---
title: "reDuh: HTTP Tunneling - Ventas de Seguridad"
description: "The latest news for Latin American integrators, contractors and wholesalers in electronic security."
url: "https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security/14490-reduh-http-tunneling-en-gb.html"
date: "2026-07-23T18:20:09+00:00"
language: "en-GB"
---

#  [ reDuh: HTTP Tunneling](https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security/14490-reduh-http-tunneling-en-gb.html "reDuh: HTTP Tunneling")

      Details     10 February 2011           In the previous post, we were left with the fact that we had managed to create a user with root privileges (uid=0) on the machine, but we did not have network-level access to the SSH port, so we could not finish establishing an interactive session.To do this, and since we only have access to the target machine through the service we have just exploited, we will try to use this same service to create a TCP traffic tunnel on this protocol, in this case TCP over HTTP. The he...

 In the previous post, we were left with the fact that we had managed to create a user with root privileges (uid=0) on the machine, but we did not have network-level access to the SSH port, so we could not finish establishing an interactive session.To do this, and since we only have access to the target machine through the service we have just exploited, we will try to use this same service to create a TCP traffic tunnel on this protocol, in this case TCP over HTTP. The tool to use will see reDuh, from Sensepost, which has two pieces: a server in php, aspx and jsp versions that can be uploaded to the compromised server, and a java client that will be launched from our computer to establish the tunnel.

Once the corresponding reDuh server has been uploaded (in this case it was php), we can check if it has been uploaded correctly simply by accessing its URL. This piece is not prepared to be called this way, so it gives us an error message, but at least confirms that the URL is correct.

Full content on Pentester

- Publicidad -

**[See original.](http://feedproxy.google.com/~r/NoticiasSeguridadInformatica/~3/TpC-2Hr2my8/reduh-http-tunneling.html "reDuh: HTTP Tunneling")**

      ###  No comments

• If you're already registered, please log in first. Your email will not be published.

###  Comments are closed

 The comments for this content are closed.

## Schema

```json
{ "@context": "https://schema.org", "@type": "BreadcrumbList", "itemListElement": [ { "@type": "ListItem", "position": 1, "name": "Inicio", "item": "https://www.ventasdeseguridad.com/en" }, { "@type": "ListItem", "position": 2, "name": "Latest News", "item": "https://www.ventasdeseguridad.com/en/news/latest-news.html" }, { "@type": "ListItem", "position": 3, "name": "Cyber Security", "item": "https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security.html" }, { "@type": "ListItem", "position": 4, "name": "reDuh: HTTP Tunneling", "item": "https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security/14490-reduh-http-tunneling-en-gb.html" } ] }
```

```json
{ "@context": "https://schema.org", "@type": "VideoObject", "name": "reDuh: HTTP Tunneling", "description": "In the previous post, we were left with the fact that we had managed to create a user with root privileges (uid=0) on the machine, but we did not have network-level access to the SSH port, so we could not finish establishing an interactive session.To do this, and since we only have access to the target machine through the service we have just exploited, we will try to use this same service to create a TCP traffic tunnel on this protocol, in this case TCP over HTTP. The he...", "thumbnailUrl": "https://www.ventasdeseguridad.com/", "uploadDate": "2011-02-10T02:00:07-05:00", "contentUrl": "https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security/14490-reduh-http-tunneling-en-gb.html" }
```

```json
{ "@context": "https://schema.org", "@type": "NewsArticle", "mainEntityOfPage": { "@type": "WebPage", "@id": "https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security/14490-reduh-http-tunneling-en-gb.html" }, "headline": "reDuh: HTTP Tunneling - Ventas de Seguridad", "description": "The latest news for Latin American integrators, contractors and wholesalers in electronic security.", "image": { "@type": "ImageObject", "url": "https://www.ventasdeseguridad.com/" }, "publisher": { "@type": "Organization", "name": "Ventas de Seguridad", "logo": { "@type": "ImageObject", "url": "https://www.ventasdeseguridad.com/images/metatags/16x9/vds.png" } }, "author": { "@type": "Person", "name": "Max Jaramillo", "url": "https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security/14490-reduh-http-tunneling-en-gb.html" }, "datePublished": "2011-02-10T02:00:07-05:00", "dateCreated": "2011-02-09T11:30:00-05:00", "dateModified": "2022-04-25T18:22:56-05:00" }
```

```json
{ "@context": "https://schema.org", "@type": "Article", "mainEntityOfPage": { "@type": "WebPage", "@id": "https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security/14490-reduh-http-tunneling-en-gb.html" }, "headline": "Latest News", "description": "The latest news for Latin American integrators, contractors and wholesalers in electronic security.", "image": { "@type": "ImageObject", "url": "https://www.ventasdeseguridad.com/images/metatags/16x9/vds.png" }, "publisher": { "@type": "Organization", "name": "Latin Press, Inc.", "logo": { "@type": "ImageObject", "url": "https://www.ventasdeseguridad.com/images/metatags/16x9/lpi-eventos-online.png" } }, "author": { "@type": "Person", "name": "Ventas de Seguridad", "url": "https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security/14490-reduh-http-tunneling-en-gb.html" } }
```
