4 ms·
Hunting for Suspicious DNS Communications
- LinuxBender 5y agoGood article. On the topic of their final recommendations I would also add IP rate limiting. A former coworker and I would red/blue team this scenario and the only way I could break his exfil script was to rate limit on the recursive DNS server by IP. Unbound and Bind have the ability to do this. I suspect others may as well. It doesn't stop the data exfiltration but will slow it to a crawl. Unbound can also rate limit by domain destination. Disclaimer: IP Rate limiting will cause problems for poorly coded applications and there are many. Example only, don't use this. Read the manual first. [1] Some directives require being on a recent version. ratelimit: 800 ratelimit-size: 4m ratelimit-factor: 10 ratelimit-below-domain: com 50 ratelimit-below-domain: net 50 ratelimit-below-domain: info 2 ratelimit-below-domain: xyz 4 ip-ratelimit: 200 ip-ratelimit-size: 255k ip-ratelimit-factor: 10 [1] - https://unbound.docs.nlnetlabs.nl/en/latest/manpages/unbound.conf.html https://unbound.docs.nlnetlabs.nl/en/latest/manpages/unbound...