exodus icon indicating copy to clipboard operation
exodus copied to clipboard

This is not "always dns", sorry!

Open thau0x01 opened this issue 3 years ago • 3 comments

This tool works by opening a socket directly to the IP of the "DNS" server. In most networks, openning an UDP socket and connecting directly to a random IP address is not allowed. That's why we use DNS queries to perform exfiltration, because you don't need to connect directly to your server.

Always DNS means that data is transfered by the query resolution, don't matter what server perform this such query.

thau0x01 avatar Apr 15 '21 01:04 thau0x01

I agree, Caralho.

c3l3si4n avatar Apr 15 '21 01:04 c3l3si4n

I agree. fix this bro, what a shame!

scall0p avatar Apr 15 '21 01:04 scall0p

I see, fair enough. This was more of a PoC/toy project. But I'll consider adding more stuff to it. Even had more ideas integrating with DNS services that offer APIs to do some things.

cpl avatar Apr 15 '21 07:04 cpl