
Multi-hop proxy tool for pentesters enabling traffic routing through multiple nodes, SOCKS5/SSH tunneling, port forwarding, remote shell, and encrypted node communication.

Stowaway is a multi-hop proxy tool for security researchers and penetration testers.
Stowaway lets you proxy external traffic through multiple hops into a target internal network, bypassing access restrictions, building a tree-like node topology, and managing it easily.
Thanks for the stars. Issues and bug reports are welcome. 😘
Please be sure to read the usage guide and the notes at the end before using.
This project is intended for cybersecurity research and educational purposes only. Any unauthorized or malicious use is strictly prohibited. Before conducting any testing, please ensure you have explicit authorization from the target system and fully comply with all applicable laws and regulations in your country or region. The user assumes full responsibility for any direct or indirect consequences resulting from the use of this tool, including but not limited to data loss, system damage, or legal issues. The author of this project does not accept any liability for misuse or illegal use of this tool. By using this tool, you acknowledge that you have read, understood, and agreed to the full contents of this disclaimer.
make to directly compile programs for multiple platforms, or refer to the Makefile for compiling specific programs.Stowaway has two roles:
admin The controller used by the operatoragent The node deployed on a target hostadmin or agentThe following commands quickly start the simplest Stowaway setup:
./stowaway_admin -l 9999./stowaway_agent -c <stowaway_admin's IP>:9999Parameter:
-l Listening address in passive mode [ip]:<port>
-s Shared secret for node communication; must be the same on all nodes (admin and agent)
-c Target node address under active mode
--socks5-proxy SOCKS5 proxy server address
--socks5-proxyu SOCKS5 proxy server username
--socks5-proxyp SOCKS5 proxy server password
--http-proxy HTTP proxy server address
--down Downstream protocol type, default is raw TCP traffic, optional HTTP/WS
--tls-enable Enable TLS for node communication, after enabling TLS, AES encryption will be disabled
--domain Specify the TLS SNI/WebSocket domain name. If it is empty, it defaults to the target node address
--heartbeat Enable heartbeat packets
Parameter:
-l Listening address in passive mode [ip]:<port>
-s Node communication encryption key
-c Target node address under active mode
--socks5-proxy SOCKS5 proxy server address
--socks5-proxyu SOCKS5 proxy server username (optional)
--socks5-proxyp SOCKS5 proxy server password (optional)
--http-proxy HTTP proxy server address
--reconnect Reconnect time interval
--rehost The IP address to be reused
--report The port number to be reused
--up Upstream protocol type, default is raw TCP traffic, optional HTTP/WS
--down Downstream protocol type, default is raw TCP traffic, optional HTTP/WS
--cs Console encoding (default: utf-8; optional: gbk)
--tls-enable Enable TLS for node communication, after enabling TLS, AES encryption will be disabled
--domain Specify the TLS SNI/WebSocket domain name. If it is empty, it defaults to the target node address.
This parameter can be used on admin&&agent, under passive mode
If you do not specify an IP address, it will default to listening on 0.0.0.0
admin: ./stowaway_admin -l 9999 or ./stowaway_admin -l 127.0.0.1:9999
agent: ./stowaway_agent -l 9999 or ./stowaway_agent -l 127.0.0.1:9999
This parameter can be used on admin&&agent, under both active && passive mode
This parameter is optional. If it is left blank, it means that the communication will not be encrypted. Conversely, if a key is provided by the user, the communication will be encrypted based on that key.
admin: ./stowaway_admin -l 9999 -s 123
agent: ./stowaway_agent -l 9999 -s 123
This parameter can be used on admin&&agent, under active mode
It represents the address of the node you wish to connect to
admin: ./stowaway_admin -c 127.0.0.1:9999
agent: ./stowaway_agent -c 127.0.0.1:9999
These four parameters can be used on admin&&agent , under active mode
--socks5-proxy represents the address of the socks5 proxy server, --socks5-proxyu and --socks5-proxyp are optional
--http-proxy represents the address of the http-proxy server, the usage is the same as socks5
Without username and password:
admin: ./stowaway_admin -c 127.0.0.1:9999 --socks5-proxy xxx.xxx.xxx.xxx
agent: ./stowaway_agent -c 127.0.0.1:9999 --socks5-proxy xxx.xxx.xxx.xxx
Require username and password:
admin: ./stowaway_admin -c 127.0.0.1:9999 --socks5-proxy xxx.xxx.xxx.xxx --socks5-proxyu xxx --socks5-proxyp xxx
agent: ./stowaway_agent -c 127.0.0.1:9999 --socks5-proxy xxx.xxx.xxx.xxx --socks5-proxyu xxx --socks5-proxyp xxx
These two parameters can be used on admin&&agent, under active && passive mode
However, note that there is no --up parameter on the admin
These two parameters are optional. If left empty, upstream/downstream traffic will use raw TCP.
If you wish for the upstream/downstream traffic to be HTTP/WS traffic, simply set these two parameters to http or ws
admin: ./stowaway_admin -c 127.0.0.1:9999 --down ws
agent: ./stowaway_agent -c 127.0.0.1:9999 --up ws or ./stowaway_agent -c 127.0.0.1:9999 --up ws --down ws
Two more notes:
First, once you set the upstream/downstream traffic of a node to TCP/HTTP/WS, the downstream/upstream traffic of its parent/child nodes must match.
Like this:
admin: ./stowaway_admin -c 127.0.0.1:9999 --down ws
agent: ./stowaway_agent -l 9999 --up ws
In this case, the agent must set --up to ws, otherwise it will cause network errors.
The rules between admin<-->agent are the same as agent<-->agent.