EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesMedium

A system administrator is reviewing network traffic logs and observes unusual outbound connections originating from an internal server to an unknown external IP address on port 53 (DNS). Further investigation reveals that the data being exfiltrated is disguised as legitimate DNS queries and responses. Which advanced attack technique is most likely being employed?

  1. AICMP Tunneling
  2. BSSH Tunneling
  3. CDNS Tunneling
  4. DHTTP Tunneling
Show answer & explanation

Correct answer: C. DNS Tunneling

The scenario explicitly describes data exfiltration using DNS queries and responses on port 53 to an external IP, where the data is disguised as legitimate DNS traffic. This is the hallmark of DNS Tunneling, a technique used to bypass firewalls and security controls.

Why the other options are wrong

  • A. ICMP Tunneling uses ICMP echo requests/replies to encapsulate data, not DNS traffic.
  • B. SSH Tunneling uses SSH to create encrypted tunnels for forwarding network services, usually on port 22.
  • D. HTTP Tunneling uses HTTP requests/responses to encapsulate other protocols, typically on ports 80/443.

DNS Tunneling

A technique used by attackers to create a covert communication channel by encoding data within DNS queries and responses, often to bypass firewalls and exfiltrate data.

  • Leverages port 53, which is often allowed outbound through firewalls.
  • Can be used for command and control (C2), data exfiltration, or proxying traffic.
  • Difficult to detect without deep packet inspection and behavioral analysis.

Memory trick: Covert channels: DNS hides in queries, ICMP in pings, HTTP in web, SSH in shell.

More System Hacking Phases and Attack Techniques questions