Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. In today's episode of "Can It Run Doom": DNS fucking TXT records.

In today's episode of "Can It Run Doom": DNS fucking TXT records.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
infosecdnsdoomitisalwaysdns
10 Indlæg 9 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • k3ym0@infosec.exchangeK This user is from outside of this forum
    k3ym0@infosec.exchangeK This user is from outside of this forum
    k3ym0@infosec.exchange
    wrote sidst redigeret af
    #1

    In today's episode of "Can It Run Doom": DNS fucking TXT records.

    Some absolute madlad (cough Adam Rice cough) compressed the entire shareware DOOM WAD, split it into around 1,964 chunks, shoved them into Cloudflare TXT records, and wrote a PowerShell script that reassembles and runs the whole goddamn game from DNS queries alone. Nothing touches disk. The DLLs are in DNS. THE FUCKING DLLS ARE IN DNS.

    RFC 1035 was written in 1987. Those engineers are spinning in their graves fast enough to generate municipal power.

    Bonus: this is a fully functional globally-distributed covert data exfil channel that your NGFW will never fucking see if you're not doing deep DNS inspection. Sleep well.

    blog: https://blog.rice.is/post/doom-over-dns/

    repo: https://github.com/resumex/doom-over-dns

    Also lmao @ every blue team that has never once looked at their DNS query volume. How's that DLP policy working out for you.

    It was always DNS.

    #infosec #dns #doom #itisalwaysdns

    kajer@infosec.exchangeK badsamurai@infosec.exchangeB tarix29@tech.lgbtT circuitsunfish@plesiosaur.netC sabik@rants.auS 8 Replies Last reply
    1
    0
    • k3ym0@infosec.exchangeK k3ym0@infosec.exchange

      In today's episode of "Can It Run Doom": DNS fucking TXT records.

      Some absolute madlad (cough Adam Rice cough) compressed the entire shareware DOOM WAD, split it into around 1,964 chunks, shoved them into Cloudflare TXT records, and wrote a PowerShell script that reassembles and runs the whole goddamn game from DNS queries alone. Nothing touches disk. The DLLs are in DNS. THE FUCKING DLLS ARE IN DNS.

      RFC 1035 was written in 1987. Those engineers are spinning in their graves fast enough to generate municipal power.

      Bonus: this is a fully functional globally-distributed covert data exfil channel that your NGFW will never fucking see if you're not doing deep DNS inspection. Sleep well.

      blog: https://blog.rice.is/post/doom-over-dns/

      repo: https://github.com/resumex/doom-over-dns

      Also lmao @ every blue team that has never once looked at their DNS query volume. How's that DLP policy working out for you.

      It was always DNS.

      #infosec #dns #doom #itisalwaysdns

      kajer@infosec.exchangeK This user is from outside of this forum
      kajer@infosec.exchangeK This user is from outside of this forum
      kajer@infosec.exchange
      wrote sidst redigeret af
      #2

      @k3ym0 new cloud storage just dropped

      kajer@infosec.exchangeK 1 Reply Last reply
      0
      • kajer@infosec.exchangeK kajer@infosec.exchange

        @k3ym0 new cloud storage just dropped

        kajer@infosec.exchangeK This user is from outside of this forum
        kajer@infosec.exchangeK This user is from outside of this forum
        kajer@infosec.exchange
        wrote sidst redigeret af
        #3

        @k3ym0 big DNSFS energy

        https://blog.benjojo.co.uk/post/dns-filesystem-true-cloud-storage-dnsfs

        1 Reply Last reply
        0
        • k3ym0@infosec.exchangeK k3ym0@infosec.exchange

          In today's episode of "Can It Run Doom": DNS fucking TXT records.

          Some absolute madlad (cough Adam Rice cough) compressed the entire shareware DOOM WAD, split it into around 1,964 chunks, shoved them into Cloudflare TXT records, and wrote a PowerShell script that reassembles and runs the whole goddamn game from DNS queries alone. Nothing touches disk. The DLLs are in DNS. THE FUCKING DLLS ARE IN DNS.

          RFC 1035 was written in 1987. Those engineers are spinning in their graves fast enough to generate municipal power.

          Bonus: this is a fully functional globally-distributed covert data exfil channel that your NGFW will never fucking see if you're not doing deep DNS inspection. Sleep well.

          blog: https://blog.rice.is/post/doom-over-dns/

          repo: https://github.com/resumex/doom-over-dns

          Also lmao @ every blue team that has never once looked at their DNS query volume. How's that DLP policy working out for you.

          It was always DNS.

          #infosec #dns #doom #itisalwaysdns

          badsamurai@infosec.exchangeB This user is from outside of this forum
          badsamurai@infosec.exchangeB This user is from outside of this forum
          badsamurai@infosec.exchange
          wrote sidst redigeret af
          #4

          @k3ym0

          #dns

          1 Reply Last reply
          0
          • k3ym0@infosec.exchangeK k3ym0@infosec.exchange

            In today's episode of "Can It Run Doom": DNS fucking TXT records.

            Some absolute madlad (cough Adam Rice cough) compressed the entire shareware DOOM WAD, split it into around 1,964 chunks, shoved them into Cloudflare TXT records, and wrote a PowerShell script that reassembles and runs the whole goddamn game from DNS queries alone. Nothing touches disk. The DLLs are in DNS. THE FUCKING DLLS ARE IN DNS.

            RFC 1035 was written in 1987. Those engineers are spinning in their graves fast enough to generate municipal power.

            Bonus: this is a fully functional globally-distributed covert data exfil channel that your NGFW will never fucking see if you're not doing deep DNS inspection. Sleep well.

            blog: https://blog.rice.is/post/doom-over-dns/

            repo: https://github.com/resumex/doom-over-dns

            Also lmao @ every blue team that has never once looked at their DNS query volume. How's that DLP policy working out for you.

            It was always DNS.

            #infosec #dns #doom #itisalwaysdns

            tarix29@tech.lgbtT This user is from outside of this forum
            tarix29@tech.lgbtT This user is from outside of this forum
            tarix29@tech.lgbt
            wrote sidst redigeret af
            #5

            @k3ym0 you may already know this, but on a related note you can tunnel basically any IPv4 traffic over DNS: https://code.kryo.se/iodine/

            1 Reply Last reply
            0
            • k3ym0@infosec.exchangeK k3ym0@infosec.exchange

              In today's episode of "Can It Run Doom": DNS fucking TXT records.

              Some absolute madlad (cough Adam Rice cough) compressed the entire shareware DOOM WAD, split it into around 1,964 chunks, shoved them into Cloudflare TXT records, and wrote a PowerShell script that reassembles and runs the whole goddamn game from DNS queries alone. Nothing touches disk. The DLLs are in DNS. THE FUCKING DLLS ARE IN DNS.

              RFC 1035 was written in 1987. Those engineers are spinning in their graves fast enough to generate municipal power.

              Bonus: this is a fully functional globally-distributed covert data exfil channel that your NGFW will never fucking see if you're not doing deep DNS inspection. Sleep well.

              blog: https://blog.rice.is/post/doom-over-dns/

              repo: https://github.com/resumex/doom-over-dns

              Also lmao @ every blue team that has never once looked at their DNS query volume. How's that DLP policy working out for you.

              It was always DNS.

              #infosec #dns #doom #itisalwaysdns

              circuitsunfish@plesiosaur.netC This user is from outside of this forum
              circuitsunfish@plesiosaur.netC This user is from outside of this forum
              circuitsunfish@plesiosaur.net
              wrote sidst redigeret af
              #6

              @k3ym0 shit like this makes me glad I no longer work in #cybersec

              1 Reply Last reply
              0
              • k3ym0@infosec.exchangeK k3ym0@infosec.exchange

                In today's episode of "Can It Run Doom": DNS fucking TXT records.

                Some absolute madlad (cough Adam Rice cough) compressed the entire shareware DOOM WAD, split it into around 1,964 chunks, shoved them into Cloudflare TXT records, and wrote a PowerShell script that reassembles and runs the whole goddamn game from DNS queries alone. Nothing touches disk. The DLLs are in DNS. THE FUCKING DLLS ARE IN DNS.

                RFC 1035 was written in 1987. Those engineers are spinning in their graves fast enough to generate municipal power.

                Bonus: this is a fully functional globally-distributed covert data exfil channel that your NGFW will never fucking see if you're not doing deep DNS inspection. Sleep well.

                blog: https://blog.rice.is/post/doom-over-dns/

                repo: https://github.com/resumex/doom-over-dns

                Also lmao @ every blue team that has never once looked at their DNS query volume. How's that DLP policy working out for you.

                It was always DNS.

                #infosec #dns #doom #itisalwaysdns

                sabik@rants.auS This user is from outside of this forum
                sabik@rants.auS This user is from outside of this forum
                sabik@rants.au
                wrote sidst redigeret af
                #7

                @k3ym0
                IP over DNS has been a thing for a while now, sometimes used to bypass captive portals for paid internet access

                #infosec #dns #doom #itisalwaysdns

                1 Reply Last reply
                0
                • k3ym0@infosec.exchangeK k3ym0@infosec.exchange

                  In today's episode of "Can It Run Doom": DNS fucking TXT records.

                  Some absolute madlad (cough Adam Rice cough) compressed the entire shareware DOOM WAD, split it into around 1,964 chunks, shoved them into Cloudflare TXT records, and wrote a PowerShell script that reassembles and runs the whole goddamn game from DNS queries alone. Nothing touches disk. The DLLs are in DNS. THE FUCKING DLLS ARE IN DNS.

                  RFC 1035 was written in 1987. Those engineers are spinning in their graves fast enough to generate municipal power.

                  Bonus: this is a fully functional globally-distributed covert data exfil channel that your NGFW will never fucking see if you're not doing deep DNS inspection. Sleep well.

                  blog: https://blog.rice.is/post/doom-over-dns/

                  repo: https://github.com/resumex/doom-over-dns

                  Also lmao @ every blue team that has never once looked at their DNS query volume. How's that DLP policy working out for you.

                  It was always DNS.

                  #infosec #dns #doom #itisalwaysdns

                  linza@kamu.socialL This user is from outside of this forum
                  linza@kamu.socialL This user is from outside of this forum
                  linza@kamu.social
                  wrote sidst redigeret af
                  #8

                  @k3ym0

                  1 Reply Last reply
                  0
                  • k3ym0@infosec.exchangeK k3ym0@infosec.exchange

                    In today's episode of "Can It Run Doom": DNS fucking TXT records.

                    Some absolute madlad (cough Adam Rice cough) compressed the entire shareware DOOM WAD, split it into around 1,964 chunks, shoved them into Cloudflare TXT records, and wrote a PowerShell script that reassembles and runs the whole goddamn game from DNS queries alone. Nothing touches disk. The DLLs are in DNS. THE FUCKING DLLS ARE IN DNS.

                    RFC 1035 was written in 1987. Those engineers are spinning in their graves fast enough to generate municipal power.

                    Bonus: this is a fully functional globally-distributed covert data exfil channel that your NGFW will never fucking see if you're not doing deep DNS inspection. Sleep well.

                    blog: https://blog.rice.is/post/doom-over-dns/

                    repo: https://github.com/resumex/doom-over-dns

                    Also lmao @ every blue team that has never once looked at their DNS query volume. How's that DLP policy working out for you.

                    It was always DNS.

                    #infosec #dns #doom #itisalwaysdns

                    simondassow@masto.aiS This user is from outside of this forum
                    simondassow@masto.aiS This user is from outside of this forum
                    simondassow@masto.ai
                    wrote sidst redigeret af
                    #9

                    @k3ym0 Doom Network Service 🎉

                    1 Reply Last reply
                    0
                    • k3ym0@infosec.exchangeK k3ym0@infosec.exchange

                      In today's episode of "Can It Run Doom": DNS fucking TXT records.

                      Some absolute madlad (cough Adam Rice cough) compressed the entire shareware DOOM WAD, split it into around 1,964 chunks, shoved them into Cloudflare TXT records, and wrote a PowerShell script that reassembles and runs the whole goddamn game from DNS queries alone. Nothing touches disk. The DLLs are in DNS. THE FUCKING DLLS ARE IN DNS.

                      RFC 1035 was written in 1987. Those engineers are spinning in their graves fast enough to generate municipal power.

                      Bonus: this is a fully functional globally-distributed covert data exfil channel that your NGFW will never fucking see if you're not doing deep DNS inspection. Sleep well.

                      blog: https://blog.rice.is/post/doom-over-dns/

                      repo: https://github.com/resumex/doom-over-dns

                      Also lmao @ every blue team that has never once looked at their DNS query volume. How's that DLP policy working out for you.

                      It was always DNS.

                      #infosec #dns #doom #itisalwaysdns

                      dago@river.group.ltD This user is from outside of this forum
                      dago@river.group.ltD This user is from outside of this forum
                      dago@river.group.lt
                      wrote sidst redigeret af
                      #10

                      @k3ym0 shit. Time to do Bad Apple on DNS.

                      1 Reply Last reply
                      0
                      • jwcph@helvede.netJ jwcph@helvede.net shared this topic
                      Svar
                      • Svar som emne
                      Login for at svare
                      • Ældste til nyeste
                      • Nyeste til ældste
                      • Most Votes


                      • Log ind

                      • Har du ikke en konto? Tilmeld

                      • Login or register to search.
                      Powered by NodeBB Contributors
                      Graciously hosted by data.coop
                      • First post
                        Last post
                      0
                      • Hjem
                      • Seneste
                      • Etiketter
                      • Populære
                      • Verden
                      • Bruger
                      • Grupper