Post #801197
2026-03-26 20:02 UTC
Replies (38)
-
@kajer@infosec.exchange 2026-03-26 20:04
@k3ym0 new cloud storage just dropped
-
@badsamurai@infosec.exchange 2026-03-26 20:33
@k3ym0 #dns
-
@circuitsunfish@plesiosaur.net 2026-03-27 04:29
@k3ym0 shit like this makes me glad I no longer work in #cybersec
-
@dago@river.group.lt 2026-03-27 08:08
@k3ym0 shit. Time to do Bad Apple on DNS.
-
@aris@infosec.exchange 2026-03-27 09:07
@k3ym0 The concept is very old, I was using dns2tcp to have free wifi on plane trips in 2010 and even before during pentests. Long TXT replies trigger red alerts on most intrusion detection systems nowadays.
-
Whoa.
-
@tml@mementomori.social 2026-03-27 10:46
@k3ym0 For quite a loose definition of "run".
-
@wolf480pl@mstdn.io 2026-03-27 10:46
@k3ym0 > covert data exfil channel as if iodine wasn't already a thing
-
@Albirew@soshar.dess.ga 2026-03-27 16:12
@k3ym0@infosec.exchange DNS haiku just got a lot bloodier...
-
@ck0@tech.lgbt 2026-03-27 17:01
@k3ym0 "Bonus: this is a fully functional globally-distributed covert data exfil channel that your NGFW will never fucking see if you're not doing deep DNS inspection. Sleep well." Doesn't work anymore for a decade. Most serious companies don't allow DNS queries to servers outside of their network. The only endpoints allowed to do that are the corporate internal DNS. With DoH I'm also not sure that will work because of the corporate web proxy. To make data exfiltrations there are so many easy ways to do so ... Why spending time to make something over DNS when you can simply upload the files or exploit USB keys, it's not hard to bypass FW and EDR policies.
-
@jawnsy@mastodon.social 2026-03-27 17:03
@k3ym0 This post is wild but the stuff people are sharing in the comments is great hahaha
-
@poetaster@mastodon.gamedev.place 2026-03-27 17:18
@k3ym0 Jeez. We were abusing DNS as http proxy caches in 1993. Some people were doing chat over DNS. Some of them WERE the engineers who were involved in standardization.
-
@Methylzero@mast.hpc.social 2026-03-27 17:47
@k3ym0 I have always wondered where the "power source" they are tapping Hell for in DOOM came from. Turns out it was the DNS engineers engineers spinning in their graves all along.
-
@retrofan64@oldbytes.space 2026-03-27 18:32
@k3ym0 this is similar to how DeCSS (DVD decryption code) was distributed over 25 years ago when there was an attempt to suppress it online.
-
@gloriouscow@oldbytes.space 2026-03-27 19:14
@k3ym0 Not DOOM, but this has been one of Infoblox's favorite sales demos for ages. "Check out all this information we can exfiltrate from your network directly from a web browser via only DNS queries" always gets people's attention
-
@memdmp@catgirl.center 2026-03-27 19:26
@k3ym0@infosec.exchange oh we may be able to make it worse...doom via standards-compliant dns direct content serving (assuming https://datatracker.ietf.org/doc/draft-dns-content-delivery/ goes through)
-
@spara@mastodon.social 2026-03-27 19:28
@k3ym0 I was at Defcon 12 when Kaminsky demoed sending voice over DNS. Glad to see the tradition continue.
-
@littlealex@infosec.exchange 2026-03-27 20:19
@k3ym0 interesting vector to deploy malware :ablobcool:
-
@woe2you@beige.party 2026-03-27 20:36
@k3ym0 Think of all the times you've wanted to take a shotgun to DNS. Now you can. Or a chainsaw.
-
@pseudonym@mastodon.online 2026-03-27 21:19
@k3ym0 DNS: "Tell them it was me." https://imgflip.com/i/ans5i3
-
@colinstu@birdbutt.com 2026-03-27 21:27
@k3ym0 DOOM over DNS, never thought I'd see the day.
-
@tiotasram@kolektiva.social 2026-03-27 22:28
@k3ym0 image ID: a screenshot of the setup in action, showing DOOM being played in one window while a terminal widow shows ASCII art reading "DOOM OVER DNS" plus other output.
-
@itgrrl@infosec.exchange 2026-03-28 00:59
@k3ym0 paging @vampiress, @voltagex, etc. ๐
-
@Flo_Rian@norden.social 2026-03-28 09:22
@k3ym0 โThose engineers are spinning in their gravesโ 1987 was less than 40 years ago and as far I can tell the author is still alive and active.
-
@Firehawke_R@mastodon.social 2026-03-28 10:31
@k3ym0 While DOOM is a pretty effective demo, I can't help but feel NES ROMs, which run anywhere from 24KB to 512KB would have been even more effective (and would seriously piss Nintendo off in the process, for a double win)
-
@zymurgic@mastodon.online 2026-03-28 13:20
@k3ym0 I did long ago work out that DNS is jolly good at distributing fairly static hierarchical datasets, because it inherently caches. For instance, they were once used to route faxes to appropriate gateways on the old tpc.int email to fax service. I also worked out a postcode to address and postcode geocoding schema.
-
@artemis@climatejustice.social 2026-03-29 08:03
@k3ym0 holy shit that is next level 'because I could'. Mad props.
-
@messieass@procial.tchncs.de 2026-03-29 09:11
@k3ym0@infosec.exchange Ho. Lee. Shit Was it already encoded in morse code? This clearly HAD to be done, but not by anyone i know.
-
I love it. Everything is a code of a code of a code of something else.
-
@abhayakara@mastodon.nl 2026-04-05 12:15
@k3ym0 Far's I know, Paul Mockapetris is still with us... Maybe @MrDNS would know for sure.
-
@comsey@mstdn.social 2026-04-05 13:28
@k3ym0 THE DLLS ARE IN DNS
-
@erikcats@dice.camp 2026-04-05 13:31
@k3ym0 I've just played with DNS settings for the first time in half a century's worth of life, so I'm both hella impressed and underwhelmed ๐๐๐
-
@adamrice@c.im 2026-04-05 16:46
@k3ym0 I just need to point out that I had nothing to do with this.
-
@Lydie@tech.lgbt 2026-04-07 20:08
@k3ym0 legendary. You can *always run DOOM. or 200 ๐ https://peertube.wtf/w/jr3Z6cgV92uedoiurkpyzM
-
@kimapr@ublog.kimapr.net 2026-03-27 21:50
@EeveeEuphoria @k3ym0 when i donโt know C# i go to msdn.microsoft.com and figure things out instead of doing anything i can to avoid learning. Kids these days ๐
-
@karlauerbach@sfba.social 2026-03-27 16:35
@k3ym0 I used to have the entire text of the Magna Carta in TXT records in a subdomain. Even during the early 1990's on the Interop show networks we discovered people streaming lewd stuff via DNS-looking UDP packets. (Another channel that we used, but it only works on a LAN, is to use the space between the end of a short IP packet and the end of the enclosing Ethernet frame. [Short IP packets are smaller than the minimum size of Ethernet frames.] This was largely used for license key exchanges.)
-
@EeveeEuphoria@social.translunar.academy 2026-03-27 21:44
@k3ym0 in today's episode of "this is lazy ai vibe-coded slop":
-
@esoteric_programmer@social.stealthy.club 2026-03-28 10:44
@k3ym0 holy shit, awesome! this sounds like a passage from @pluralistic little brother, I can't spoil it any further, but it involves dns