Comment on Why is DNS often joked about in the I.T. Industry?

<- View Parent
IphtashuFitz@lemmy.world ⁨2⁩ ⁨months⁩ ago

Our web servers are locked down in such a way that you can’t copy data off of them using standard protocols like scp, ftp, and even http, etc. Our firewall blocks all such outbound traffic.

This hacker found a bug in a framework used on our web servers that let him execute commands remotely. When commands to copy data off the server failed using those more typical methods he switched to a more novel (and difficult) method of leveraging DNS instead. He discovered we weren’t locking DNS down the same way we were locking other protocols down and used that as a way to extract data from our server.

source
Sort:hotnewtop