CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementMedium

A penetration tester has gained a shell on a Linux server that is restricted from making direct outbound connections to the internet, except for DNS queries. The tester wants to establish a persistent C2 channel for data exfiltration and command execution without alerting network defenders. Which technique is most suitable for this scenario?

  1. AICMP tunneling to bypass firewall rules.
  2. BReverse HTTP/HTTPS shell using a common web port.
  3. CDNS tunneling using a tool like iodine or dnscat2.
  4. DSSH tunnel to an external C2 server.
Show answer & explanation

Correct answer: C. DNS tunneling using a tool like iodine or dnscat2.

DNS tunneling is a technique that encapsulates other protocols within DNS queries and responses. Since DNS traffic is almost always allowed outbound, it provides a stealthy C2 channel for data exfiltration and command execution even when direct outbound connections are restricted.

Why the other options are wrong

  • A. ICMP tunneling might be detected by network monitoring and can also be blocked by firewalls.
  • B. Direct HTTP/HTTPS connections might be blocked by egress filtering, as only DNS is explicitly allowed.
  • D. SSH tunnels require direct outbound TCP connections, which are restricted in this scenario.

DNS Tunneling for C2/Exfiltration

A covert communication technique that encodes data within DNS queries and responses to create a C2 channel or exfiltrate data, often bypassing firewalls that restrict other outbound traffic.

  • Leverages the fact that DNS traffic is almost universally allowed outbound.
  • Tools like iodine and dnscat2 facilitate DNS tunneling.
  • Can be slow due to the nature of DNS protocol and query limits.

Memory trick: DNS hides secrets in plain sight.

More Post-exploitation and Lateral Movement questions