Penetration Testing mailing list archives

Re: local proxy udp 53


From: shiri_yacov () hotmail com
Date: 14 Feb 2006 06:26:38 -0000

Hi Julian, 
if I understand correctly, You need to send/receive some illegal traffic (In terms of the network security policy), and 
your network allows traffic on port DNS "from any to any".
At this point, there are two possibilities.

A. The security mechanism (Firewall/Router) is probing the packet's destination port only.
B. There is some kind of content filtering device on the network, which assurs that packets on port DNS are truly DNS 
packets.

In case A, the answer to your question is quite simple. All you need is a port redirector - like Fpipe or winrelay 
which needs to operate on both sides (of your connection).

Case B is much more complicated, and requires a tailor made solution which will encode your protocol with DNS packets - 
some "AllYouWant over DNS".

I suppose A is your cup of tea...
Is it ?

------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner: 

Hackers are concentrating their efforts on attacking applications on your 
website. Up to 75% of cyber attacks are launched on shopping carts, forms, 
login pages, dynamic content etc. Firewalls, SSL and locked-down servers are 
futile against web application hacking. Check your website for vulnerabilities 
to SQL injection, Cross site scripting and other web attacks before hackers do! 
Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------


Current thread: