CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementMedium

A penetration tester has gained a shell on a Linux server that is restricted from making direct outbound connections to the internet, but can resolve external DNS queries. The tester wants to exfiltrate a small text file containing sensitive data (e.g., /etc/shadow) without attracting suspicion. Which of the following techniques would be MOST effective for this scenario?

  1. AEncoding the file content and exfiltrating it via DNS queries.
  2. BEstablishing an SSH tunnel to a remote server.
  3. CUsing an HTTP reverse shell to transmit the file.
  4. DDirectly uploading the file to a public file-sharing service.
Show answer & explanation

Correct answer: A. Encoding the file content and exfiltrating it via DNS queries.

DNS tunneling leverages the DNS protocol, which is often permitted through firewalls for name resolution, to create a covert channel. By encoding data into DNS queries or responses, a penetration tester can bypass egress filtering and exfiltrate data from restricted networks.

Why the other options are wrong

  • B. Establishing an SSH tunnel requires outbound SSH connectivity, which is likely blocked in a restricted environment.
  • C. An HTTP reverse shell requires direct outbound HTTP/HTTPS connections, which are restricted in this scenario.
  • D. Directly uploading to a public service would require direct outbound internet access, which is restricted.

DNS Tunneling for Exfiltration

A technique to bypass network restrictions by encoding arbitrary data within DNS queries and responses, allowing for covert data transfer.

  • Utilizes the DNS protocol as a covert channel.
  • Effective in environments with strict egress filtering.
  • Data is typically encoded (e.g., Base64) to fit DNS query format.
  • Requires a controlled DNS server to receive and decode the tunneled data.

Memory trick: DNS queries can carry secrets like a hidden message in a bottle.

More Post-exploitation and Lateral Movement questions