\u044c. \u0413\u0434\u0435-\u0442\u043e \u0448\u0442\u0430\u0442\u043d\u044b\u0439 VPN \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u043f\u043e MFA [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":26164,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-34725","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0442\u043e\u0440\u0438\u044f \u043e\u0431 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u0438 \u0438 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0432 3-\u0445 \u0447\u0430\u0441\u0442\u044f\u0445. \u0427\u0430\u0441\u0442\u044c 1 \u2014 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c\u0441\u043a\u0430\u044f. \u0411\u0443\u043a\u043e\u0432 \u043c\u043d\u043e\u0433\u043e \u2014 \u043f\u043e\u043b\u044c\u0437\u044b \u0435\u0449\u0435 \u0431\u043e\u043b\u044c\u0448\u0435. \u041f\u043e\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 \u0437\u0430\u0434\u0430\u0447\u0438 \u0412 \u0445\u043e\u0434\u0435 \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043f\u0435\u043d\u0442\u0435\u0441\u0442\u043e\u0432 \u0438 RedTeam \u043a\u0430\u043c\u043f\u0430\u043d\u0438\u0439 \u043d\u0435 \u0432\u0441\u0435\u0433\u0434\u0430 \u0443\u0434\u0430\u0435\u0442\u0441\u044f \u0432\u043e\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0448\u0442\u0430\u0442\u043d\u044b\u043c\u0438 \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430\u043c\u0438 \u0417\u0430\u043a\u0430\u0437\u0447\u0438\u043a\u043e\u0432, \u0442\u0430\u043a\u0438\u043c\u0438 \u043a\u0430\u043a VPN, RDP, Citrix \u0438 \u0442.\u0434. \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0437\u0430\u043a\u0440\u0435\u043f\u043b\u0435\u043d\u0438\u044f \u0434\u043b\u044f \u0437\u0430\u0445\u043e\u0434\u0430 \u0432\u043e \u0432\u043d\u0443\u0442\u0440\u0435\u043d\u043d\u044e\u044e \u0441\u0435\u0442\u044c. \u0413\u0434\u0435-\u0442\u043e \u0448\u0442\u0430\u0442\u043d\u044b\u0439 VPN \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u043f\u043e MFA\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/pishem-reverse-socks5-proxy-na-powershell-chast-1\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041f\u0438\u0448\u0435\u043c Reverse socks5 proxy \u043d\u0430 powershell.\u0427\u0430\u0441\u0442\u044c 1 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0442\u043e\u0440\u0438\u044f \u043e\u0431 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u0438 \u0438 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0432 3-\u0445 \u0447\u0430\u0441\u0442\u044f\u0445. \u0427\u0430\u0441\u0442\u044c 1 \u2014 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c\u0441\u043a\u0430\u044f. \u0411\u0443\u043a\u043e\u0432 \u043c\u043d\u043e\u0433\u043e \u2014 \u043f\u043e\u043b\u044c\u0437\u044b \u0435\u0449\u0435 \u0431\u043e\u043b\u044c\u0448\u0435. \u041f\u043e\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 \u0437\u0430\u0434\u0430\u0447\u0438 \u0412 \u0445\u043e\u0434\u0435 \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043f\u0435\u043d\u0442\u0435\u0441\u0442\u043e\u0432 \u0438 RedTeam \u043a\u0430\u043c\u043f\u0430\u043d\u0438\u0439 \u043d\u0435 \u0432\u0441\u0435\u0433\u0434\u0430 \u0443\u0434\u0430\u0435\u0442\u0441\u044f \u0432\u043e\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0448\u0442\u0430\u0442\u043d\u044b\u043c\u0438 \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430\u043c\u0438 \u0417\u0430\u043a\u0430\u0437\u0447\u0438\u043a\u043e\u0432, \u0442\u0430\u043a\u0438\u043c\u0438 \u043a\u0430\u043a VPN, RDP, Citrix \u0438 \u0442.\u0434. \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0437\u0430\u043a\u0440\u0435\u043f\u043b\u0435\u043d\u0438\u044f \u0434\u043b\u044f \u0437\u0430\u0445\u043e\u0434\u0430 \u0432\u043e \u0432\u043d\u0443\u0442\u0440\u0435\u043d\u043d\u044e\u044e \u0441\u0435\u0442\u044c. \u0413\u0434\u0435-\u0442\u043e \u0448\u0442\u0430\u0442\u043d\u044b\u0439 VPN \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u043f\u043e MFA\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/pishem-reverse-socks5-proxy-na-powershell-chast-1\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:00:00+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Writing a Reverse socks5 proxy in PowerShell. Part 1 | ProHoster","description":"A story about research and development in 3 parts. Part 1 \u2014 research. There are many letters \u2014 even more benefits. Problem Statement: During penetration tests and Red Team campaigns, it is not always possible to use the client's standard tools, such as VPN, RDP, Citrix, etc., to consolidate access to the internal network. Sometimes the standard VPN operates under MFA.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/pishem-reverse-socks5-proxy-na-powershell-chast-1","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041f\u0438\u0448\u0435\u043c Reverse socks5 proxy \u043d\u0430 powershell.\u0427\u0430\u0441\u0442\u044c 1 | ProHoster","og:description":"\u0418\u0441\u0442\u043e\u0440\u0438\u044f \u043e\u0431 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u0438 \u0438 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0432 3-\u0445 \u0447\u0430\u0441\u0442\u044f\u0445. \u0427\u0430\u0441\u0442\u044c 1 \u2014 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c\u0441\u043a\u0430\u044f. \u0411\u0443\u043a\u043e\u0432 \u043c\u043d\u043e\u0433\u043e \u2014 \u043f\u043e\u043b\u044c\u0437\u044b \u0435\u0449\u0435 \u0431\u043e\u043b\u044c\u0448\u0435. \u041f\u043e\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0430 \u0437\u0430\u0434\u0430\u0447\u0438 \u0412 \u0445\u043e\u0434\u0435 \u043f\u0440\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043f\u0435\u043d\u0442\u0435\u0441\u0442\u043e\u0432 \u0438 RedTeam \u043a\u0430\u043c\u043f\u0430\u043d\u0438\u0439 \u043d\u0435 \u0432\u0441\u0435\u0433\u0434\u0430 \u0443\u0434\u0430\u0435\u0442\u0441\u044f \u0432\u043e\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0448\u0442\u0430\u0442\u043d\u044b\u043c\u0438 \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430\u043c\u0438 \u0417\u0430\u043a\u0430\u0437\u0447\u0438\u043a\u043e\u0432, \u0442\u0430\u043a\u0438\u043c\u0438 \u043a\u0430\u043a VPN, RDP, Citrix \u0438 \u0442.\u0434. \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0437\u0430\u043a\u0440\u0435\u043f\u043b\u0435\u043d\u0438\u044f \u0434\u043b\u044f \u0437\u0430\u0445\u043e\u0434\u0430 \u0432\u043e \u0432\u043d\u0443\u0442\u0440\u0435\u043d\u043d\u044e\u044e \u0441\u0435\u0442\u044c. \u0413\u0434\u0435-\u0442\u043e \u0448\u0442\u0430\u0442\u043d\u044b\u0439 VPN \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u043f\u043e MFA","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/pishem-reverse-socks5-proxy-na-powershell-chast-1","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:00:00+00:00","article:modified_time":"2019-10-31T19:00:00+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"34725","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 20:23:33","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 02:16:32","updated":"2026-01-21 20:23:33","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/34725","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=34725"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/34725\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/26164"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=34725"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=34725"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=34725"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}