Open cardosec

Case CD2F54 · Network · L3 Applied

DNS Tunneling

Practise as: Explain it · Interview · Deep dive

Interview questionHow does DNS tunneling work, and how would you detect it?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Data is encoded in subdomain labels of queries to an attacker-controlled authoritative server; replies carry data back
  2. Works because internal resolvers forward queries outbound even when direct egress is blocked
  3. Tools: iodine, dnscat2, DNS-based C2 in Cobalt Strike; often uses TXT, NULL or CNAME records
  4. Detect: high label entropy, long query names, high unique-subdomain count per domain, unusual TXT volume
  5. Prevent: force clients to internal resolvers, block external DNS and DoH, apply protective DNS and RPZ

If the interviewer pushes back

  • How does DNS over HTTPS change both the attacker and defender side of this problem?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.