CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementMedium
A penetration tester has gained a shell on a Linux server that is restricted from making direct outbound connections to the internet, but can resolve external DNS queries. The tester wants to exfiltrate a small text file containing sensitive data (e.g., /etc/shadow) without attracting suspicion. Which of the following techniques would be MOST effective for this scenario?
- AEncoding the file content and exfiltrating it via DNS queries.
- BEstablishing an SSH tunnel to a remote server.
- CUsing an HTTP reverse shell to transmit the file.
- DDirectly uploading the file to a public file-sharing service.
Show answer & explanationAnswer & explanation
Correct answer: A. Encoding the file content and exfiltrating it via DNS queries.
DNS tunneling leverages the DNS protocol, which is often permitted through firewalls for name resolution, to create a covert channel. By encoding data into DNS queries or responses, a penetration tester can bypass egress filtering and exfiltrate data from restricted networks.
Why the other options are wrong
- B. Establishing an SSH tunnel requires outbound SSH connectivity, which is likely blocked in a restricted environment.
- C. An HTTP reverse shell requires direct outbound HTTP/HTTPS connections, which are restricted in this scenario.
- D. Directly uploading to a public service would require direct outbound internet access, which is restricted.
DNS Tunneling for Exfiltration
A technique to bypass network restrictions by encoding arbitrary data within DNS queries and responses, allowing for covert data transfer.
- Utilizes the DNS protocol as a covert channel.
- Effective in environments with strict egress filtering.
- Data is typically encoded (e.g., Base64) to fit DNS query format.
- Requires a controlled DNS server to receive and decode the tunneled data.
Memory trick: DNS queries can carry secrets like a hidden message in a bottle.