Read [DNS Hack!] DNS "Wind Walk"
Network_Security_-_OS_Security.pngA hack system to bypass perimetral defense in most DMZ architectures.

The high level idea to bypass perimetral defense in most DMZ architectures is based to common DNS configuration that permit resolution without authentication.

Network architecture is visualized in next image:

DNS Wind Walk.

DNS resolution is allowed for any host that have one IP address, but the traffic is blocked AFTER name resolution if the firewall haven't a rule to permit traffic for a specified host. This rule is allowed dinamically by Radius Server response that identifies host like authorised checking UserName and Password.

If I succeed to create a IP tunnel in DNS traffic, I can perform a data transfer without authentication!!!

Soon I will insert more specific informations on the carried out job!

--
Enjoy!


Posted Friday 23 June 2006 - 14:36




<< Previous news | No more recent news

Other news about this topic

Read [DNS Hack!] DNS "Wind Walk" (23/06/2006 - 14:36) read 140 times
Necrosoft Home

Calendar
Date: 27/11/2009
Time: 15:51



Search





Poll
Tech_Bl0G Quality?






[ Results | Polls ]
Votes: 3 | Comments: 0

Users
People on-line:     
guests 3 guests

Stats
Visits: 2837
Statistics

Admin Login

: