When performing SSH dynamic port forwarding with the -D flag, what is the primary benefit compared to local port forwarding (-L)?
Dynamic port forwarding acts as a SOCKS proxy, allowing client applications to route traffic through the SSH server to any destination reachable by that server. This eliminates the need to create individual -L tunnels for every specific internal IP or service, providing much greater flexibility during network enumeration.
Why this answer
Dynamic port forwarding creates a SOCKS proxy, which allows the user to route traffic to any destination reachable by the remote jump host. Unlike local port forwarding, which requires specifying a target IP and port upfront, dynamic forwarding is flexible. This is essential during the discovery phase of a penetration test, as it allows tools like Nmap or browser-based tools to explore an entire internal network segment without individual tunnel configurations.
Exam trap
Candidates often confuse dynamic port forwarding with local port forwarding, assuming they need to create a new tunnel every time they want to access a different internal service.