CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementHard

After gaining access to a web server, a penetration tester discovers that outbound HTTP/HTTPS connections are heavily filtered, but DNS traffic is allowed. To maintain a covert channel for command and control (C2), which 'Burp Suite' feature or related technique would be MOST useful?

  1. AUsing Burp Repeater to replay HTTP requests to the C2 server.
  2. BImplementing a DNS tunnel by encoding C2 commands within DNS requests and responses.
  3. CLeveraging Burp Intruder to brute-force a hidden HTTP C2 endpoint.
  4. DConfiguring Burp Proxy to intercept and modify DNS queries.
Show answer & explanation

Correct answer: B. Implementing a DNS tunnel by encoding C2 commands within DNS requests and responses.

Given that HTTP/HTTPS is filtered but DNS is allowed, establishing a DNS tunnel is the most effective way to create a covert C2 channel. While Burp Suite itself doesn't natively create DNS tunnels, the concept of DNS tunneling is a critical technique for bypassing such restrictions, and a penetration tester would pivot to a tool (like dnscat2 or Iodine) to implement this.

Why the other options are wrong

  • A. Burp Repeater relies on HTTP/HTTPS, which is blocked.
  • C. Burp Intruder also relies on HTTP/HTTPS, which is blocked.
  • D. Burp Proxy can intercept DNS if configured, but it doesn't inherently create a tunnel for C2; it's an inspection tool.

DNS Tunneling for C2

A technique that establishes a covert command and control (C2) channel by encapsulating attacker commands and victim responses within DNS queries and responses.

  • Bypasses firewalls that block common C2 protocols (HTTP/S, SSH).
  • Relies on the fact that DNS traffic is almost always allowed outbound.
  • Requires a controlled DNS server to receive and process tunneled data.

Memory trick: For stealthy communication, use ghost signals through allowed channels.

More Post-exploitation and Lateral Movement questions