3 ms·
If you know a bug in the DNS resolving stack of the client, you can make it send a query to your DNS server and exploit it to establish a connection. So no, it
by mshook 9y ago
If you know a bug in the DNS resolving stack of the client, you can make it send a query to your DNS server and exploit it to establish a connection. So no, it doesn't have to know it's about to connect.
A query is easily triggered by sending an email with a an external picture embedded or something like that.
Nothing NAT/PAT can protect you against.
- slau 9y agoBut why would the client use _your_ DNS server? It will just use its local resolver, which will most likely use the router, or ISPs DNS server, and so forth.
- dec0dedab0de 9y agothats also something a firewall cant protect you against.
- rocqua 9y agoThe difference is that NAT doesn't track the counter party, so after you reached out to the DNS, any other service can use the opened port to connect to your PC. With a stateful firewall, it tracks that the port was opened only used for the DNS server. If a connection to that port from a different IP address than the DNS server is made, the firewall will block it.