3 ms·
There's also the Iodine project if you want to tunnel raw IPv4 over DNS [53] [53] https://github.com/yarrick/iodine https://github.com/yarrick/iodine
by BuildTheRobots 1y ago
There's also the Iodine project if you want to tunnel raw IPv4 over DNS [53]
[53] https://github.com/yarrick/iodine https://github.com/yarrick/iodine
- mmh0000 1y agoI love iodine. I used to do a lot of consulting work at locations with extremely locked down networks. I could use iodine + wireguard to punch through most firewalls, slow, but effective.
- lormayna 1y agoThis means that the security department is not doing a good job: things like iodine can be detected easily by a NGFW or by an analysis on DNS logs. This is a quite basic security posture.
- EvanAnderson 1y agoBack when I was using it similarly to the other poster (say, 15 years ago) that wasn't the case. It's still a great litmus test of security posture today. Just using DNS for data exfiltration, in general, is usually pretty fruitful. I wrote a "live off the land" data exfil script for Windows once, using the certutil and nslookup commands to base64 encode data and ship it out to my off-site DNS server. I'll have to try it against a Palo Alto NGFW sometime and see what alarms I trip. I honestly never thought to try.
- lormayna 1y agoThat's make sense 15 years ago. Right now even the SOHO appliances have the DNS inspection feature.
- bongodongobob 1y agoLol no it isn't. Most companies don't even have MFA across the board, much less do anything with DNS security beyond maybe a blacklist.
- lormayna 1y agoMFA is quite more complex to implement, especially if legacy applications are involved. Applying a basic DNS security monitoring is not hard, you can even implement with few policies on the border FW and something like an ELK stack. The most difficult part is implementing an appropriate process
- roygbiv2 1y agoThe only real place I got iodine to work was 40k feet above the ocean. Even then it was only good enough to telnet into an SMTP server to send an email. Most of the time it's failed for me.