Elektrine lite

← Feed

@ck0@tech.lgbt

Post #1060963

2026-03-27 17:01 UTC

@k3ym0 "Bonus: this is a fully functional globally-distributed covert data exfil channel that your NGFW will never fucking see if you're not doing deep DNS inspection. Sleep well." Doesn't work anymore for a decade. Most serious companies don't allow DNS queries to servers outside of their network. The only endpoints allowed to do that are the corporate internal DNS. With DoH I'm also not sure that will work because of the corporate web proxy. To make data exfiltrations there are so many easy ways to do so ... Why spending time to make something over DNS when you can simply upload the files or exploit USB keys, it's not hard to bypass FW and EDR policies.

Replies (1)

  • @k3ym0@infosec.exchange 2026-03-27 22:58

    @ck0 Most serious companies don't allow DNS queries to servers outside of their network. Oh my sweet, sweet, child. If only this were true. I could name-drop several multi-billion $ enterprise orgs that still don’t do this.

    Open ##1217096