DNS Tunnels (RE-REDUX)
ID: d222b964-1f62-5e22-aeb2-7e75d1b390fc
STIX ID: report--d222b964-1f62-5e22-aeb2-7e75d1b390fc
Feed Name: SensePost Blog
This document outlines a penetration testing technique to pivot from a compromised perimeter Linux webserver (accessed via a web command interpreter) into an internal network where only UDP/53 is permitted. It demonstrates establishing a dns2tcp tunnel to a remote server, then creating a reverse SSH port forward to expose internal services (e.g., HTTP on intranet hosts or SMB on a CEO laptop) and finally accessing them from the tester’s workstation via local SSH port forwarding. The method shows how to retarget internal hosts by modifying only the SSH reverse tunnel while keeping the DNS tunnel persistent.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
