Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Slide 56 onwards (2-way communication over DNS) is basically what Iodine [0] does to defeat firewalls. Quite a cool hack.

[0] http://code.kryo.se/iodine/



Hey, I'm the guy that wrote the talk and you're right - Iodone is similar in some ways.

Some quick background - I wrote the original version of dnscat a few years ago, and AFAIK Iodine was made at the same time. dnscat was designed to be an all-purpose DNS relay.

dnscat2 was re-written from scratch with one thing in mind - pentesting. It's NOT a general purpose DNS tunnel, and I've actively avoided adding features that would make it that way. It's for offensive security, plain and simple.

I realize I didn't call that out very well in the slides, and I should have. Next time! :)


Thanks for the background! I didn't know about the original dnscat - that's why I mentioned iodine in case someone was interested in trying this out as a tunneling method.

And thanks also for your thoroughly enjoyable talk.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: