HPE6-A84 · Question #21
Refer to the exhibit. Which security issue is possibly indicated by this traffic capture?
The correct answer is C. A command and control channel established with DNS tunneling. DNS tunneling is a technique that abuses the DNS protocol to tunnel data or commands between a compromised host and an attacker's server. DNS tunneling can be used to establish a command and control channel, which allows the attacker to remotely control the malware or…
Question
Refer to the exhibit. Which security issue is possibly indicated by this traffic capture?
Exhibit
Options
- AAn attempt at a DoS attack by a device acting as an unauthorized DNS server
- BA port scan being run on the 10.1.7.0/24 subnet
- CA command and control channel established with DNS tunneling
- DAn ARP poisoning or man-in-the-middle attempt by the device at 94:60:d5:bf:36:40
How the community answered
(50 responses)- A30% (15)
- B6% (3)
- C50% (25)
- D14% (7)
Explanation
DNS tunneling is a technique that abuses the DNS protocol to tunnel data or commands between a compromised host and an attacker's server. DNS tunneling can be used to establish a command and control channel, which allows the attacker to remotely control the malware or exfiltrate data from the infected host. The traffic capture in the exhibit shows some signs of DNS tunneling. The source IP address is 10.1.7.2, which is likely an internal host behind a firewall. The destination IP address is 8.8.8.8, which is a public DNS resolver. The DNS queries are for subdomains of badsite.com, which is likely a malicious domain registered by the attacker. The subdomains have long and random names, such as 0x2a0x2a0x2a0x2a0x2a0x2a0x2a0x2a.badsite.com, which could be used to encode data or commands. The DNS responses have large sizes, such as 512 bytes, which could be used to carry data or commands back to the host.
Topics
Community Discussion
No community discussion yet for this question.
