CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementMedium
A penetration tester has gained a shell on a Linux server that is restricted from making direct outbound connections to the internet, except for DNS queries. The tester wants to establish a persistent C2 channel for data exfiltration and command execution without alerting network defenders. Which technique is most suitable for this scenario?
- AICMP tunneling to bypass firewall rules.
- BReverse HTTP/HTTPS shell using a common web port.
- CDNS tunneling using a tool like iodine or dnscat2.
- DSSH tunnel to an external C2 server.
Show answer & explanationAnswer & explanation
Correct answer: C. DNS tunneling using a tool like iodine or dnscat2.
DNS tunneling is a technique that encapsulates other protocols within DNS queries and responses. Since DNS traffic is almost always allowed outbound, it provides a stealthy C2 channel for data exfiltration and command execution even when direct outbound connections are restricted.
Why the other options are wrong
- A. ICMP tunneling might be detected by network monitoring and can also be blocked by firewalls.
- B. Direct HTTP/HTTPS connections might be blocked by egress filtering, as only DNS is explicitly allowed.
- D. SSH tunnels require direct outbound TCP connections, which are restricted in this scenario.
DNS Tunneling for C2/Exfiltration
A covert communication technique that encodes data within DNS queries and responses to create a C2 channel or exfiltrate data, often bypassing firewalls that restrict other outbound traffic.
- Leverages the fact that DNS traffic is almost universally allowed outbound.
- Tools like iodine and dnscat2 facilitate DNS tunneling.
- Can be slow due to the nature of DNS protocol and query limits.
Memory trick: DNS hides secrets in plain sight.