4 ms·
Huh? The traffic has to travel over wire as TCP/IP, regardless of what device generated it. Any outbound firewall would detect that, especially traffic going to
by simplecomplex 8y ago
Huh? The traffic has to travel over wire as TCP/IP, regardless of what device generated it. Any outbound firewall would detect that, especially traffic going to ports that aren’t even open/used.
- tomc1985 8y agoIf I were an attacker in that situation I'd probably find a way to get my data to hitch a ride with other outgoing data
- deleted 8y ago[deleted]
- wyldfire 8y agoMany/most AWS customers use ssh sessions to interact with their allocated nodes. And when it's not ssh traffic, it's often https. What good does it do to detect the bad traffic if you can't distinguish it from legitimate customer traffic? > has to travel over wire as TCP/IP, BTW, this is not the case. If exfil via conventional system networking is too hard to avoid detection, they'll find another channel. RF via LOS, ultrasonic, or some of a million other ideas.