4 ms·
This may work for "casual" attempts, but if someone really want to exfiltrate data, they can still do so in any number of ways. For example, they can send DNS q
by anyfoo 2y ago
This may work for "casual" attempts, but if someone really want to exfiltrate data, they can still do so in any number of ways. For example, they can send DNS queries. To your usual DNS server, so you won't see a new address. Which will happily pass it along to whatever the registered nameserver for the queried domain is.
- ChuckMcM 2y agoAbsolutely correct, any APT won’t be caught this way. But script kiddies will be every day of the week. And if you’re browser is suddenly sending queries to China after that last add-on, it can be a good bread crumb to follow up. Security, like dressing for variable weather, is best done in layers.