CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementHard
After gaining access to a web server, a penetration tester discovers that outbound HTTP/HTTPS connections are heavily filtered, but DNS traffic is allowed. To maintain a covert channel for command and control (C2), which 'Burp Suite' feature or related technique would be MOST useful?
- AUsing Burp Repeater to replay HTTP requests to the C2 server.
- BImplementing a DNS tunnel by encoding C2 commands within DNS requests and responses.
- CLeveraging Burp Intruder to brute-force a hidden HTTP C2 endpoint.
- DConfiguring Burp Proxy to intercept and modify DNS queries.
Show answer & explanationAnswer & explanation
Correct answer: B. Implementing a DNS tunnel by encoding C2 commands within DNS requests and responses.
Given that HTTP/HTTPS is filtered but DNS is allowed, establishing a DNS tunnel is the most effective way to create a covert C2 channel. While Burp Suite itself doesn't natively create DNS tunnels, the concept of DNS tunneling is a critical technique for bypassing such restrictions, and a penetration tester would pivot to a tool (like dnscat2 or Iodine) to implement this.
Why the other options are wrong
- A. Burp Repeater relies on HTTP/HTTPS, which is blocked.
- C. Burp Intruder also relies on HTTP/HTTPS, which is blocked.
- D. Burp Proxy can intercept DNS if configured, but it doesn't inherently create a tunnel for C2; it's an inspection tool.
DNS Tunneling for C2
A technique that establishes a covert command and control (C2) channel by encapsulating attacker commands and victim responses within DNS queries and responses.
- Bypasses firewalls that block common C2 protocols (HTTP/S, SSH).
- Relies on the fact that DNS traffic is almost always allowed outbound.
- Requires a controlled DNS server to receive and process tunneled data.
Memory trick: For stealthy communication, use ghost signals through allowed channels.