4 ms·
This is an actual working example, not theory on how to do it. IMO, that's what makes it significant. Lot's of people talk about how this can be done, few show
by 16s 13y ago
This is an actual working example, not theory on how to do it. IMO, that's what makes it significant. Lot's of people talk about how this can be done, few show actual working examples (with source code) that others can re-create on their networks.
- codexon 13y agohttp://code.kryo.se/iodine/ http://code.kryo.se/iodine/
- cypherpunks01 13y agoSorry to rain on your parade, but Dan Kaminsky additionally wrote an implementation called ozymandns in 2005 or so: http://dnstunnel.de/ http://dnstunnel.de/ I use it when I need an ssh or web connection in extremely hostile environments that only allow free DNS queries out, like some planes, buses, establishments, etc. There are also links to other implementations here: http://en.cship.org/wiki/OzymanDNS http://en.cship.org/wiki/OzymanDNS
- 16s 13y agoThose examples tunnel traffic over DNS. They do not specifically break large files up into small chunks and exfiltrate them off of a secure network with simple DNS queries.
- cypherpunks01 13y agoSure, yes. All those examples (ozyman, iodine, etc.) tunnel arbitrary traffic over DNS, whereas yours is more traffic-efficient in essentially being a static file server via DNS, I suppose?
- amckenna 13y agoTunneling traffic over DNS is breaking up files (data) into chunks (packets) and exfiltrating off of a network through DNS. Don't get me wrong, it's nice to see a simple example like yours, but projects like http://code.kryo.se/iodine/ http://code.kryo.se/iodine/ do essentially (from an abstract perspective) the same thing.
- deleted 13y ago[deleted]
- darklajid 13y agoBut scp localfile user@tunnelhost:/some/place does that. The sample is cool, I really like digging into that stuff. But it's not really different from ozyman/iodine.
- micah94 13y agoWould this work after caching? I suppose you could hash the data so the "hostnames" are different each time, forcing an auth lookup.
- rwg 13y agoIt encodes a 4-byte sequence number in the base64 glop before the 8-byte chunk of data, so all of the DNS labels generated for a file should be unique.