EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesHard
A system administrator notices unusual outbound network traffic from a critical database server during off-hours. Upon investigation, they find a suspicious executable running with system privileges. The executable appears to communicate with an external IP address over port 53 (DNS). What technique is the attacker MOST likely employing to maintain covert communication and control?
- AICMP exfiltration
- BSSH port forwarding
- CHTTP tunneling
- DDNS tunneling
Show answer & explanationAnswer & explanation
Correct answer: D. DNS tunneling
DNS tunneling involves encoding data within DNS queries and responses. Since DNS traffic (port 53) is commonly allowed through firewalls, attackers use this technique to establish a covert communication channel for command and control (C2) or data exfiltration, making it difficult to detect with standard network monitoring.
Why the other options are wrong
- A. ICMP exfiltration uses ICMP packets, not DNS queries.
- B. SSH port forwarding typically uses port 22 and is not inherently covert over DNS.
- C. HTTP tunneling uses port 80/443, not 53.
DNS Tunneling
A method of cyberattack that encodes data of other programs or protocols in DNS queries and responses to bypass firewalls and security controls, often for command and control or data exfiltration.
- Utilizes legitimate DNS protocol (port 53).
- Effective for covert communication due to common firewall rules.
- Can transport various types of data, including C2 commands and file transfers.
Memory trick: To 'hide' your 'messages', 'tunnel' them through common traffic.