data exfiltration 101 - basics & dns tunnelling

61
- Data Exfiltration 101 - Basics & DNS Tunnelling ืžืืช ืžืื•ืจ ื’ื•ืจื“ื•ืŸ ื”ืงื“ืžื” ื‘ืฉื ื™ื ื”ืื—ืจื•ื ื•ืช, ืื™ืจื•ืข ืฉืœ ื“ืœื™ืคืช ืžื™ื“ืข ื”ืคืš ืœืื—ื“ ื”ืคื—ื“ื™ื ื”ื›ื™ ื’ื“ื•ืœื™ื ืฉืœ ื›ืœ ืืจื’ื•ืŸ, ื• ื™ ื“ึฐ ื› ื ื‘ึน ืœ : ื”ื ื–ืง ื”ื•ื ืขืฆื•ื ื›ืœื›)ื‘ื™ืŸ ืื ืžื™ื“ืข ืฉืœ ืžืฉืชืžืฉื™ื ืื• ืงื ื™ื™ืŸ ืจื•ื—ื ื™ ืื—ืจ( ืฉื ืขืฉื” ืœื—ื‘ืจื” ืฉื—ื•ื•ืชื” ืื™ืจื•ืข ื›ื–ื” ืœื™ืช ื•ืชื“ืžื™ืชื™ืช. ื—ืฉื•ื‘ ืœื–ื›ื•ืจ ืฉื—ื‘ืจื•ืช ื’ื“ื•ืœื•ืช ื”ืŸ ืœื ืืชืจWordPress ืคืฉื•ื˜ ืฉืžื•ืชืงืŸ ืขืœ ืื—ืกื•ืŸ ื‘ืฉืงืœ, ื•ืฉื”ื•ืฆืืช ืžื™ื“ืข ืžืชื•ืš ืžื—ืฉื‘ื™ื ืฉื ืžืฆืื™ื ื‘ืจืฉืชื•ืช ืคื ื™ืžื™ื•ืช ื“ื•ืจืฉืช ืืช ืžื” ืฉืžืชื•ืืจ ื‘ืกืจื˜ื™ื ื‘ืชื•ืจ- "ืœืขื‘ื•ืจ ืžืกืคืจ ื—ื•ืžื•ืช- ืืฉ".)ืื• ืฉื™ืจื•ืชื™ื ื—ื™ืฆื•ื ื™ื™ื( ืขืกืงื™ื ื‘ื™ื ื•ื ื™ื™ื ื•ื’ื“ื•ืœื™ื ื”ื—ืœื• ืœื”ืฉืชืžืฉ ื‘ืชื•ื›ื ื•ืช ืฉืžื˜ืจืชื ืœื–ื”ื•ืช ื•ืœื ื˜ืจืœ ื‘ื–ืžืŸ ืืžืช ื›ืœ ื ื™ืกื™ื•ืŸ ืชืงื™ืคื”, ื’ื™ืฉื•ืฉ ืื• ื’ื™ืฉื” ืœื- ืœื“ื•ื’' ืžืขืจื›ื•ืช( ืžื•ืจืฉื™ืช ื‘ืชื•ืš ื”ืจืฉืชIDS , ืžืขืจื›ื•ืชDLP , ืžืขืจื›ื•ืชEDR , ื ื™ื˜ื•ืจื™ ืจืฉืช, ื•ืœืื—ืจื•ื ื” ื’ื ื›ืืœื• ืฉืžืฉืชืžืฉื™ื ื‘- AI . ืœื›ืŸ, ืœื—ื“ื•ืจ ืœืจืฉืช ื›ื–ื• ื”ื™ื ื›ืžื• ืœื”ื™ื›ื ืก) ืœืžื‘ื•ืš ืœื™ื™ื–ืจื™ื- ืœื ืจืง ืฉื–ื” ืœื ืคืฉื•ื˜ ืœื”ื™ื›ื ืก, ื–ื” ื’ื ืœื ืคืฉ ื•ื˜ ืœื”ื•ืฆื™ื ืžืฉื ืžื™ื“ืข.ืžืงื•ืจ:[ Freepik ] ื›ื›ืœ ืฉืžื‘ื•ื›ื™ ื”ืœื™ื™ื–ืจื™ื ื ืขืฉื• ืกื‘ื•ื›ื™ื ื•ืžื•ืจื›ื‘ื™ื ื™ื•ืชืจ, ืชื•ืงืคื™ื ื ืืœืฆื• ืœืžืฆื•ื ืฉื™ื˜ื•ืช ื™ืฆื™ืจืชื™ื•ืช ื™ื•ืชืจ ืฉื™ืขื‘ืจื• ืืช ื”ืžื‘ื•ืš ื•ื™ื•ืฆื™ืื• ืžื™ื“ืข ืžืžื—ืฉื‘ื™ื ืฉื•ื ื™ื ืฉื ืžืฆืื™ื ืชื—ืช ื”ืฉื’ื—ื”, ื•ื–ืืช ืžื‘ืœื™ ืœื”ืชืจื™ืข ืขืœ ื›ืš ืœืžื ื”ืœื™ ื”- IT ืฉืœ ื”ืืจื’ื•ืŸ.

Upload: others

Post on 13-Nov-2021

7 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: Data Exfiltration 101 - Basics & DNS Tunnelling

-

Data Exfiltration 101 - Basics & DNS Tunnelling

ืžืื•ืจ ื’ื•ืจื“ื•ืŸ ืžืืช

ื”ืงื“ืžื”

ื™ื‘ืฉื ื™ื ื”ืื—ืจื•ื ื•ืช, ืื™ืจื•ืข ืฉืœ ื“ืœื™ืคืช ืžื™ื“ืข ื”ืคืš ืœืื—ื“ ื”ืคื—ื“ื™ื ื”ื›ื™ ื’ื“ื•ืœื™ื ืฉืœ ื›ืœ ืืจื’ื•ืŸ, ื• ื›ึฐื“ึดึผ : ื”ื ื–ืง ืœืึน ื‘ึดึผ

ืœื™ืช ืฉื ืขืฉื” ืœื—ื‘ืจื” ืฉื—ื•ื•ืชื” ืื™ืจื•ืข ื›ื–ื” )ื‘ื™ืŸ ืื ืžื™ื“ืข ืฉืœ ืžืฉืชืžืฉื™ื ืื• ืงื ื™ื™ืŸ ืจื•ื—ื ื™ ืื—ืจ( ื”ื•ื ืขืฆื•ื ื›ืœื›

ืคืฉื•ื˜ ืฉืžื•ืชืงืŸ ืขืœ ืื—ืกื•ืŸ ื‘ืฉืงืœ, WordPressื•ืชื“ืžื™ืชื™ืช. ื—ืฉื•ื‘ ืœื–ื›ื•ืจ ืฉื—ื‘ืจื•ืช ื’ื“ื•ืœื•ืช ื”ืŸ ืœื ืืชืจ

-ื•ืฉื”ื•ืฆืืช ืžื™ื“ืข ืžืชื•ืš ืžื—ืฉื‘ื™ื ืฉื ืžืฆืื™ื ื‘ืจืฉืชื•ืช ืคื ื™ืžื™ื•ืช ื“ื•ืจืฉืช ืืช ืžื” ืฉืžืชื•ืืจ ื‘ืกืจื˜ื™ื ื‘ืชื•ืจ

ืืฉ". -"ืœืขื‘ื•ืจ ืžืกืคืจ ื—ื•ืžื•ืช

ืฉืžื˜ืจืชื ืœื–ื”ื•ืช ื•ืœื ื˜ืจืœ ื‘ื–ืžืŸ ืขืกืงื™ื ื‘ื™ื ื•ื ื™ื™ื ื•ื’ื“ื•ืœื™ื ื”ื—ืœื• ืœื”ืฉืชืžืฉ ื‘ืชื•ื›ื ื•ืช )ืื• ืฉื™ืจื•ืชื™ื ื—ื™ืฆื•ื ื™ื™ื(

, DLP, ืžืขืจื›ื•ืช IDSืžื•ืจืฉื™ืช ื‘ืชื•ืš ื”ืจืฉืช )ืœื“ื•ื’' ืžืขืจื›ื•ืช -ืืžืช ื›ืœ ื ื™ืกื™ื•ืŸ ืชืงื™ืคื”, ื’ื™ืฉื•ืฉ ืื• ื’ื™ืฉื” ืœื

(. ืœื›ืŸ, ืœื—ื“ื•ืจ ืœืจืฉืช ื›ื–ื• ื”ื™ื ื›ืžื• ืœื”ื™ื›ื ืก AI-, ื ื™ื˜ื•ืจื™ ืจืฉืช, ื•ืœืื—ืจื•ื ื” ื’ื ื›ืืœื• ืฉืžืฉืชืžืฉื™ื ื‘EDRืžืขืจื›ื•ืช

ื•ื˜ ืœื”ื•ืฆื™ื ืžืฉื ืžื™ื“ืข.ืœื ืจืง ืฉื–ื” ืœื ืคืฉื•ื˜ ืœื”ื™ื›ื ืก, ื–ื” ื’ื ืœื ืคืฉ -ืœืžื‘ื•ืš ืœื™ื™ื–ืจื™ื

[Freepik]ืžืงื•ืจ:

ื›ื›ืœ ืฉืžื‘ื•ื›ื™ ื”ืœื™ื™ื–ืจื™ื ื ืขืฉื• ืกื‘ื•ื›ื™ื ื•ืžื•ืจื›ื‘ื™ื ื™ื•ืชืจ, ืชื•ืงืคื™ื ื ืืœืฆื• ืœืžืฆื•ื ืฉื™ื˜ื•ืช ื™ืฆื™ืจืชื™ื•ืช ื™ื•ืชืจ ืฉื™ืขื‘ืจื•

-ื”ืžื‘ืœื™ ืœื”ืชืจื™ืข ืขืœ ื›ืš ืœืžื ื”ืœื™ ื•ื–ืืชืืช ื”ืžื‘ื•ืš ื•ื™ื•ืฆื™ืื• ืžื™ื“ืข ืžืžื—ืฉื‘ื™ื ืฉื•ื ื™ื ืฉื ืžืฆืื™ื ืชื—ืช ื”ืฉื’ื—ื”,

IT ืฉืœ ื”ืืจื’ื•ืŸ.

Page 2: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

2 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

DNS-ื•ื™ ืื™ืš ืืชื ืจื•ืื™ื ืืช ื”ืกื™ื˜ื•ืืฆื™ื”(, ื™ืฉ ื“ื‘ืจื™ื ืฉืœื ืžืฉืชื ื™ื. ืžืขืจื›ืช ื”ืืš ืœืžื–ืœื ื• )ืื• ืœืฆืขืจื ื•, ืชืœ

)ื•ืื ื™ ื™ื•ื“ืข, ื›ื™ 3891ื”ืžืฆื™ื ืื•ืชื” ื‘ืฉื ืช Paul Mockapetris-ื”ื‘ืกื™ืกื™ืช ื›ืžืขื˜ ื•ืœื ืขื‘ืจื” ืฉื™ื ื•ื™ื™ื ืžืื– ืฉ

ืœื™, -, ืกืจ ื˜ื™ื ื‘ืจื ืจืก3888ื‘ืฉื ืช ืฉืงืฉื•ืจื™ื ืœื›ืš. ืœื ื”ื™ื• ืฉื™ื ื•ื™ื™ื ืžืืกื™ื‘ื™ื™ื(. RFC-ืงืจืืชื™ ื‘ืขื™ื•ืŸ ืืช ื›ืœ ื”

:DNS, ืืžืจ ืžืฉืคื˜ ืžืจืชืง ื‘ื ื•ื’ืข ืœืžืขืจื›ื•ืช HTMLืคืช ื”ืžืžืฆื™ื ืฉืœ ืฉ

ื”ืžืขืจื›ืช ืžื”ื•ื•ื” ื‘ืกื™ืก ืงืจื™ื˜ื™ ืœื›ืœ ืื“ื ืฉืจื•ืฆื” ืœื’ืœื•ืฉ ื‘ืื™ื ื˜ืจื ื˜. ื‘ืžืขืจื›ืช -ื•ืื›ืŸ, ื™ืฉ ืœื• ื ืงื•ื“ื” ื˜ื•ื‘ื”

ื’ื•ืจืžืช ืœืžืขืจื›ืช DNS, ื’ื ืื ื™ืฉ ื—ื™ื‘ื•ืจ ืœืื™ื ื˜ืจื ื˜ ื•ืœืกืคืง ืจืฉืช, ื—ื•ืกืจ ื’ื™ืฉื” ืœืฉืจืช Windows 10ื”ื”ืคืขืœื”

ืื™ืŸ ื—ื™ื‘ื•ืจ ืื™ื ื˜ืจื ื˜ ื‘ื›ืœืœ. - DNSื–ื” ื›ื™ )ืœื˜ืขื ืชื( ืื ืื™ืŸ ืœื”ืฆื™ื’ ืกืžืœ ืœืคื™ื• ืื™ืŸ ืชืงืฉื•ืจืช ืื™ื ื˜ืจื ื˜ ื›ืœืœ, ื•

ื“ืจืš ืฉื‘ื” ืชื•ืงืฃ ื™ื›ื•ืœ -ืฉืื™ื ืŸ ืžื ื•ื”ืœื•ืช ื›ืจืื•ื™ ืขืœื•ืœื•ืช ืœื”ื™ื•ืช ืœื”ื•ื•ืช ื—ื•ืจ ื‘ืžื‘ื•ืš ื”ืœื™ื™ื–ืจื™ื DNSืžืขืจื›ื•ืช

ืœื”ื•ืฆื™ื ืžื™ื“ืข ืžืžื—ืฉื‘ )ื•ื ืจืื” ื‘ื”ืžืฉืš ื’ื ืื™ืš ืขื•ืฉื™ื ื–ืืช(.

ืžืฉืชื™ ื ืงื•ื“ื•ืช ืžื‘ื˜: Data Exfiltrationื‘ืžืืžืจ ื”ื–ื” ืืกืงื•ืจ ืืช ื”ื ื•ืฉื ืฉืœ

ืžื” ืžืืคื™ื™ืŸ ืฉื™ื˜ื” ื˜ื•ื‘ื” ืœื”ื“ืœืคืช ืžื™ื“ืข? ื”ืื ื™ืฉ -ื ืืคื™ื™ืŸ ืืช ื”ื ื•ืฉื - ื•ื“ืช ืžื‘ื˜ื• ืฉืœ ืžื”ื ื“ืกื ืง

ืฉื™ื˜ื” ืžื•ืฉืœืžืช? ืืฆื™ื’ ืฉื™ื˜ื•ืช ืงื™ื™ืžื•ืช ื•ื ืคื•ืฆื•ืช, ื•ื ื™ืชื•ื— ืœื’ื‘ื™ ื™ืชืจื•ื ื•ืช ื•ื—ืกืจื•ื ื•ืช ื”ืžืœื•ื•ื™ื ื‘ื›ืœ ืฉื™ื˜ื”.

ื ืขื‘ื•ืจ ืขืœ ืชื”ืœื™ืš ื”ื—ืฉื™ื‘ื” ื•ืคืชืจื•ืŸ ื”ื‘ืขื™ื•ืช ืžืื—ื•ืจื™ ื‘ื ื™ื™ืช ืžืขืจื›ืช ืžืฉืœื™ - ื ืงื•ื“ืช ืžื‘ื˜ื• ืฉืœ ืชื•ืงืฃ

, ื•ืžืกืชืžื›ืช ืขืœ ื”ืขืงืจื•ื ื•ืช ืฉื™ื•ื’ื“ืจื• ื‘ื ืงื•ื“ืช DNS Tunnellingืฉืžื‘ื•ืกืกืช ืขืœ Data Exfiltrationืœื‘ื™ืฆื•ืข

, ื•ืืฆื™ื’ ื“ืจืš ืฉื‘ื” ืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ืขื‘ื™ืจ ืžื™ื“ืข ืขืœ ื™ื“ื™ ื ื™ืฆื•ืœ DNSื”ืžื‘ื˜ ืฉืœ ื”ืžื”ื ื“ืก. ืืกืงื•ืจ ืืช ืคืจื•ื˜ื•ืงื•ืœ

ื”ืคืจื•ื˜ื•ืงื•ืœ.

Page 3: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

3 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ื”ืžื”ื ื“ืกื ืงื•ื“ืช ืžื‘ื˜ื• ืฉืœ

ื ืฉื™ื˜ื•ืช ืงื™ื™ืžื•ืช ื‘ื›ื•ื‘ืข ื”ืžื”ื ื“ืก, ื ืจืฆื” ืœื”ื›ื™ืจ ืืช ื”ืขืงืจื•ื ื•ืช ื”ื‘ืกื™ืกื™ื™ื ื•ื›ืžื• ื›ืŸ ื’

)ื›ื™ ืœืžื” ืœื”ืžืฆื™ื ืืช ื”ื’ืœื’ืœ ืžื—ื“ืฉ ื›ืฉืืคืฉืจ ืœืงื ื•ืช Data Exfiltrationืœื‘ื™ืฆื•ืข

ื’ืœื’ืœื™ื ืงื™ื™ืžื™ื ื•ืœืฉืคืจ ืื•ืชื?(.

?Data Exfiltrationืžื” ื–ื”

Darren Kitchen ื—ื•ืงืจ ืื‘ื˜ื—ื” ื•ื”ืžื™ื™ืกื“ ืฉืœ ,Hak5 ื ืชืŸ ื”ื’ื“ืจื” ืžืจืชืงืช )ื•ืฆื™ื ื™ืช ,

ืขื‘ืจื™ืช(:" )ืื• "ื–ืœื™ื’ืช ืžื™ื“ืข" ื‘Data Exfiltrationืœื”ืคืœื™ื( ืœืžื•ืฉื’ "

ื”ืžื•ืฉื’ "ื–ืœื™ื’ืช ืžื™ื“ืข" ืžืชืืจ ืกื˜ ืฉืœ ืฉื™ื˜ื•ืช ื•ื™ื›ื•ืœื•ืช ืœื”ืฉื’ืช ืžื™ื“ืข ืจื’ื™ืฉ ื•ื—ืกื•ื™ ืžื”ืจืฉืช ืฉืœ ืืจื’ื•ืŸ ืœื™ื“ื™ื• ืฉืœ

ืชื•ืงืฃ. ื–ื” ืงื•ืจื” ืชื—ืช ื”ื”ื ื—ื” ืฉื”ืชื•ืงืฃ ื›ื‘ืจ ื ืžืฆื ื‘ืชื•ืš ื”ืจืฉืช, ื•ืฉื”ื•ื ืžืฆื ืžื—ืฉื‘ ืฉืžื›ื™ืœ ืืช ื”ืžื™ื“ืข

ื•ื˜ื•ืžื˜ื™ืช ืขืœ ื™ื“ื™ ืงื•ื“ ื”ืจืฆื•ื™. ื”ืชื”ืœื™ืš ื™ื›ื•ืœ ืœื”ื™ื•ืช ื™ื“ื ื™, ืขืœ ื™ื“ื™ ืชื•ืงืฃ ื‘ืขืœ ื’ื™ืฉื” ืคื™ื–ื™ืช ืœืžื—ืฉื‘, ืื• ืžื‘ื•ืฆืข ื

ืฉืžืฉื•ืœื‘ ืœืจื•ื‘ ืขื ื ื•ื–ืงื” ื›ืœืฉื”ื™.

ื›ืœ ืชื”ืœื™ืš ืฉืžืชืืจ ื”ืขืชืงืช ืžื™ื“ืข ืืœ ืžื›ืฉื™ืจ ืฉืื™ืŸ ืœื• ื”ืจืฉืื” ืœื”ื—ื–ื™ืง ื‘ืžื™ื“ืข ื”ื "ืœ ื ื—ืฉื‘ ืœืชื”ืœื™ืš ื–ืœื™ื’ืช

"ืขืจื•ืฅ ืชืงืฉื•ืจืช" ืฉืื™ืŸ ืขืœื™ื• ื”ืจื‘ื” ื”ืฉื’ื—ื”, ื•ืœืงื•ื“ื“ ืืœื™ื• ืืช ื”ืžื™ื“ืข ืื•ืชื• -ืžื™ื“ืข. ืœืจื•ื‘, ื ืจืฆื” ืœื”ืฉืชืžืฉ ื‘

ืืžื ื ื”ืฉืœื‘ ื”ืื—ืจื•ืŸ ื‘ืฉืจืฉืจืช ืชืงื™ืคื•ืช ืกื™ื™ื‘ืจ ืืš ื”ื™ื ื ืจืฆื” ืœื”ืขื‘ื™ืจ. ื”ื•ืฆืืช ื”ืžื™ื“ืข ืžื”ืžื—ืฉื‘ ื”ื™ื

ื—ืฉื•ื‘ื” ืœื ืคื—ื•ืช ืžื”ืฉืœื‘ื™ื ืฉืœืคื ื™ื”.

ืื– ืชื•ืงืฃ ื”ืฉื™ื’ ื’ื™ืฉื” ืœืจืฉืช ืฉืœ ืืจื’ื•ืŸ ื’ื“ื•ืœ, ื•ืžืฆื ืืช ื”ืžื™ื“ืข ืฉื”ื•ื ืจื•ืฆื” ืœื”ื•ืฆื™ื. ืžื” ื›ืขืช? ืฆืจื™ืš ืœื”ื‘ื™ืŸ

DLP, ืชื•ื›ื ื•ืช anti-exfiltrationืื™ืš ืœืฉืœื•ื— ืืช ื”ืžื™ื“ืข ื—ื–ืจื” ืืœ ื”ืชื•ืงืฃ ื•ื‘ื• ื–ืžื ื™ืช ืœื”ืชื—ืžืง ืžืชื•ื›ื ื•ืช

)ืงื™ืฆื•ืจ ืฉืœ IDS, ืชื•ื›ื ื•ืช ืฉื ื•ืขื“ื• ืœื—ืคืฉ ื•ืœืขืฆื•ืจ ื–ืœื™ื’ื•ืช ืžื™ื“ืข(, ืชื•ื›ื ื•ืช Data Leak Preventionื•ืจ ืฉืœ )ืงื™ืฆ

Intrusion Detection System ืœื’ื™ืœื•ื™ ื—ื“ื™ืจื” ืœืจืฉืช(, ื›ืœื™ื ืœื ื™ื˜ื•ืจ ื”ืจืฉืช ื•ื›ื•' )ื ืคืจื˜ ืขืœ ื›ืš ื‘ื”ืžืฉืš(. ื›ืœ ,

ื”ืชืงื™ืคื” ื™ื›ื•ืœื” ืœื”ื™ื•ืช ืœืฉื•ื•ื ืื ืœื ื™ืžืฆืื• ื“ืจืš ืœื”ื•ืฆื™ื ืžื™ื“ืข ืžื”ืจืฉืช ืฉืœ ื”ืืจื’ื•ืŸ.

[Team Fortress 2 :ืžืงื•ืจ]

Page 4: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

4 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

"ืกื•ื”ืจ"ื” - ื”ื”ื‘ืขื™

(, ืงืจื™ืคื˜ื•ื’ืจืคืจ ื•ืžืชืžื˜ื™ืงืื™ ืžื•ืขืจืš, ื›ืชื‘ ืžืืžืจ Gustavus J. Simmons, ื’ื•ืกื˜ืื‘ื•ืก ืกื™ืžื•ื ืก )3891ื‘ืฉื ืช

Subliminal the and Problemโ€™ Prisoners The ืคื•ืจืฅ ื“ืจืš ืฉื ืงืจื "ื‘ืขื™ื™ืช ื”ืืกื™ืจื™ื ื•ื”ืขืจื•ืฅ ื”ืกืื‘ืœื™ืžื™ื ืœื™" )

annelCh.)

ื‘ืขื™ื™ืช ื”ืืกื™ืจื™ื

ื‘ืžืืžืจ, ื”ื•ื ืžืฆื™ื’ ืืช ื”ื‘ืขื™ื” ืฉืœื ื• ื‘ืืžืฆืขื•ืช ืกื™ืคื•ืจ ืฉื ืงืจื "ื‘ืขื™ื™ืช ื”ืืกื™ืจื™ื" )ืœื ืœื”ืชื‘ืœื‘ืœ ืขื "ื“ื™ืœืžืช

ื”ืืกื™ืจ" ืฉืœ ืชื•ืจืช ื”ืžืฉื—ืงื™ื(:

ืฉื ื™ ืืกื™ืจื™ื ื ืขื•ืœื™ื ื‘ืฉื ื™ ืชืื™ ืžืขืฆืจ ืฉืฆืžื•ื“ื™ื ื–ื” ืœื–ื” ื•ื”ื ืžืชื›ื ื ื™ื ืืช ื”ื‘ืจื™ื—ื” ืฉืœื”ื. ืžื•ืชืจ ืœื”ื ืœื“ื‘ืจ

ืžื•ืข ืืช ื”ืฉื™ื—ื” ืฉืœื”ื. ืœื“ื‘ืจ ืื—ื“ ืขื ื”ืฉื ื™ ื–ืืช ื“ืจืš ื”ืชืงืฉื•ืจืช ืื—ื“ ืขื ื”ืฉื ื™ ืื‘ืœ ื”ืกื•ื”ืจ ื™ื›ื•ืœ ืœืฉ

ืื ื”ืฉื•ืžืจ ื™ื—ื•ืฉ ืฉื”ื ืžืชื›ื ื ื™ื ืžืฉื”ื•, ื”ื•ื ื™ืขื‘ื™ืจ -ื‘ื™ืŸ ืฉื ื™ื”ื. ื”ื ื—ื™ื™ื‘ื™ื ืœื”ื™ื–ื”ืจ ื”ืืคืฉืจื™ืช ื”ื™ื—ื™ื“ื”

.ืฉืœื”ื ืชื•ื›ื ื™ืช ื”ื‘ืจื™ื—ื”ืืช ืื•ืชื ืœืชืื™ื ืจื—ื•ืงื™ื ื™ื•ืชืจ, ื•ื‘ื›ืš ื™ืžื ืข ื›ืœ ืชืงืฉื•ืจืช ื‘ื™ื ื™ื”ื ื•ื™ื”ืจื•ืก

ืชื›ื ืŸ ื‘ืจื™ื—ื”?ืื™ืš ื™ื›ื•ืœื™ื ื”ืืกื™ืจื™ื ืœืชืงืฉืจ ื‘ื™ื ื™ื”ื ื•ืœ

Page 5: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

5 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

: ื”ืฆืคื ื” 1ื ื™ืกื™ื•ืŸ ืคืชืจื•ืŸ #

ื ื’ื™ื“ ืฉืžื‘ืขื•ื“ ืžื•ืขื“, ื”ื—ืœื™ื˜ื• ื”ืืกื™ืจื™ื ืฉื‘ืžื™ื“ื” ื•ื™ื™ืชืคืกื• ื”ื ื™ื•ื›ืœื• ืœืชื›ื ืŸ ืืช ื”ื‘ืจื™ื—ื” ืฉืœื”ื ื‘ืืžืฆืขื•ืช

ืฉื™ืžื•ืฉ ื‘ืฆื•ืคืŸ ืงื™ืกืจ ืขื ืžืคืชื— -ืฉื™ืžื•ืฉ ื‘ืฉื™ื˜ืช ื”ืฆืคื ื” )ืœืฆื•ืจืš ื”ื”ื“ื’ืžื” ื ืฉืชืžืฉ ื‘ืฉื™ื˜ื” ื‘ืกื™ืกื™ืช ื‘ื™ื•ืชืจ(

ืื•ืชื™ื•ืช ืงื“ื™ืžื”(, 'ื‘' ื–ื” 'ื–' ื•ื›ื•' : 5'ื' ื–ื” 'ื•' )-. ืฆื•ืคืŸ ืงื™ืกืจ ื”ื•ื ืฆื•ืคืŸ ื”ื–ื–ื”, ื›ืš ืฉ5

ื”ืฉื•ืžืจ ืื™ื ื• ืžื•ื“ืข ืœื”ืกื“ืจ ื”ื–ื”, ืจืง ืฉื ื™ ื”ืืกื™ืจื™ื ืžื›ื™ืจื™ื ืืช ืฉื™ื˜ืช ื”ื”ืฆืคื ื” ื•ืœื›ืŸ ืฉื ื™ื”ื ื™ื›ื•ืœื™ื ืœืชืงืฉืจ

ื‘ื™ื ื™ื”ื ืžื‘ืœื™ ืฉื”ืฉื•ืžืจ ื™ื‘ื™ืŸ ืืช ืชื•ื›ืŸ ื”ืฉื™ื—ื” ืฉืœื”ื )ืืœื• ืฉืžืฉืขืžื ืœื”ื ื•ืžืขื•ื ื™ื™ื ื™ื ืœืชืจื’ื ืืช ื”ืชืงืฉื•ืจืช

(:ืžื•ื–ืžื ื™ื ืœืขืฉื•ืช ื–ืืชืฉืœ ื”ืืกื™ืจื™ื

. ื›ืชื•ืฆืื” ื—ื•ืกืจ ื”ื™ื›ื•ืœืช ืฉืœื• ืœื”ื‘ื™ืŸ ืื•ืชื ื’ื•ืจื ืœื• ืœื—ืฉื•ื“ ื‘ื”ืืœืžืจื•ืช ืฉื”ืกื•ื”ืจ ืœื ืžื‘ื™ืŸ ืืช ืชื•ื›ืŸ ื”ืฉื™ื—ื”,

ืžื›ืš ื”ื•ื ืฉื ืื•ืชื ื‘ืชืื™ื ืจื—ื•ืงื™ื ื™ื•ืชืจ ื•ืขื•ืฆืจ ื›ืœ ืชืงืฉื•ืจืช ื‘ื™ื ื™ื”ื )ื”ื ืœื ื™ื›ื•ืœื™ื ืœืชื›ื ืŸ ื‘ืจื™ื—ื” ืขื›ืฉื™ื•(.

ืœื›ืŸ, ื”ืฆืคื ื” ืœื‘ื“ื” ื”ื™ื ืœื ืคืชืจื•ืŸ ืœื‘ืขื™ื”.

ืขืจื•ืฅ ืชืงืฉื•ืจืช ืกืžื•ื™: 2ื ื™ืกื™ื•ืŸ ืคืชืจื•ืŸ #

ื ื ืกื” ื›ื™ื•ื•ืŸ ืื—ืจ. ื‘ืžืงื•ื ืœื”ืฆืคื™ืŸ ืืช ื”ืžื™ื“ืข ืœื‘ืœื™ืœ ื—ืกืจ ืžืฉืžืขื•ืช ืฉืœ ืื•ืชื™ื•ืช ื‘ืขื‘ืจื™ืช, ื ื ืกื” ืœืงื•ื“ื“ ืžื™ื“ืข

ืžืกื•ื™ื ืœืžืฉืคื˜ ื ืคื•ืฅ ื•ื”ื’ื™ื•ื ื™ ื‘ืขื‘ืจื™ืช ืื• ืœืžื™ืœื” ื”ื’ื™ื•ื ื™ืช ื‘ืขื‘ืจื™ืช:

"ื”ื™ื™", ื ืชื—ื™ืœ ืœืกืคื•ืจ ืืช ื›ืžื•ืช ื”ืคืขืžื™ื ืฉืžื™ืœื™ื ืžืกื•ื™ืžื•ืช -ื›ืืฉืจ ืื—ื“ ื”ืืกื™ืจื™ื ืื•ืžืจ ืžืฉืคื˜ ืฉืžืชื—ื™ืœ ื‘

ืขืœ ืขืฆืžืŸ. ื—ื•ื–ืจื•ืช

Page 6: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

6 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ื•ื›ืœ ืคืขื ืฉื”ืืกื™ืจ ืื•ืžืจ 2, ื›ืœ ืคืขื ืฉื”ืืกื™ืจ ืื•ืžืจ "ืืชื”" ื ื•ืกื™ืฃ 3ื›ืœ ืคืขื ืฉื”ืืกื™ืจ ืื•ืžืจ "ืื ื™" ื ื•ืกื™ืฃ

)ื ืชื—ื™ืœ ืœืกืคื•ืจ ืจืง ืžื”ืจื’ืข ืฉื‘ื• ื”ืืกื™ืจ ืื•ืžืจ "ื”ื™ื™", ื›ื“ื™ ืฉืœื ื ืคืกื•ืœ ืฉื™ืžื•ืฉ ืจื’ื™ืœ ื‘ืžื™ืœื™ื 31"ืื ื—ื ื•" ื ื•ืกื™ืฃ

ื”ื‘ืกื™ืกื™ื•ืช ื”ืœืœื•(:

ืช ื‘ืชื•ืจ ืฉื™ื˜ืช ืงื™ื“ื•ื“ ืœืžืกืคืจื™ื )ืœื ื–ื›ื•ืจ ืœื™ ืžื“ื•ื‘ืจ ื‘ืฉื™ื˜ื” ืœื ืฉื’ืจืชื™ืช ื‘ื›ืœืœ ืœื”ืฉืชืžืฉ ื‘ืžื™ืœื™ื ื‘ืขื‘ืจื™

ืฉืœืžื“ืชื™ ืืช ื–ื” ืœื‘ื’ืจื•ืช ื‘ืœืฉื•ืŸ ื‘ื›ืœ ืžืงืจื”(. ื‘ืื•ืคืŸ ื–ื”ื” ืœืฉื™ื˜ื” ื”ืจืืฉื•ื ื”, ื”ืกื•ื”ืจ ืื™ื ื• ืžื•ื“ืข ืœื˜ื‘ืœืช

ื”ืžืฉืžืขื•ื™ื•ืช ืฉืœ ืฉื™ื˜ืช ื”ืงื™ื“ื•ื“ ืฉื™ืฆืจื• ื”ืืกื™ืจื™ื. ื”ืืกื™ืจื™ื ื”ื ื”ื™ื—ื™ื“ื™ื ืฉืžื›ื™ืจื™ื ืืช ื”ืฉื™ื˜ื” ื•ืœื›ืŸ ื”ื

ื ืฉื™ื ืฉืฉื•ืžืขื™ื )ื›ื•ืœืœ ื”ืกื•ื”ืจ( ืœื ืืžื•ืจื™ื ืืžื•ืจื™ื ืœื”ื™ื•ืช ื”ื™ื—ื™ื“ื™ื ืฉืžื‘ื™ื ื™ื ื–ื” ืืช ื–ื” ื‘ืขื•ื“ ืฉืฉืืจ ื”ื

ืœื—ืฉื•ื“. ื›ืขืช, ืื ื™ืจืฆื• ืœืงื‘ื•ืข ื‘ืื™ื–ื• ืฉืขื” ืœื”ืชื—ื™ืœ ืืช ื”ื—ืคื™ืจื•ืช ืœืžื ื”ืจื” ื‘ืฉื‘ื™ืœ ื”ื‘ืจื™ื—ื”, ื™ื•ื›ืœ ืื—ื“ ืžื”ื

ืœื•ืžืจ ืžืฉืคื˜ ื›ืžื• ื”ืžืฉืคื˜ ื”ื‘ื:

ื›ื™ ืžื‘ื—ื™ื ืชื• ื”ื•ื ืœื ืจื•ืื” ืฉื ืขืฉื” ืคื” ืฉื•ื ื“ื‘ืจ ื–ื“ื•ื ื™. ื”ืกื•ื”ืจ ื™ืืฉืจ ืืช ื”ืชืงืฉื•ืจืช ื‘ื™ื ื™ื”ืื•ื”ืชื•ืฆืื”?

ื•ืง ืžืจื’ืฉ ื•ืื•ืคื˜ื™ืžื™ ืœืžืจื•ืช ืฉื”ื ื›ื ืจืื” ืœื ื™ืฉืชื—ืจืจื• ื‘ื–ืžืŸ ื”ืงืจื•ื‘ )ื›ื™ ื”ื ื‘ื›ืœื ืžื‘ื—ื™ื ืชื•, ื–ื” ืžืฉืคื˜ ื—ื™ื–

ืขืœ ืคืฉืข ืฉืขืฉื•(, ืื™ืŸ ืกื™ืžื ื™ื ื ืจืื™ื ืœืขื™ืŸ ืœืชื›ื ื•ืŸ ื‘ืจื™ื—ื” ืžื”ื›ืœื.

ื”ืื ื–ื” ืื™ื“ื™ืืœื™? ื‘ื•ื•ื“ืื•ืช ืœื. ืื‘ืœ ืœืคื—ื•ืช ื–ื” ืขื•ื‘ื“...

Page 7: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

7 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ืขืจื•ืฆื™ ืชืงืฉื•ืจืช ืกืžื•ื™ื™ื -ื”ืคืชืจื•ืŸ

ืกื™ืžืชื” ื”ืžื™ื™ื“ื™ืช ืฉืœ ื”ื—ื‘ื™ืœื” ืžืœืฆืืช ืฉืœื™ื—ืช ื”ืžื™ื“ืข ื”ืžืคื•ืจืฉ ื“ืจืš ื›ืœ ืฉื™ื˜ื” ื‘ืจื•ืจื” ื“ื•ืžื” ื™ื’ืจื•ื ืœื—

( ืฉืžืชืืจื™ื ื›ืœ ืฉื™ื˜ื” CWE :Channels Covert-514ืžื”ืจืฉืช. ืœื›ืŸ, ื™ืฉ ืฆื•ืจืš ืœื”ืฉืชืžืฉ ื‘ืขืจื•ืฆื™ื ืกืžื•ื™ื™ื )

ื‘ืคืจื•ื˜ื•ืงื•ืœื™ ืฉื‘ื” ื ื™ืชืŸ ืœื”ืขื‘ื™ืจ ืžื™ื“ืข ื‘ืฆื•ืจื” ืœื ื‘ื•ืœื˜ืช ืžืจืฉืช ื”ืืจื’ื•ืŸ. ืœืจื•ื‘, ืขื•ืฉื™ื ื–ืืช ืขืœ ื™ื“ื™ ืฉื™ืžื•ืฉ

(. ืขืจื•ืฆื™ื ืกืžื•ื™ื™ื ื ื•ื˜ื™ื T1572 MITRETunnelling: Protocolืชืงืฉื•ืจืช ื‘ืฆื•ืจื” ืœื ืฉื’ืจืชื™ืช ืืš ืžื•ืชืจืช )

ืžืกื•ืจืชื™ื•ืช ื‘ื’ืœืœ ื”ืฉื™ืžื•ืฉ ื”ืœื ืฆืคื•ื™ ื‘ื”ื. Access Controlืœืขืงื•ืฃ ืžืขืจื›ื•ืช

ืขืœ ื™ื“ื™ ืฉื™ืžื•ืฉ ืœื ืฉื’ืจืชื™ )ืืš ืžื•ืจืฉื”( -ืฉืœ ืฉื™ืžื•ืฉ ื‘ืขืจื•ืฅ ืกื•ื“ื™ ื”ื“ื•ื’ืžื” ืœืžืขืœื” ื”ื™ื ื’ืจืกื” ื‘ืกื™ืกื™ืช ืžืื•ื“

ื‘ืฉืคื” ื”ืขื‘ืจื™ืช, ื”ืืกื™ืจื™ื ื™ื›ืœื• ืœืชืงืฉืจ ื‘ื™ื ื™ื”ื )ื•ืืฃ ืœืขื‘ื•ืจ ืืช ืžืขืจื›ืช ื”ื”ื’ื ื” ืฉืœ ื”ืกื•ื”ืจ(.

ืขืจื•ืฆื™ ื”ืชืงืฉื•ืจืช ื”ืกืžื•ื™ื™ื ืžืชื—ืœืงื™ื ื‘ืื•ืคืŸ ื’ืก ืœืฉื ื™ ืกื•ื’ื™ื ืžืจื›ื–ื™ื™ื:

( 385ืขืจื•ืฆื™ื ืกืžื•ื™ื™ื ืžื‘ื•ืกืกื™ ื–ืžืŸ-CWE :Channel Timing Covert) - ืขืจื•ืฅ ืชืงืฉื•ืจืช ืฉืžื‘ื•ืกืก ืขืœ

' ืืฆืœ ื”ืชื•ืงืฃ 1. ืœื“ื•ื’ืžื”, ืฉืœื™ื—ืชื• ืฉืœ ืื•ืชื• ื”ืžื™ื“ืข ืคืขื ื‘ื“ืงื” ื‘ืฉื‘ื™ืœ ืœืกืžืŸ 'ืชื–ืžื•ืŸ ืฉืœื™ื—ืช ื”ืžื™ื“ืข

'.3ื•ืคืขืžื™ื™ื ื‘ื“ืงื” ื‘ืฉื‘ื™ืœ ืœืกืžืŸ '

( 515ืขืจื•ืฆื™ื ืกืžื•ื™ื™ื ืžื‘ื•ืกืกื™ ืื—ืกื•ืŸ-CWE :Channel Storage Covert) - ืขืจื•ืฅ ืชืงืฉื•ืจืช ืฉืžื‘ื•ืกืก ืขืœ

.HTTP Header. ืœื“ื•ื’ืžื”, ืฉืœื™ื—ืช ืžื™ื“ืข ืืฉืจ ืžื•ืกืชืจ ื‘ืชื•ืš ืฉื™ื ื•ื™ ืชื•ื›ืŸ ื”ืžื™ื“ืข ื”ื ืฉืœื—

The Perfect Balanceื”ืื™ื–ื•ืŸ ื‘ื™ืŸ ืกื•ื“ื™ื•ืช ืœืžื”ื™ืจื•ืช :

ืฉื”ื ืœื ื™ืขื™ืœื™ื ื‘ืขืœื™ืœ. ื›ืžื•ืช ื”ืžื™ื“ืข ืฉืœืจื•ื‘ ื“ื‘ืจ ื ื•ืกืฃ ืฉื—ืฉื•ื‘ ืœืฆื™ื™ืŸ ื‘ื ื•ื’ืข ืœืขืจื•ืฆื™ ืชืงืฉื•ืจืช ืกืžื•ื™ื™ื ื–ื”

( ืฉืœ ืžื™ื“ืข ื‘ืขืจื•ืฅ ืกืžื•ื™ ื”ื•ื ืžืฉืžืขื•ืชื™ืช ื’ื“ื•ืœ ื™ื•ืชืจ ื‘ื”ืฉื•ื•ืื” ืœืฉื™ืžื•ืฉ 3Bื ืฉืœื— ื‘ืฉื‘ื™ืœ ืœื”ืขื‘ื™ืจ ื‘ื™ืช ื‘ื•ื“ื“ )

ื‘ืคืจื•ื˜ื•ืงื•ืœื™ ืชืงืฉื•ืจืช ื‘ืื•ืคืŸ ืฉื‘ื• ืชื•ื›ื ื ื• ืœื”ื™ื•ืช ื‘ืฉื™ืžื•ืฉ. ืžื”ื™ืจื•ืช ื”ืขื‘ืจืช ืžื™ื“ืข ื‘ืืžืฆืขื•ืช ื–ืœื™ื’ืช ืžื™ื“ืข ื”ื•ื

ื ืžื•ืš ื‘ื™ื•ืชืจ, ืขื“ ืœื‘ื™ื˜ื™ื ื‘ื•ื“ื“ื™ื ื‘ื™ื•ื.

ืืžื ื ืœื ื™ืขื™ืœ ื‘ืฉื‘ื™ืœ ืงื‘ืฆื™ื ื’ื“ื•ืœื™ื ืžืื•ื“ )ืืœื ืื ื›ืŸ ืืชื ืœื ืžืžื”ืจื™ื ืœืฉื•ื ืžืงื•ื(, ืื‘ืœ ื”ืžื”ื™ืจื•ืช ื–ื”

ื”ื ืžื•ื›ื” ืœื ืคื•ื’ืขืช ื‘ื™ื›ื•ืœืช ืฉืœ ื”ืžื™ื“ืข ื”ืžื•ื“ืœืฃ ืœื’ืจื•ื ืœื ื–ืง ืœืืจื’ื•ืŸ. ืžื‘ื™ืŸ ืกื•ื’ื™ ื”ืžื™ื“ืข ื”ืจื’ื™ืฉ ืฉื ื™ืชืŸ ืœื”ืขื‘ื™ืจ

ื‘ืงืœื•ืช:

ื‘ื™ื˜( 252ืžืคืชื—ื•ืช ืงืจื™ืคื˜ื•ื’ืจืคื™ื )ื’ื•ื“ืœ ืžืžื•ืฆืข ืฉืœ

ืฉืœ ื‘ื™ื˜ ื‘ื•ื“ื“(ืชืฉื•ื‘ื•ืช ืœืฉืืœื•ืช ื›ืŸ/ืœื )ื’ื•ื“ืœ

Page 8: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

8 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ืžืกืคืจื™ ื–ื”ื•ืช, ืžืกืคืจื™ ื˜ืœืคื•ืŸ, ืชืืจื™ื›ื™ื, ืงื•ื“PIN...

...ืงื‘ืฆื™ื ืงื˜ื ื™ื ืื—ืจื™ื

ื›ื›ืœ ืฉื”ืฉื™ื˜ื” ืœื”ื“ืœืคืช ื”ืžื™ื“ืข ืชื”ื™ื” ื™ื•ืชืจ ืžื”ื™ืจื”, ื•ื™ื•ืชืจ ืžื™ื“ืข ื™ืขื‘ื•ืจ ื‘ื™ื—ื™ื“ืช ื–ืžืŸ, -ื›ืืŸ ื ื›ื ืก ืงื˜ืข ื‘ืขื™ื™ืชื™

ื‘ื™ืŸ ื”ืจื‘ื” ื›ืš ื’ื“ืœ ื”ืกื™ื›ื•ื™ ืฉื™ื’ืœื• ืืช ื”ืขืจื•ืฅ ื”ื—ืกื•ื™. ื”ืกื™ื‘ื” ืœื›ืš ื”ื™ื ื›ื™ ืžืขืจื›ื•ืช ื”ื”ื’ื ื” ื”ืืจื’ื•ื ื™ื•ืช ื‘ื•ื“ืงื•ืช,

ืงืจื™ื˜ืจื™ื•ื ื™ื, ื–ื™ื ื•ืง ื‘ื ืคื— ื”ืžื™ื“ืข ืฉื”ื•ืขื‘ืจ ื‘ื™ื—ื™ื“ืช ื–ืžืŸ. ืœื“ื•ื’ืžื”, ืžื—ืฉื‘ ืžืฉืจื“ื™ ื‘ืืจื’ื•ืŸ ืœืจื•ื‘ ืžื•ืจื™ื“ ื•ืžืขืœื”

ืžื”ืื™ื ื˜ืจื ื˜ ื‘ื™ื•ื, ื•ื›ืš ื”ื•ื ืขื•ืฉื” ื‘ื“ืจืš ื›ืœืœ. ืฉื™ื ื•ื™ ื”ืชื ื”ื’ื•ืชื™ ื‘ืฆืจื™ื›ืช ื”ืื™ื ื˜ืจื ื˜ )ื›ืžื• ืฉื™ืžื•ืฉ 31MB-ื›

ื ื•ื ื™ ื”ื’ื ื” ื•ืœื”ืจืชื™ืข ื‘ืฆืจื™ื›ืช ื”ืื™ื ื˜ืจื ื˜( ืขืœื•ืœ ืœื”ืคืขื™ืœ ืžื ื’ x100ื–ื™ื ื•ืง ืฉืœ -ื‘ื™ื•ื 3GBืžืืกื™ื‘ื™ ืฉืœ

ืื“ืžื™ื ื™ืกื˜ืจื˜ื•ืจื™ื ืฉืœ ื”ืžืขืจื›ืช.

Ping = ?ืฉื™ื˜ื” ืœื–ืœื™ื’ืช ืžื™ื“ืข

ืขืœ ืžื ืช ืœื”ื“ืœื™ืฃ ืžื™ื“ืข ืžืžื—ืฉื‘ ืฉืœ ICMPื“ื•ื’ืžื” ืฉืชื‘ื”ื™ืจ ื”ื™ื˜ื‘ ืืช ื”ืื™ื–ื•ืŸ ื”ืžื“ื•ื‘ืจ ื”ื™ื ืฉื™ืžื•ืฉ ื‘ื”ื•ื“ืขื•ืช

ืœื›ืœ -ื”ื•ื ืคืจื•ื˜ื•ืงื•ืœ ืฉืžืฉืžืฉ ืœืžื˜ืจืช ืื‘ื—ื•ืŸ ื‘ืขื™ื•ืช ื‘ืจืฉืช, ื•ืขืœ ื›ืŸ ICMPืืจื’ื•ืŸ ืืœ ืžื—ืฉื‘ ืฉืœ ื”ืชื•ืงืฃ.

.ICMPื™ืฉ ื’ื ืืช ื”ื™ื›ื•ืœืช ืœืฉืœื•ื—, ืœืงื‘ืœ ื•ืœืขื‘ื“ ื”ื•ื“ืขื•ืช IPื•ื‘ืช ืžื›ืฉื™ืจ ืฉื™ืฉ ืœื• ื›ืช

)ืฉืืžื•ืจ pingื‘ืชื•ืจ ืขืจื•ืฅ ืกืžื•ื™. ืื•ืคืฆื™ื” ืื—ืช ื”ื™ื ืœื”ืฉืชืžืฉ ื‘ื›ืœื™ ICMP-ื ื ื™ื— ืฉื”ื™ื™ืชื™ ืจื•ืฆื” ืœื”ืฉืชืžืฉ ื‘

ืœื”ื™ื•ืช ืžื•ืชืงืŸ ื‘ื›ืœ ืžื—ืฉื‘ ืฉืžื—ื•ื‘ืจ ืœืื™ื ื˜ืจื ื˜(.

Page 9: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

9 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ื ืช ืœืงื‘ื•ืข " ืขืœ ืžn-"-)ื ืฉืชืžืฉ ื‘ ICMPื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืคืงื•ื“ื” ื”ื‘ืื” ื‘ืฉื‘ื™ืœ ืœืฉืœื•ื— ื—ื‘ื™ืœื” ื‘ื•ื“ื“ืช ืฉืœ

)ื™ืฉ ื”ื‘ื“ืœื™ื ืกืžื ื˜ื™ื™ื ื‘ื™ืŸ ื”ืคืงื•ื“ื” ื‘ืœื™ื ื•ืงืก ื•ื ื’ื–ืจื•ืชื™ื” ืœื‘ื™ืŸ X.X.X.Xืืช ื›ืžื•ืช ื”ื—ื‘ื™ืœื•ืช ืฉื™ื™ืฉืœื—ื•( ืœื›ืชื•ื‘ืช

ื”ืคืงื•ื“ื” ื‘ื•ื•ื™ื ื“ื•ืก, ื ืชื™ื™ื—ืก ืœืกืžื ื˜ื™ืงื” ืฉืœ ื•ื•ื™ื ื“ื•ืก(:

ื”ื™ื“ื“! ืขื›ืฉื™ื• ืฉื™ืฉ ื‘ื™ื›ื•ืœืชื ื• ืœืฉืœื•ื— ืคืงื•ื“ื” ื‘ื•ื“ื“ืช ืœืžื—ืฉื‘ ื—ื™ืฆื•ื ื™, ืืคืฉืจ ืœืชื–ืžืŸ ืืช ื–ื” )ื•ื–ืืช ืชื”ื™ื”

ืจื•ืฅ ืกืžื•ื™ ืžื‘ื•ืกืก ื–ืžืŸ(: ื“ื•ื’ืžื” ื ื”ื“ืจืช ืœืฉื™ืžื•ืฉ ื‘ืข

ืžืกืžืœ ื‘ื˜ื•ื•ื— ื–ืžืŸ ืžืกื•ื™ื ืืฆืœ ื”ืชื•ืงืฃ, ื•ืฉืœื™ื—ืช ื—ื‘ื™ืœื” ืื—ืช 3ืžืกืžืœ ื–ืžืŸ ืžืกื•ื™ืื‘ื˜ื•ื•ื— ืฉืœื™ื—ืช ืฉืชื™ ื—ื‘ื™ืœื•ืช

ืฉืœื™ื—ืช ื‘ื™ืช ื‘ื•ื“ื“ื–ื•, ืฉื ื™ื•ืช. ื‘ืฉื™ื˜ื” ื” 5ื‘ื™ืŸ ื›ืœ ืจืฆืฃ ื‘ืงืฉื•ืช ื™ืฉ ื”ืžืชื ื” ืฉืœ ื‘ื“ื•ื’ืžื” ืฉืœื ื•, ืืฆืœ ื”ืชื•ืงืฃ. 1

. (B/s 1.025: ื™ืจื•ืช ื”ืขื‘ืจืช ืžื™ื“ืข ืกืžื•ื™ืžื”ืฉื ื™ื•ืช ) 11ื•ืชื™ืงื— ICMPื—ื‘ื™ืœื•ืช 32ืชื“ืจื•ืฉ ืขื“ ืกื™ื‘ื™ื•ืช( 9)

" ืืขืฉื” ืืช ื”ืคืขื•ืœื•ืช ื”ื‘ืื•ืช:313ืœื“ื•ื’ืžื”, ืื ืืจืฆื” ืœืฉืœื•ื— ืืช ื”ืจืฆืฃ ื”ื‘ื™ื ืืจื™ "

ืฉื ื™ื•ืช ืœื—ืฆื™ ืฉื ื™ื™ื” )ื•ื ื’ื“ื™ืœ ืืช ืžื”ื™ืจื•ืช 5-ื ื™ืชืŸ ืœื”ื•ืจื™ื“ ืืช ื–ืžืŸ ื”ื”ืžืชื ื” ืž -ืžืจื’ื™ืฉ ืื™ื˜ื™? ืื™ืŸ ื‘ืขื™ื”

ื”ื—ื‘ื™ืœื•ืช ื ืจืื•ืช ืœื’ื™ื˜ื™ืžื™ื•ืช ืฉื ื™ื•ืช, ื•ื’ื ืื 1-ื—ื‘ื™ืœื•ืช ื‘ 32(. ืืžื” ืžื”, ืขื›ืฉื™ื• ื ืขื‘ื™ืจ ืขื“ 31ื”ื”ืขื‘ืจื” ืคื™

. ื–ื” ืืžื•ืจ ืœื”ื‘ื”ื™ืจ ืืช ื”ืฆื•ืจืš ื‘ืื™ื–ื•ืŸ ื‘ื™ืŸ ื”ืงืฆื‘ ื”ื’ื‘ื•ื” ืฉื‘ื• ื”ืŸ ื ื•ืฆืจื•ืช ื•ื ืฉืœื—ื•ืช ืžืขื•ืจืจ ื—ืฉื“ืœื—ืœื•ื˜ื™ืŸ,

ื”ืขื‘ืจืช ื ืชื•ื ื™ื ืžื”ื™ืจื” ื™ื•ืชืจ ืขืœื•ืœื” ืœื—ืฉื•ืฃ ืืช ื”ืขืจื•ืฅ ื”ืกืžื•ื™, ืื‘ืœ -ืžื”ื™ืจื•ืช ื”ืขื‘ืจืช ื”ื ืชื•ื ื™ื ืœื‘ื™ืŸ ืกื•ื“ื™ื•ืช

ืื•ื“.ืขืจื•ืฅ ืกืžื•ื™ ืืžื™ืชื™ ื™ื”ื™ื” ื‘ืขืœ ืžื”ื™ืจื•ืช ื”ืขื‘ืจืช ื ืชื•ื ื™ื ื ืžื•ื›ื” ืž

ื’ื ื‘ืฉื‘ื™ืœ ืขืจื•ืฆื™ื ืกืžื•ื™ื™ื ืžื‘ื•ืกืกื™ ืื—ืกื•ืŸ )ื‘ื ื™ื’ื•ื“ ืœืฉื™ื˜ื” ping-ืื ื‘ื“ื•ื’ืžืื•ืช ืขืกืงื™ื ืŸ, ืืคืฉืจ ืœื”ืฉืชืžืฉ ื‘

ืขื“ ืขื›ืฉื™ื• ืฉื”ื™ื™ืชื” ืžื‘ื•ืกืกืช ืขืœ ื–ืžืŸ(.

Page 10: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

11 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ืžื”ืชื‘ื•ื ื ื•ืช ืขืœ ื”ืคืจืžื˜ืจื™ื ืฉืืคืฉืจ ืœื”ื–ื™ืŸ, ื ื™ืชืŸ ืœืจืื•ืช ื›ืžื” ืฉื“ื•ืช ื ื•ืกืคื™ื ืฉืืคืฉืจ ืœืงื•ื“ื“ ืืœื™ื”ื ืžื™ื“ืข:

ืžื’ื“ื™ืจ ืืช ืื•ืจืš ื”ืžื™ื“ืข ืฉื™ืชื•ื•ืกืฃ ืœื—ื‘ื™ืœื” ื›ื“ื™ ืœืชืช ืœื” ื”ืคืจืžื˜ืจ ื”ื–ื” - (l size-ืฉื™ื ื•ื™ ื’ื•ื“ืœ ืžื™ื“ืข ) .1

ื‘ืชื™ื(. ืขืœ ื™ื“ื™ ืฉื™ื ื•ื™ ื”ืžืกืคืจ ื”ื–ื” ื ื™ืชืŸ "ืœืื•ืชืช" ืœืชื•ืงืฃ ื˜ื•ื•ื— ืขืจื›ื™ื 12 -"ืžืฉืงืœ" )ื’ื•ื“ืœ ื‘ืจื™ืจืช ืžื—ื“ืœ

ืจื—ื‘ ืžืื•ื“ ืฉืœ ืžื™ื“ืข. ื›ืžื•ื‘ืŸ ืฉื”ืคืจืžื˜ืจ ื”ื–ื” ืฆืจื™ืš ืœื”ืฆื“ื™ืง ืืฉื›ืจื” ืžื™ื“ืข ืฉืืžื•ืจ ืœื”ื™ื•ืช ืงื™ื™ื ื‘ื—ื‘ื™ืœื”,

pingื”ื—ื‘ื™ืœื” ืฉื ื•ืฆืจื” ืขืœ ื™ื“ื™ -ืจ "ืžื™ื“ืข ืฉืจื™ืจื•ืชื™" )ื‘ืชืžื•ื ื” ื‘ืชื• abc-ืžืฆื™ื‘ ืืช ืื•ืชื™ื•ืช ื” pingื•ืขืœ ื›ืš,

ื‘ืชื™ื ื•ื”ืžื™ื“ืข ื”ืฉืจื™ืจื•ืชื™ ืžืกื•ืžืŸ ื‘ื›ื—ื•ืœ(: 12ืฉืœ bufferื‘ื’ื•ื“ืœ

ื”ื—ื™ืกืจื•ืŸ ื”ืžืจื›ื–ื™ ืคื” ื”ื•ื ืฉื”ืขืจื•ืฅ ื”ืกืžื•ื™ ืขืœื•ืœ ืœื”ืชื’ืœื•ืช ื•ืœื”ื™ื”ืจืก ื›ืืฉืจ ื ืฉืชืžืฉ ื‘ืขืจื›ื™ื ื’ื“ื•ืœื™ื ืžื“ื™

( ืื• ืฉื ืฉืœื— ื™ื•ืชืจ ืžื“ื™ ื‘ืงืฉื•ืช ื‘ื˜ื•ื•ื— ื–ืžืŸ ืงืฆืจ ืžื“ื™ death of Ping-)ื”ืžืขืจื›ืช ืชื—ืฉื•ื‘ ืฉืžื“ื•ื‘ืจ ื‘

(.attack Smurf-ืื• ื‘ Flood Ping-)ื”ืžืขืจื›ืช ืชื—ืฉื•ื‘ ืฉืžื“ื•ื‘ืจ ื‘

Page 11: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

11 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

(. 1-255ืกื™ื‘ื™ื•ืช ืฉืื ื—ื ื• ื™ื›ื•ืœื™ื ืœื”ื’ื“ื™ืจ )ื‘ื™ืŸ 9ื”ื•ื ืžืกืคืจ ื‘ื’ื•ื“ืœ TTL - (i ttl-ื—ื™ื™ื )-ื‘ืฉื“ื” ื–ืžืŸ ืฉื™ืžื•ืฉ .2

ืจืืฉื•ื ื™ )ืฉื–ื” ืžื” ืฉืื ื—ื ื• ืžื’ื“ื™ืจื™ื(. ื‘ื›ืœ TTLื”ื—ื•ืง ืขื ื”ืžืกืคืจ ื”ื–ื” ืคืฉื•ื˜: ื—ื‘ื™ืœื” ื ื•ืฆืจืช ืขื ืขืจืš

. 3-ืชื—ื ื” ื‘ืจืฉืช, ื‘ื›ืœ ืžื›ืฉื™ืจ ืื• ื ืชื‘ ืฉื“ืจื›ื• ืขื•ื‘ืจืช ื”ื—ื‘ื™ืœื” ืขื“ ืœื”ื’ืขืชื” ืœื™ืขื“ื”, ื”ืžืกืคืจ ื”ื–ื” ื™ื•ืจื“ ื‘

ื ื•ืขื“ ืœืžื ื•ืช ืืช ื›ืžื•ืช ื”ืชื—ื ื•ืช ื•ืœืขืฆื•ืจ TTL, ื”ื—ื‘ื™ืœื” ื—ื“ืœื” ืžืœื”ืชืงื™ื™ื. 1-ืืฉืจ ื”ืžืกืคืจ ื”ื–ื” ืžื’ื™ืข ืœื›

ืœืคื ื™ ืฉื”ื•ื 1-ื—ื‘ื™ืœื•ืช ืฉืขื•ืฉื•ืช ืœื•ืœืื•ืช ื‘ืชื•ืš ืจืฉืชื•ืช ืžื—ืฉื‘ื™ื. ื‘ื”ืงืฉืจ ืฉืœื ื•, ืื ื”ืžืกืคืจ ื”ื–ื” ื™ื’ื™ืข ืœ

ื”ื•ื ืœื ื™ื’ื™ืข ืœืชื•ืงืฃ. -ื™ื’ื™ืข ืœืชื•ืงืฃ

)ืขื“ ื›ืžื” 21-ื ืžื•ืš ืž TTLื—ื‘ื™ืœื” ืขื ื™ื’ืจื•ื ืœืชื•ืงืฃ ืœืงื‘ืœ ืืช ื” 21ืฉืœ TTLืขื ืขืจืš pingื‘ื™ืฆื•ืข ืคืงื•ื“ืช

ื ืžื•ืš? ืชืœื•ื™ ื‘ืžืกืคืจ ื”ืชื—ื ื•ืช ื‘ื“ืจืš(. ืœืžืจื•ืช ื”ืขื™ื•ื•ืช ืฉื ืขืฉื” ืœืฉื“ื” ื‘ื–ืžืŸ ื”ืฉืœื™ื—ื” ืฉืœื•, ื ื™ืชืŸ ืœื”ื’ื“ื™ืจ

TTLืจืืฉื•ื ื™ื™ื ืฉื™ื”ื™ื• ืฉื•ื ื™ื ื–ื” ืžื–ื” ื‘ืื•ืคืŸ ืžื•ื‘ื”ืง ื•ืœื”ืคืจื™ื“ ื‘ื™ื ื™ื”ื. ืœื“ื•ื’' ืขืจืš TTLืœื• ืฉื ื™ ืขืจื›ื™

ื•ืช ื‘ื“ืจืš(. ื”ืชื•ืงืฃ ืžื‘ื™ืŸ ืฉื–ื” ื™ื•ืชืจ ืชื—ื  31)ื ื’ื™ื“ ืฉื™ืฉ 391ื™ืชืงื‘ืœ ืืฆืœ ื”ืชื•ืงืฃ ื‘ืชื•ืจ 211ื”ืชื—ืœืชื™ ืฉืœ

, 91-ืชืชืงื‘ืœ ืืฆืœ ื”ืชื•ืงืฃ ื› 311ื”ืชื—ืœืชื™ ืฉืœ TTL'. ื—ื‘ื™ืœื” ืื—ืจืช, ื‘ืขืœืช 3ื•ืœื›ืŸ ื”ื•ื ืžืงื‘ืœ ' 311-ืž

'. ื–ืืช ืฉื™ื˜ื” ื“ื•ืžื” ืœืฉื™ื˜ื” ื”ืจืืฉื•ื ื” ืฉืœื ื•, ืืš 1'-, ื”ืชื•ืงืฃ ื™ื‘ื™ืŸ ืฉืžื“ื•ื‘ืจ ื‘311-ื•ืžืื—ืจ ื•ื”ืขืจืš ื ืžื•ืš ืž

ืฆื•ืจืš ื‘ื”ืžืชื ื”(. ืฉืื™ื ื” ืžื‘ื•ืกืกืช ืขืœ ื–ืžืŸ, ืื– ื™ื›ื•ืœื” ืœืืคืฉืจ ืฉืœื™ื—ืช ื—ื‘ื™ืœื•ืช ื‘ืจืฆืฃ )ืื™ืŸ

ืชื—ื ื•ืช ื‘ื“ืจืš ืœืชื•ืงืฃ 311-ืžืงืจื” ืงื™ืฆื•ืŸ ืคื•ื˜ื ืฆื™ืืœื™ ืฉื™ื›ื•ืœ ืœื”ืจื•ืก ืืช ื”ืฉื™ื˜ื” ื”ื–ื• ื–ื” ืื ื™ืฉื ืŸ ื™ื•ืชืจ ืž

ื”ืชื—ืœืชื™ TTLื•ื—ื‘ื™ืœื•ืช ืขื 311-ืชื’ื™ืข ืœืชื•ืงืฃ ืขื ืขืจืš ื ืžื•ืš ืž TTL 211)ื›ืœื•ืžืจ ืฉื—ื‘ื™ืœื” ืฉืžืชื—ื™ืœื” ืขื

TTL-ืืช ืขืจืš ื”ืœื ื™ื’ื™ืขื• ืœืชื•ืงืฃ ื›ืœืœ(. ื“ื‘ืจ ืืคืฉืจื™ ื ื•ืกืฃ ื”ื•ื ืฉื™ืฉื ื” ืชื—ื ื” ื‘ื“ืจืš ืฉื“ื•ืจืกืช 311ืฉืœ

ืงื‘ื•ืข. ืžืงืจื™ื ืืœื• ืคื•ื’ืขื™ื ื‘ืขืจื•ืฅ ื”ืกืžื•ื™ ื”ืžืชื•ืืจ TTLืขื‘ื•ืจ ื›ืœ ื”ื—ื‘ื™ืœื•ืช ื”ืขื•ื‘ืจื•ืช ื“ืจื›ื” ื•ืžืฆื™ื‘ื” ืขืจืš

ื›ืืŸ ื•ื—ื•ืกืžื™ื ืื•ืชื• ืœื—ืœื•ื˜ื™ืŸ.

Page 12: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

12 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

"ืคืชื•ื—ื•ืช" Wi-Fiื•ืขืงื™ืคื” ืฉืœ ืจืฉืชื•ืช ICMP Tunnelingื‘ื•ื ื•ืก:

"( ื”ื•ื ืคืจื•ื˜ื•ืงื•ืœ ื‘ืกื™ืกื™ Protocol Message Control Internet: 792 RFC"-)ืžื•ื’ื“ืจ ื‘ v4ICMPืคืจื•ื˜ื•ืงื•ืœ

ืœื ื ื•ืขื“ ืœื“ื™ื•ื•ื— ืฉื’ื™ืื•ืช ืฉืžืฉืชืžืฉื™ื ื‘ื• ืจื›ื™ื‘ื™ ืจืฉืช )ื ืชื‘ื™ื, ืฉืจืชื™ื ื•ื›ื•'(. ื”ืคืจื•ื˜ื•ืงื•ืœ ื”ื–ื”, ื‘ื”ื’ื“ืจืชื•,

ื‘ื™ืŸ ืฉื ื™ ืžื—ืฉื‘ื™ื, ืืœื ืจืง ืœื‘ื“ื•ืง ืืช ื˜ื™ื‘ ื”ืชืงืฉื•ืจืช ื‘ื™ื ื™ื”ื. ืื•ืœื, ื‘ื“ื•ื’ืžื ืœืžืขืœื” ืจืื™ื ื• ืœื”ืขื‘ื™ืจ ืžื™ื“ืข

( ื‘ืชื•ืš ื”ื—ื‘ื™ืœื”, ื•ืœื›ืŸ ื™ืฉ ืœื” ืืช ื”ื™ื›ื•ืœืช ืœืกื—ื•ื‘ ืžื™ื“ืข. abcืฆื™ื‘ ืžื™ื“ืข ืฉืจื™ืจื•ืชื™ )ืื•ืชื™ื•ืช ืž pingืฉื”ื›ืœื™

ื‘ืžืคืจื˜ ืฉืœ ื”ืคืจื•ื˜ื•ืงื•ืœ ื ื•ื›ืœ ืœืžืฆื•ื ืืช ื”ืฉื“ื” ื”ืื—ืจืื™:

ื” )ืฉื›ื‘ื” ( ืฉืคื•ืขืœื•ืช ื‘ืื•ืชื” ืจืžProtocol Internet: 791 RFC) IPื”ืŸ ืชื•ืกืคื•ืช ืœืคืจื•ื˜ื•ืงื•ืœ ICMPื”ื•ื“ืขื•ืช

( IP Header -)ื‘ืชืžื•ื ื” IPืžืฉืชืžืฉื•ืช ื‘ืื•ืชืŸ ืฉื“ื•ืช ื›ืžื• ืคืจื•ื˜ื•ืงื•ืœ ICMP(, ื•ืœื›ืŸ ื”ื•ื“ืขื•ืช OSIืฉืœื™ืฉื™ืช ื‘ืžื•ื“ืœ

(. ICMP Header -ื•ืžื•ืกื™ืคื•ืช ื›ืžื” ืžืฉืœื”ืŸ )ื‘ืชืžื•ื ื”

ืกื™ื‘ื™ื•ืช ืฉืžืชืืจ ืืช ื’ื•ื“ืœ 32ืฉื ื™ืชืŸ ืœื”ื’ื“ื™ืจ ื‘ื’ื•ื“ืœ Total Lengthืžื—ื–ื™ืง ืฉื“ื” IPืœืคื™ ื”ื’ื“ืจื”, ืคืจื•ื˜ื•ืงื•ืœ

25,515(. ื›ืœื•ืžืจ, ื’ื•ื“ืœื” ืฉืœ ื—ื‘ื™ืœื” ืื—ืช ืžื•ื’ื‘ืœืช ืขื“ ืœื’ื•ื“ืœ ืฉืœ 25,515ืขื“ ื”ื—ื‘ื™ืœื” ื”ื›ื•ืœืœืช )ื›ืœ ืžืกืคืจ

ื•ื‘ื• ICMPื‘ืชื•ืš ื”ื•ื“ืขืช Data, ื–ื” ื—ื•ืงื™ ืœื›ืœื•ืœ ืฉื“ื” RFC972(. ื‘ื ื•ืกืฃ ืœื›ืš, ืœืคื™ Headers-ื‘ืชื™ื )ื›ื•ืœืœ ื”

ืžืกื•ืžืŸ ื‘ืื“ื•ื(. -ืœืฉื™ื ื›ืœ ืžื™ื“ืข ืฉืจื™ืจื•ืชื™, ืฉืœื ืžื•ื’ื‘ืœ ืžื‘ื—ื™ื ืช ืชื•ื›ืŸ )ื‘ืชืžื•ื ื”

. IPืชื•ื“ื•ืช ืœืคืจื•ื˜ื•ืงื•ืœ Total Lengthืจื›ื•, ื•ื”ื™ื ื ื•ื‘ืขืช ืžื”ืฉื“ื” ื”ื”ื’ื‘ืœื” ื”ื™ื—ื™ื“ื” ืฉืœ ื”ืฉื“ื” ื”ื "ืœ ื”ื™ื ื‘ืื•

( ืฉืœ ืžื™ื“ืข ื ื˜ื• ื‘ืชื•ืš ื›ืœ 65.5KB~ื‘ืชื™ื ) 25,511ืžืฉืชืžืฉ ื™ื›ื•ืœ ืœื”ืขื‘ื™ืจ ืขื“ -ืžื›ืœ ื–ื” ื ื•ื‘ืข ืžืฉื”ื• ืžื“ื”ื™ื

, ืœืžืจื•ืช ืฉื”ื™ื ื‘ื›ืœืœ ืœื ื ื•ืขื“ื” ืœื”ืขื‘ืจืช ืžื™ื“ืข.ICMPื—ื‘ื™ืœืช

-ื‘ืคืจื•ื˜ื•ืงื•ืœ ืื—ืจ )ืžื” ืฉื ืงืจื "ืขื•ื˜ืคื™ื" ืžื™ื“ืข ืฉืœ ืคืจื•ื˜ื•ืงื•ืœ ืื—ื“-ืœืื•ืจืš ื”ืฉื ื™ื, ืงืžื• ืคืจื•ื™ืงื˜ื™ื ืฉื•ื ื™ื ืฉ

Tunneling Protocol ื‘ืื•ืคืŸ ื˜ื‘ืขื™, ืื—ื“ ื”ืคืจื•ื˜ื•ืงื•ืœื™ื ืฉื ืžืฆืื™ื ื‘ืฉื™ืžื•ืฉ ื ืคื•ืฅ ื‘ืชื”ืœื™ืš ื”ื–ื” ื”ื•ื .)ICMP

)ืฉื–ื” ื“ื™ ื”ื’ื™ื•ื ื™ ื ื•ื›ื— ื”ื™ื›ื•ืœืช ืฉืœื• ืœื”ืขื‘ื™ืจ ืžื™ื“ืข ืœืžืจื•ืช ืฉื”ื•ื ืื™ื ื• ื ื•ืขื“ ืœื›ืš(.

Tunneling ICMP ื”ื™ื ืกื•ื’ ืฉืœ ืชืงืฉื•ืจืช ืกืžื•ื™ื” ืฉื‘ื” ื—ื‘ื™ืœื•ืชTCP ื ืขื˜ืคื•ืช ื—ื‘ื™ืœื•ืชICMP ื•ื ืฉืœื—ื•ืช

ื“ื• ื›ื™ื•ื•ื ื™ืช TCP(, ื•ื›ืš ืžืชืืคืฉืจืช ืชืงืฉื•ืจืช Echo)ื‘ืงืฉื•ืช ping-ื›ื‘ืงืฉื•ืช ืฉื“ื•ืžื•ืช ืœื‘ืงืฉื•ืช ื”ื™ื•ืฆืื•ืช ืž

ICMPื” ื‘ื“ืจืš, ืžืงื‘ืœื™ื ืขืจื•ืฅ ืกืžื•ื™ ืฉืžืขื‘ื™ืจ ื—ื‘ื™ืœื•ืช . ืื ืžื•ืกื™ืคื™ื ื”ืฆืคื ICMPืžืœืื”, ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœ

ื›ื™ ื”ื™ื ICMPืฉื ืจืื•ืช )ื™ื—ืกื™ืช( ืœื’ื™ื˜ื™ืžื™ื•ืช. ื˜ื›ื ื™ืช, ืื™ืŸ ืกื™ื‘ื” ืœืชื•ื›ื ื•ืช ื”ื’ื ื” ืœื‘ื“ื•ืง ืืช ื”ืชื•ื›ืŸ ืฉืœ ื—ื‘ื™ืœืช

Page 13: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

13 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ืœื ืืžื•ืจื” ืœื”ื›ื™ืœ ืžื™ื“ืข ืฉื”ื•ื ื™ื•ืชืจ ืžืื•ืชื™ื•ืช ืฉืจื™ืจื•ืชื™ื•ืช )ืœืžืจื•ืช ืฉื›ื™ื•ื ื›ืœ ื”ืชื•ื›ื ื•ืช ื›ื‘ืจ ื”ืชืจื’ืœื• ืœื›ืš

ืขืจื•ื›ื•ืช ื‘ื”ืชืื(. ื•ื”ืŸ ICMPืฉืืคืฉืจ ืœื”ืขื‘ื™ืจ ืžื™ื“ืข ื‘ืืžืฆืขื•ืช

, ืžืคืขื ื— ืืช ื”ืžื™ื“ืข ICMPื—ื‘ื™ืœื•ืช ื”ืžื™ื“ืข ืฉื ืฉืœื—ื•ืช ืžื’ื™ืขื•ืช ืœืฉืจืช ื‘ื™ื ื™ื™ื, ืฉืคื•ืชื— ืืช ื”ืขื˜ื™ืคื” ืฉืœ

(. IP Masquerading-ื•ืฉื•ืœื— ืื•ืชื• ื›ืจื’ื™ืœ ื“ืจืš ื”ืื™ื ื˜ืจื ื˜ ืœืฉืจืช ืืœื™ื• ื”ืœืงื•ื— ืจื•ืฆื” ืœื”ืชื—ื‘ืจ )ืฉื™ืžื•ืฉ ื‘

ื•ื ืฉืœื—ืช ืืœ ื”ืœืงื•ื—. ICMPื”ืชืฉื•ื‘ื” ืฉืžืชืงื‘ืœืช ืžื”ืฉืจืช ืžื•ืฆืคื ืช ืžื—ื“ืฉ ื•ื ืขื˜ืคืช ื‘ืชื•ืจ ื—ื‘ื™ืœืช

, ืžื›ื™ืœื™ื ื‘ื•ื ื•ืก ืžืขื ื™ื™ืŸ ื‘ื™ื•ืชืจ. DhavaKapilืฉืœ icmptunnel, ื›ืžื• Tuneling ICMPืคืจื•ื™ืงื˜ื™ื ืฉืžืฆื™ืขื™ื

. Portal aptiveCื”ืคืจื•ื™ืงื˜ ื”ื–ืืช ืืžื ื ื™ื›ื•ืœ ืœืฉืžืฉ ืœื–ืœื™ื’ืช ืžื™ื“ืข, ืืš ื”ื•ื ื’ื ืžืฆื•ื™ืŸ ืœืขืงื™ืคื” ืฉืœ ืžืขืจื›ื•ืช

ื”ืจืฉืชื•ืช ืฉื ืจืื•ืช ืฉืื™ื ืŸ ืžื•ื’ื ื•ืช ื‘ืกื™ืกืžื” ืืš -ื”ืฆื™ื‘ื•ืจื™ื•ืช "ื”ืคืชื•ื—ื•ืช" ื”ืŸ ืœื ื–ืจื•ืช ืœื ื• Wi-Fi-ืจืฉืชื•ืช ื”

ืืค ืฉืžื‘ืงืฉ ืื™ืžื•ืช ืื• ื›ืกืฃ. -ื‘ืžืขืžื“ ื”ื—ื™ื‘ื•ืจ ืืœื™ื”ืŸ ืขื•ืœื” ื—ืœื•ืŸ ืคื•ืค

ืœ ืฉืจืช ืฉืžื•ื‘ื™ืœ ื 112)ืงื•ื“ HTTPืžืจื‘ื™ืช ืžืขืจื›ื•ืช ื‘ืงืจืช ื”ื’ื™ืฉื” ื”ืœืœื• ืžืฉืชืžืฉื•ืช ื‘ื”ืคื ื™ื” ื‘ืืžืฆืขื•ืช

)ื›ืœ ื“ื•ืžื™ื™ืŸ ืžื•ื‘ื™ืœ ืืœ ืฉืจืช ื”ืื™ืžื•ืช(. ืœืจื•ื‘, ื”ืžืขืจื›ื•ืช ื”ืœืœื• DNS( ืื• ื”ืคื ื™ื” ื‘ืืžืฆืขื•ืช 533ื”ืื™ืžื•ืช, ืื• ืงื•ื“

ICMP(. DNS)ื›ื™ ื“ืจื›ืŸ ืขื•ื‘ืจ UDP( ืื• ื—ื‘ื™ืœื•ืช HTTP)ื›ื™ ื“ืจื›ืŸ ืขื•ื‘ืจ TCPืžื—ืคืฉื•ืช ื‘ืื•ืคืŸ ืืงื˜ื™ื‘ื™ ื—ื‘ื™ืœื•ืช

ืฆื™ื•ื ืœื™ื•ืช ืฉืœ ื”ืจืฉืช )ืœื›ืŸ, ืœื ื ื•ืขื“ ืœื”ืขื‘ืจืช ืžื™ื“ืข ื‘ื“ืจืš ื›ืœืœ, ื•ื—ืกื™ืžื” ืฉืœ ื”ืคืจื•ื˜ื•ืงื•ืœ ื™ื›ื•ืœื” ืœืคื’ื•ืข ื‘ืคื•ื ืง

ืœื ืกื‘ื™ืจ ืฉื™ื‘ื˜ืœื• ืื•ืชื•(.

, ืื—ื“ ื™ื›ื•ืœ ื‘ืื•ืคืŸ ืชื™ืื•ืจื˜ื™ ืœืขืงื•ืฃ icmptunnel, ื›ืžื• Tunneling ICMPืขืœ ื™ื“ื™ ืฉื™ืžื•ืฉ ื‘ืชื•ื›ื ื•ืช ืฉืžืฆื™ืขื•ืช

Captive Portals ืคื™ "ืคืชื•ื—ื•ืช", ืœืœื ืื™ืžื•ืช )ื•ื‘ื—ื™ื ื!(.-ื•ืœื”ืชื—ื‘ืจ ืœืจืฉืชื•ืช ื•ื•ื™

Page 14: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

14 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ื•ืžื” ืขื•ืฉื™ื ืขื ื”ืžื™ื“ืข? ืขืœ ื“ื—ื™ืกื”, ื”ืฆืคื ื” ื•ืงื™ื“ื•ื“ ืžื™ื“ืข

ื›ืขืช ื ืขืกื•ืง ื‘ื—ืœืง ืฉื—ืฉื•ื‘ ืœื ืคื—ื•ืช ืžื‘ื—ื™ืจืช ื”ืขืจื•ืฅ ื”ืกืžื•ื™, ื•ื”ื•ื ื”ืชื”ืœื™ืš ืฉื ืฆื˜ืจืš ืœื”ืขื‘ื™ืจ ืืช ื”ืžื™ื“ืข

ืฉืœื ื• ืœืคื ื™ ืฉืœื™ื—ืชื•. ื›ืคื™ ืฉื ื™ืชืŸ ืœืจืื•ืช, ืขืจื•ืฆื™ื ืกืžื•ื™ื™ื ื‘ืื™ื ืขื ื“ืจื™ืฉื•ืช ืฉื•ื ื•ืช ื‘ื ื•ื’ืข ืœืžื™ื“ืข ืฉื ื™ืชืŸ ืœื”ืฆื™ื‘

ืช, ืœื ื™ื›ื•ืœ ืœืขื‘ื•ืจ ื‘ืžืจื‘ื™ืช ื”ืขืจื•ืฆื™ื ื”ืกืžื•ื™ื™ื ืœืœื ื”ืฆื’ืชื• ื‘ืฆื•ืจื” ืื—ืจืช, ืื• ื‘ื”ื. ื”ืžื™ื“ืข, ื‘ืฆื•ืจืชื• ื”ื’ื•ืœืžื™

ื—ืœืงื™ื. -ื—ืœื•ืงื” ืฉืœื• ืœืชืชื™

ื›ืฉืžื“ื•ื‘ืจ ืขืœ ื”ืžื™ื“ืข ื”ืžื•ืขื‘ืจ, ื™ืฉ ืœื ื• ืžืกืคืจ ืžื˜ืจื•ืช ืฉื ืจืฆื” ืœื”ืฉื™ื’:

ื™ื•ืชืจ ืฉื ืขื‘ื™ืจ ื•ื›ื›ืœ ืžืื—ืจ, (ื“ื—ื™ืกื”) ืงื˜ื ื” ืฉื™ื•ืชืจ ื›ืžื” ืชื”ื™ื”ื”ืžื™ื“ืข ืฉื ืฆื˜ืจืš ืœื”ืขื‘ื™ืจ ืฉื›ืžื•ืช ื ืจืฆื”

. ืื•ืชื• ื•ื™ืกื’ืจื• ืฉืœื ื• ื”ืกืžื•ื™ ื”ืขืจื•ืฅ ืืช ืฉื™ื–ื”ื• ื”ืกื™ื›ื•ื™ ื™ืขืœื”ืžื™ื“ืข ืœืื•ืจืš ื–ืžืŸ ื›ืš

ื•ืœื–ื”ื•ืช ืื•ืชื•ืœื ื™ื•ื›ืœื• ืœืคืขื ื— ื‘ื“ืจืš ื•ื”ื’ื ื”ื›ืš ืฉืžืขืจื›ื•ืช ื–ื™ื”ื•ื™ ื”ืžื•ืขื‘ืจ ื”ืžื™ื“ืข ืืช ืœื”ืฆืคื™ืŸ ื ืจืฆื”

)ื”ืฆืคื ื”(. ืจื’ื™ืฉ ื‘ืžื™ื“ืข ืฉืžื“ื•ื‘ืจ

ื›ืš ืฉืชืชืื™ื ืœืขืจื•ืฅ ื”ืกืžื•ื™ )ืงื™ื“ื•ื“ ืžื™ื“ืข(, ื”ืžื™ื“ืข ืืช ืžืฆื™ื’ื™ื ืื ื—ื ื• ื‘ื” ื”ื“ืจืš ืืช ืœืฉื ื•ืช ื ืจืฆื”

. ื—ื›ืžื” ื‘ืฆื•ืจื” ื–ืืช ื•ืœืขืฉื•ืช

ืื ื•ืฉื™". ืœืฉื ื›ืš ื ืฆื˜ืจืš ืœื”ืกืชื™ืจ ืžื™ื“ืข ื—ืกื•ื™ -ื• ืœื’ื™ื˜ื™ืžื™ ืฉื™ื•ืชืจ ื›ืžื” ื™ื™ืจืื” ืฉื ืขื‘ื™ืจ ืฉื”ืžื™ื“ืข ืจืฆื”ื "

ื‘ืžืืžืจ ื”ื–ื”(. ืœื–ื”, ืื‘ืœ ืœื ื ื™ื›ื ืก ืกื˜ื’ื ื•ื’ืจืคื™ื”ื‘ืชื•ืš ืžื™ื“ืข ืœื’ื™ื˜ื™ืžื™ )

ืฉื™ืžื•ืฉ ื‘ื“ื—ื™ืกื”

ื‘ืกืจื˜ื•ืŸ ืฉืœ ืื ืืชื ืœื ืžื›ื™ืจื™ื ืืช ื”ืขืงืจื•ื ื•ืช ื”ื‘ืกื™ืกื™ื™ื ืฉืœ ื“ื—ื™ืกื”, ืื ื™ ืžืžืœื™ืฅ ืฉืชืฆืคื•

Techquickie ืฉื ื•ืชืŸ ื”ืกื‘ืจ ื›ืœืœื™ ืขืœ ืฉื™ื˜ื•ืช ืœื“ื—ื™ืกืช ื ืชื•ื ื™ื ื•ืื™ืš ื”ืŸ ืขื•ื‘ื“ื•ืช. ืื ื”ืกื‘ืจ

ื”ื›ืชื‘ื” ืฉืœ ืฉื—ืฃ ืืœืงืกืœืกื™ ืžืขืžื™ืง ื™ื•ืชืจ ื”ื•ื ืžื” ืฉืืชื ืžื—ืคืฉื™ื, ืื ื™ ืžืžืœื™ืฅ ื‘ื—ื•ื ืขืœ

ื–ื™ื•, -ืฉื ื›ื ืกืช ืœืขื•ืžืง ื‘ื ื•ืฉืื™ื ื›ืžื• ืงื•ื“ ื”ืืคืžืŸ, ืืœื’ื•ืจื™ืชื ืœืžืคืœ 312( ืžื’ื™ืœื™ื•ืŸ cp77fk4rื•ืืคื™ืง ืงืกื˜ื™ืืœ )

. Web-ื•ืขืœ ื”ืฉื™ืžื•ืฉื™ื ืฉืœ ื“ื—ื™ืกื” ื‘ืขื•ืœื ื”

ื”ืงื˜ื ืช ื›ืžื•ืช ื”ืžื™ื“ืข ืฉืขื•ื‘ืจ ื‘ืชื•ื•ืš ื›ื“ื™ ืœื -ื“ื—ื™ืกื” ื”ื™ื ื“ื‘ืจ ื ื”ื“ืจ, ื›ื™ ื”ื™ื ืขื•ื ื” ืœื ื• ืขืœ ืฆื•ืจืš ื‘ืกื™ืกื™

ื—ืฉื•ืฃ ืืช ื”ืขืจื•ืฅ ื”ืกืžื•ื™. ื‘ืคืจื•ื™ืงื˜ื™ื ืงื•ื“ืžื™ื ืฉืขืฉื™ืชื™ ื”ื™ื™ืชื™ ื ื•ื˜ื” ืœื“ื—ื•ืก ื›ืœ ืคื™ืกืช ืžื™ื“ืข ื‘ืžื—ืฉื‘ื” ืฉื–ื” ืœ

ื™ืขืฉื” ืืช ื”ืžื™ื“ืข ืงืฆืจ ื™ื•ืชืจ, ื•ื™ื’ืจื•ื ืœื• ืœืขื‘ื•ืจ ืžื”ืจ ื™ื•ืชืจ ื“ืจืš ื”ืจืฉืช.

Page 15: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

15 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ืืš ืžื”ืจ ืžืื•ื“ ืœืžื“ืชื™ ืฉื™ืฉ ืžืงืจื™ื ืฉื‘ื”ื ืœื ื ืจืฆื” ืœื“ื—ื•ืก ืืช ื”ื ืชื•ื ื™ื ืฉืœื ื•:

ื•ืชืŸ". ื›ืœื•ืžืจ, -ื“ื—ื™ืกื” ื”ื™ื ืžืฉื—ืง ืฉืœ "ืงื— - (ืžืขื˜ ืžื“ื™ ืžื™ื“ืข ืื• ืžื™ื“ืข ืจื ื“ื•ืžืœื™ ืžื“ื™ )ืœืœื ื™ืชื™ืจื•ืช .1

ื“ื—ื™ืกื•ืช ืฉื•ื ื•ืช ื™ื›ื•ืœื•ืช ืœื”ืงื˜ื™ืŸ ืืช ื’ื•ื“ืœ ื”ืžื™ื“ืข ื”ื’ื•ืœืžื™ ืื‘ืœ ื”ืŸ ืฆืจื™ื›ื•ืช ืœื”ื•ืกื™ืฃ ืžื™ื“ืข ืžืฉืœื”ืŸ ื‘ืจืืฉ

(, ืงื•ื“ ืœืื™ืชื•ืจ ืฉื’ื™ืื•ืช ื•ื›ืžื• ื›ืŸ ื’ื ืžื™ื“ืข ืฉืงืจื™ื˜ื™ ืœืฆื•ืจืš ื”ืคืชื™ื—ื” ืฉืœ ื”ื“ื—ื™ืกื” File Headerื”ืงื•ื‘ืฅ )

ื•ืจื™ ืงืฆืจ ืžื“ื™, ื‘ื™ืฆื•ืข ื“ื—ื™ืกื” ื™ื›ื•ืœ ื‘ืขืฆื ืœื”ื’ื“ื™ืœ ืื ื”ืžื™ื“ืข ื”ืžืง)ื›ืžื• ื”ืขืฅ ื”ื‘ื™ื ืืจื™ ื‘ืงื•ื“ ื”ืืคืžืŸ(. ืœื›ืŸ,

, ืฉื–ื” ืœื ื“ื‘ืจ ืจืฆื•ื™. ื‘ื ื•ืกืฃ, ืžื™ื“ืข ืฉืื™ืŸ ื‘ื• ื™ืชื™ืจื•ืช ืื• ืชื‘ื ื™ื•ืช ื›ืœืฉื”ืŸ ืฉื—ื•ื–ืจื•ืช ืขืœ ืืช ื”ืชื•ืฆืจ ื”ืกื•ืคื™

ื”ื’ื•ื“ืœ ืฉืœ ื”ืงื•ื‘ืฅ ื”ื“ื—ื•ืก ืœื ื™ื”ื™ื” ืขืฆืžืŸ )ื›ืžื• ืžื™ื“ืข ืจื ื“ื•ืžืœื™ ืœื—ืœื•ื˜ื™ืŸ( ื’ื ืœื ื™ื™ื˜ื™ื‘ ืขื ื“ื—ื™ืกื”, ืžืื—ืจ ื•

. ืงื˜ืŸ ื‘ื”ืจื‘ื” ืžื’ื•ื“ืœ ื”ืžื™ื“ืข ื”ืžืงื•ืจื™

ื‘ืžืจื‘ื™ืช ื”ืžืงืจื™ื, ื›ืืฉืจ ื ื“ื—ื•ืก ืžื™ื“ืข, ื’ื ืื ื”ื•ื ื˜ืงืกื˜ ื‘ืžืฆื‘ื• - ื—ื•ืก ื”ื•ื ืœื ื˜ืงืกื˜ื•ืืœื™ืžื™ื“ืข ื“ .2

. ื”ืกื™ื‘ื” ืœื›ืš ื”ื™ื ื›ื™ ืคื•ืจืžื˜ื™ ื“ื—ื™ืกื” ืจื•ืฆื™ื ืœืชืคื•ืก ื›ืžื” ื”ืงื•ื‘ืฅ ื”ื“ื—ื•ืก ืœืจื•ื‘ ืœื ื™ื”ื™ื” ื˜ืงืกื˜ื”ืžืงื•ืจื™,

ื•ืœืขื‘ื•ืจ ASCII-ืฉืคื—ื•ืช ืžืงื•ื, ืœื”ื™ื•ืช ื›ืžื” ืฉื™ื•ืชืจ ื™ืขื™ืœื™ื, ื•ื”ืคืชืจื•ืŸ ืœื›ืš ื”ื•ื ืœืขื–ื•ื‘ ืืช ืขื•ืœื ืื•ืชื™ื•ืช ื”

ื ืืจื™. ืœืจื•ื‘, ื–ืืช ืœื ืชื”ื™ื” ื‘ืขื™ื” ืืฆืœื ื• ื›ื™ ืžืจื‘ื™ืช ื”ืฉื™ื˜ื•ืช ืœื‘ื™ืฆื•ืข ื–ืœื™ื’ืช ืžื™ื“ืข ืฉืืฆื™ื’ ื›ืืŸ ืœืžื™ื“ืข ื‘ื™

(. ืขื ื–ืืช, ASCIIื ื•ืขื“ื• ืœื”ืขื‘ื™ืจ ืกื™ื‘ื™ื•ืช ื‘ื™ื ืืจื™ื•ืช )ื›ืš ืฉืื™ืŸ ืžื’ื‘ืœื” ื›ืœืฉื”ื™ ืฉืžื—ื™ื™ื‘ืช ืฉื™ืžื•ืฉ ื‘ืื•ืชื™ื•ืช

ื—ืฉื•ื‘ ืœื–ื›ื•ืจ ืืช ื”ืฉื™ื ื•ื™ ื”ื–ื” ืฉืœืื—ืจื™ื• ืžื™ื“ืข ื™ื”ื™ื” ืœืจื•ื‘ ื“ื—ื•ืก ื•ื‘ื™ื ืืจื™.

ื”ื•ื ืœื ืื—ืจ ืžื”ืžื—ืฉื‘ ื”ืืจื’ื•ื ื™ืจืš ืœื‘ืฆืข ืืช ื”ืœื™ืš ื”ื“ื—ื™ืกื” ื‘ื ื•ืกืฃ, ื™ืฉ ืœื–ื›ื•ืจ ืฉื”ืžื—ืฉื‘ ืฉื™ืฆื˜

-ืฉื”ืฉืชืœื˜ื ื• ืขืœื™ื• )ืฉืžื—ื–ื™ืง ืืช ื”ืžื™ื“ืข ื”ืจื’ื™ืฉ(. ื–ื” ืžื•ืกื™ืฃ ื ื“ื‘ืš ื ื•ืกืฃ ืฉืœ ื“ืงื•ื™ื•ืช ืœื”ืชื—ืฉื‘ ื‘ื”ืŸ

ื”ืžืฉืื‘ื™ื ืฉืœ ื”ืžื—ืฉื‘ )ืžื‘ื—ื™ื ืช ื™ื›ื•ืœืช ืœื‘ืฆืข ืืช ื”ื“ื—ื™ืกื”(, ื”ืจืฉืื•ืช ืžืฉืชืžืฉ ื–ืžื™ื ื•ืช, ื”ื•ืกืคืช ืงื•ื“

ื•ื•ื™ืจื•ืก. ื”ืจื›ื‘ืชื™ ืจืฉื™ืžื” -ื•ืช ืขืœ ื™ื“ื™ ืžืขืจื›ื•ืช ืื ื˜ื™ืžื‘ืœื™ ืœื”ืชื’ืœ -ืฉืชืขืฉื” ืืช ื”ื“ื—ื™ืกื”, ื•ื›ืœ ื–ื” RATืœืชื•ื›ื ืช

ืฉืœ ืงืจื™ื˜ืจื™ื•ื ื™ื ืฉื ื™ืชืŸ ืœื”ืชื™ื™ื—ืก ืืœื™ื”ื ื›ืฉื‘ื•ื—ืจื™ื ื“ื—ื™ืกื” ืœืฉื™ื˜ื” ืœื–ืœื™ื’ืช ืžื™ื“ืข:

ื–ื” ื—ืฉื•ื‘ ืžืื•ื“ - (specific-purposeื“ื—ื™ืกื” ืกืคืฆื™ืคื™ืช ) .vs( general-purposeื“ื—ื™ืกื” ื›ืœืœื™ืช ) .1

ื•ื ื‘ื ื•ื™ ื•ื›ื•'. ืฉื™ื˜ื•ืช ื“ื—ื™ืกื” ืžื” ื”ืคื•ืจืžื˜ ืฉืœื•, ืื™ืš ื” -ืœื”ื›ื™ืจ ืืช ื”ืžื™ื“ืข ืฉืื ื—ื ื• ืจื•ืฆื™ื ืœื”ื•ืฆื™ื ืžื”ืจืฉืช

( ื™ื•ื“ืขื•ืช ืœื“ื—ื•ืก ื›ืœ ืจืฆืฃ ื‘ืชื™ื, ื•ืœื”ื•ืฆื™ื ืงื•ื‘ืฅ ื“ื—ื•ืก ื‘ืกื•ืฃ. ื“ื—ื™ืกื•ืช ืกืคืฆื™ืคื™ื•ืช, ืœืขื•ืžืช gzipื›ืœืœื™ื•ืช )ื›ืžื•

ื–ืืช, ื ื•ืขื“ื• ืœืคื•ืจืžื˜ ืžืกื•ื™ื ื›ืฉื”ืŸ ื™ื•ื“ืขื•ืช ืื™ืš ืœื ืฆืœ ืื•ืชื• ื‘ืฆื•ืจื” ืฉื‘ื” ื”ื“ื—ื™ืกื” ืชื”ื™ื” ืžื™ื˜ื‘ื™ืช ืื™ืชื•.

. PDFืื•ื“ ืžื“ื—ื™ืกืช ื•ื•ื™ื“ืื• ืื• ืงื‘ืฆื™ ื“ื—ื™ืกืช ืงื‘ืฆื™ื ื›ืœืœื™ื™ื ืฉื•ื ื” ืžืื•ื“ ืžื“ื—ื™ืกืช ืชืžื•ื ื•ืช ื•ื”ืŸ ืฉื•ื ื•ืช ืž

ื“ื•ื’ืžื”, ืื ืชืžื•ื ื•ืช ื–ื” ืžื” ืฉืืชื ืžืขื•ื ื™ื™ื ื™ื ืœื”ื•ืฆื™ื ืžืจืฉืช ื”ืืจื’ื•ืŸ, ืื•ืœื™ ืชืฉืงืœื• ืœื”ืงื˜ื™ืŸ ืืช ืœ

ืœื ื™ื•ื“ืข ืœืขืฉื•ืช(, ืื• ืœื”ืฉืชืžืฉ ื‘ืžืงื•ื“ื“ ืชืžื•ื ื•ืช ื™ื™ื—ื•ื“ื™ ื›ืžื• gzip-ื”ืจื–ื•ืœื•ืฆื™ื” ืฉืœ ื”ืชืžื•ื ื” )ื“ื‘ืจ ืฉ

MozJPEG , ืฉื™ื›ื•ืœ ืœื”ืงื˜ื™ืŸ ืžืฉืžืขื•ืชื™ืช ืืช ื’ื•ื“ืœ ื”ืงื•ื‘ืฅ ืžื‘ืœื™ ืœืื‘ื“ ื”ืจื‘ื” ืžืื™ื›ื•ืช ื”ืชืžื•ื ื” )ืฉื™ืคื•ืจ ืฉืœ

app.squooshืœืขื•ืžืช ื“ื—ื™ืกื” ื›ืœืœื™ืช(. ื ื™ืชืŸ ืœื—ื–ื•ืช ื‘ื›ื•ื— ืฉืœ ื“ื—ื™ืกืช ืชืžื•ื ื•ืช ื‘ืืชืจ %911-ืœ %111ื‘ื™ืŸ

ื™ื‘ื•ืช ืฉืคืฉื•ื˜ ืœื ื ื™ืชืŸ ืœื”ืฉื™ื’ ( ื•ืชื•ืฆืื•ืช ืžืจื”MozJPEGืฉืžืฆื™ื’ ืฉื™ื˜ื•ืช ื“ื—ื™ืกื” ืฉื•ื ื•ืช ืœืชืžื•ื ื•ืช )ื’ื ืืช

ืขื ื“ื—ื™ืกื” ืจื’ื™ืœื”. ืขื ื–ืืช, ืœื ื”ื™ื™ืชื™ ืžืžื”ืจ ืœื”ืกืคื™ื“ ืืช ื”ื“ื—ื™ืกื•ืช ื”ื›ืœืœื™ื•ืช.

ื”ืกื™ื‘ื” ื”ืžืจื›ื–ื™ืช ืœื›ืš ื”ื™ื ื›ื™ ื“ื—ื™ืกื•ืช ื›ืœืœื™ื•ืช ื”ืŸ ื›ืœื™ ืžื•ืขื™ืœ ื›ืฉื–ื” ื‘ื ืœืžืจื‘ื™ืช ื”ืงื‘ืฆื™ื ื”ื‘ื™ื ืืจื™ื™ื

ืช ืœื›ื•ื•ืฅ , ืžื•ื“ืœื™ื ืชืœืช ืžืžื“ื™ื™ื, ื•ื›ื•'(. ื”ื“ื™ื ืืžื™ื•ืช ืฉืœื”ื ื‘ื™ื›ื•ืœDOCX, ืงื‘ืฆื™ PDFืฉื”ื ืœื ืžื“ื™ื” )ืงื‘ืฆื™

Page 16: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

16 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ื”ื›ืœ )ื’ื ืื ืžืขื˜ ื‘ื”ืฉื•ื•ืื” ืœื“ื—ื™ืกื” ืกืคืฆื™ืคื™ืช( ืžืฉืื™ืจื” ืื•ืชื ืื•ืคืฆื™ื” ื‘ื“ื™ื•ืง ื›ืžื• ืฉื™ื˜ื•ืช ืื—ืจื•ืช.

ื™ืชืจื•ืŸ ื ื•ืกืฃ ืฉืœ ื”ื“ื—ื™ืกื” ื”ื›ืœืœื™ืช ื ื™ืชืŸ ืœืจืื•ืช ื‘ืคืกืงื” ื”ื‘ืื”.

ื—ื•ื• ื”ืฆืœื—ื” ืื“ื™ืจื” Filelessื” ืžืกื•ื’ ื ื•ื–ืงืžืชืงืคื•ืช - ืขื“ื™ืฃ ืœื”ืฉืชืžืฉ ื‘ืชื•ื›ื ื•ืช ื”ืžื•ืชืงื ื•ืช ืขืœ ื”ืžื—ืฉื‘ .2

ื‘ืจื—ื‘ื™ ื”ืขื•ืœื )ื”ืŸ ื‘ืžื—ืฉื‘ื™ื ืคืจื˜ื™ื™ื ื•ื”ืŸ ransomware-ื›ืฉื”ืŸ ื”ืจืื• ื™ืขื™ืœื•ืช ื•ืชื•ืฆืื•ืช ื‘ืฉื™ืžื•ืฉ ื‘

ื‘ืžื—ืฉื‘ื™ื ืืจื’ื•ื ื™ื™ื(. ื”ืจืขื™ื•ืŸ ืœื”ืฉืชืžืฉ ื‘ื›ืœื™ื ืฉื›ื‘ืจ ืžื•ืชืงื ื™ื ืืฆืœ ื”ืžืฉืชืžืฉ ื‘ืžืงื•ื ืœื”ื•ืจื™ื“ ืงื‘ืฆื™

ืช ืžื•ื‘ื ื•ืช ื ืจืื” ืœื’ื™ื˜ื™ืžื™ ื”ืจืฆื” ื•ืœื”ืคืขื™ืœ ืื•ืชื ื”ื•ื ืžืชื•ืง ื‘ื“ื™ื•ืง ื›ืžื• ืฉื”ื•ื ืงื˜ืœื ื™. ื”ืฉื™ืžื•ืฉ ื‘ืชื•ื›ื ื•

ื‘ื”ืฉื•ื•ืื” ืœื”ื•ืจื“ืช ืงื‘ืฆื™ ื”ืจืฆื” ื—ื“ืฉื™ื, ื•ื”ืชื•ื›ื ื•ืช ื”ืžื•ื‘ื ื•ืช ื™ื›ื•ืœื•ืช ืœื”ื™ื•ืช ื‘ืขืœื•ืช ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืœื

, ื›ืœื™ ื“ื—ื™ืกื”tarืžืขื˜ื” ืื ื™ื•ื“ืขื™ื ืื™ืš ืœื”ืฉืชืžืฉ ื‘ื”ืŸ ื ื›ื•ืŸ. ื‘ืžืจื‘ื™ืช ืžืขืจื›ื•ืช ืœื™ื ื•ืงืก ื ื™ืชืŸ ืœืžืฆื•ื ืืช

. BZip2-ื• GZIPืขื•ืฆืžืชื™ ืฉืžืฉืžืฉ ืœื“ื—ื™ืกื” ืฉืœ ืงื‘ืฆื™ื ื‘ืคื•ืจืžื˜ื™ื ืฉื•ื ื™ื ื›ื•ืœืœ

ืฉื™ืžื•ืฉ ื‘ื• ื™ื›ื•ืœ, ืœื“ื•ื’ืžื”, ืœื—ืกื•ืš ืืช ืฉื•ืจื•ืช ื”ืงื•ื“ ืฉืžื’ื“ื™ืจื•ืช ืืช ื”ืžืชืžื˜ื™ืงื” ื•ื”ืืœื’ื•ืจื™ืชืžื™ืงื” ืฉื”ื™ื™ื ื•

GNU(. ื‘ื ื•ืกืฃ, ื›ืœื™ RATืฆืจื™ื›ื™ื ืœื”ื•ืกื™ืฃ ื‘ืชื•ื›ื ื” ืฉืœื ื• ืœื‘ื™ืฆื•ืข ืชื”ืœื™ืš ื“ื•ืžื” )ื›ื ืจืื” ื ื•ื–ืงื” ื›ืœืฉื”ื™ ืื•

ื ื™ื ื‘ืฆื•ืจื” ืžืื•ื“ ื™ืขื™ืœื”, ื•ืœื›ืŸ ื”ื‘ื™ืฆื•ืขื™ื ืฉืœื• ื™ื›ื•ืœื™ื ืœื”ื™ื•ืช ื˜ื•ื‘ื™ื ื™ื•ืชืจ ื‘ื”ืฉื•ื•ืื” ืœืจื•ื‘ ื›ืชื•ื‘ื™ื ื•ืžืชื•ื›ื 

ื‘ืชื•ื›ื ื•ืช ืฉืžื•ืชืงื ื•ืช ืขืœ ื™ื™ืชื›ืŸ ืฉืœื ืชืจืื• ืœื ื›ื•ืŸ ืœื”ื™ื•ืช ืชืœื•ื™ื™ืืœื“ื—ื™ืกื” ืฉืชื ืกื• ืœื™ืฆื•ืจ ื‘ืขืฆืžื›ื. ืื•ืœื,

ื”ืžื—ืฉื‘ ื”ืืจื’ื•ื ื™ ื”ืžื•ื’ื‘ืœ ื•ื”ื™ืฉืŸ, ื•ื‘ืฆื“ืง.

PowerShell ืœื“ื•ื’ืžื”, ืžื•ืชืงืŸ ืขืœ ืžืจื‘ื™ืช ืžื—ืฉื‘ื™ ,Windows ืžื—ื“ืœ, ืืš ืขืงื‘ ื”ืฉื™ืžื•ืฉ ื‘ืชื•ืจ ื‘ืจื™ืจืช

ืขืœ ืžื—ืฉื‘ื™ื ืžื‘ื˜ืœื™ื ืื•ืชื• ื•ืœื ืžืืคืฉืจื™ื ืœื• ืœืจื•ืฅื”ื ืจื—ื‘ ืฉืœ ื ื•ื–ืงื•ืช ื‘ื›ืœื™ ื”ืขื•ืฆืžืชื™ ื”ื–ื”, ืœืขื™ืชื™ื

ื™ื ื‘ืžืขืจื›ืช ื”ื”ืคืขืœื” ื›ื—ืœืง ื‘ืื•ืคืŸ ื“ื•ืžื”, ื™ืฉื ื ืืจื’ื•ื ื™ื ืฉืžื’ื‘ื™ืœื™ื ื’ื™ืฉื” ืœื›ืœื™ื ื‘ืกื™ืกื™ ืืจื’ื•ื ื™ื™ื.

ืืžื•ืŸ.-ืžื“ื•ืงื˜ืจื™ื ืช ืืคืก

Page 17: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

17 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ืฉื™ืžื•ืฉ ื‘ื”ืฆืคื ื”

. ื›ืžืขื˜ ื›ืœ ื“ื’ื™ืžืช Data Exfiltrationื”ืฆืคื ื” ื”ื™ื ื”ื—ื‘ืจื” ื”ื›ื™ ื˜ื•ื‘ื” ืฉืœ ื›ืœ ืฉื™ื˜ื” ืœื‘ื™ืฆื•ืข

ื™ื•ืชืจ -ื•ื•ื™ืจื•ืก ืฉื ืชืงืœืชื™ ื‘ื” ื”ื›ื™ืœื” ืกื•ื’ ื›ื–ื” ืื• ืื—ืจ ืฉืœ ื”ืฆืคื ื”. ื”ืกื™ื‘ื” ืœื›ืš ื”ื™ื ืคืฉื•ื˜ื”

ื‘ืฉื•ื ื” ืžื“ื—ื™ืกื”, ืฉื™ืžื•ืฉ ื‘ื”ืฆืคื ื” ืœื ืงืฉื” ืœื–ื”ื•ืช ื“ืœื™ืคื•ืช ืฉืœ ืžื™ื“ืข ืจื’ื™ืฉ ื›ืฉื”ื•ื ืžื•ืฆืคืŸ.

ืžื™ื“ืข ืžื•ืฆืคืŸ ื™ื•ืฆื ืืจื•ืš ื™ื•ืชืจ ืžื”ืžื™ื“ืข ื”ืžืงื•ืจื™ ื‘ื’ืœืœ ืžืกืคืจ ืกื™ื‘ื•ืช: -ืืžื•ืจ ืœื”ื’ื“ื™ืœ ืืช ืื•ืจืš ื”ืžื™ื“ืข. ื‘ืคื•ืขืœ

( ื™ื›ื•ืœ ืœื”ื™ื•ืช ืžืคื•ืขื ื— ืœืžื™ื“ืข ืžืงื•ืจื™ ciphertextืกื™ืžื˜ืจื™ื•ืช ื‘ืขืœื•ืช ืชื›ื•ื ื” ืœืคื™ื” ื›ืœ ืฆื•ืคืŸ ) ืชื”ืฆืคื ื• .1

(plaintext ืื• ื‘ืžื™ืœื™ื ืื—ืจื•ืช ,)- ื•ืคืŸ, ืขื“ื™ื™ืŸ ื™ื”ื™ื” ื ื™ืชืŸ ืœืคืขื ื— ืื•ืชื• )ืคืฉื•ื˜ ืœื ืื ืžื™ืฉื”ื• ื™ืฉื ื” ืืช ื”ืฆ

ื•ื™ื“ื•ื ืฉื”ืžื™ื“ืข ื”ืžื•ืฆืคืŸ ื”ื•ืขื‘ืจ ืœืœื ืฉื™ื ื•ื™ ืœืžื™ื“ืข ื”ืžืงื•ืจื™ ืฉืจืฆื™ื ื•(. ืื ืืชื ืžืฆืคื™ื ื™ื ืงื•ื‘ืฅ, ืชืจืฆื•

, ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช ื•ื›ื•'(.Checksum ,Hash, ื•ืœืฉื ื›ืš ืžื•ืกื™ืคื™ื ืžื™ื“ืข ื ื•ืกืฃ ืฉืžืฉืžืฉ ืœืื™ืžื•ืช )ื‘ื“ืจืš

ืœืชืืจ ื™ื—ื™ื“ืช ืžื™ื“ืข ื‘ื•ื“ื“ืช ืฉืžื‘ืฆืขื™ื ืขืœื™ื” "ื‘ืœื•ืง" )ืžื•ืฉื’ -ืžืจื‘ื™ืช ื”ืฆืคื ื™ื ื”ืกื™ืžื˜ืจื™ื™ื ืžืฉืชืžืฉื™ื ื‘ .2

, ืœื“ื•ื’ืžื”, ืขื•ืฉื” ื”ืฆืคื ื” ื•ืคืขื ื•ื— AES-128ืืช ื”ื”ืœื™ืš ื”ืžืชืžื˜ื™ ืฉืœ ื”ื”ืฆืคื ื”/ืคืขื ื•ื—( ืฉื’ื“ื•ืœ ืžื‘ื™ืช ื‘ื•ื“ื“.

ื‘ืชื™ื(. ื›ืชื•ืฆืื” ืžื›ืš, ืื ื’ื•ื“ืœ 32ื”ื•ื AES-128ื‘ืชื™ื ื‘ืžื›ื” ืื—ืช )ื›ืœื•ืžืจ, "ื‘ืœื•ืง" ื™ื—ื™ื“ ืฉืœ 32ืขื

)ืขืœ ื™ื“ื™ ืืช ื”ืžื™ื“ืข( padding) "ืœืจืคื“" ืฆื•ืจืšื”ืงื•ื‘ืฅ ื”ื•ื ืื™ื ื• ืžื›ืคืœื” ื™ืฉื™ืจื” ืฉืœ ื’ื•ื“ืœ ื”ื‘ืœื•ืง, ื™ื”ื™ื”

. ืขื ื–ืืช, ื™ืฉื ื ื“ืจื›ื™ื ืขืœ ืžื ืช ืฉื™ื”ื™ื” ืžืกืคื™ืง ื‘ืฉื‘ื™ืœ ื‘ืœื•ืง ืื—ืจื•ืŸ ืฉืœืื”ื•ืกืคืช ืžื™ื“ืข ื‘ืกื•ืฃ ื”ืงื•ื‘ืฅ(

( ืื‘ืœ ื–ื” ื™ื‘ื•ื Stealing Ciphertextืœืขืฉื•ืช ืืช ื”ืžืชืžื˜ื™ืงื” ืขืœ ื”ื‘ืœื•ืง ื”ืื—ืจื•ืŸ ืžื‘ืœื™ ืœืจืคื“ ืื•ืชื• )ื›ืžื•

ืขืœ ื—ืฉื‘ื•ืŸ ืกื™ื‘ื•ื›ื™ื•ืช ื•ื–ืžืŸ ืจื™ืฆื” ืฉืœ ืืœื’ื•ืจื™ืชื ื”ื”ืฆืคื ื”.

ืฉื›ืชื•ื‘ ื‘ื• ืžื™ื“ืข ืจืœื•ื•ื ื˜ื™ ืœืฉื™ื˜ืช headerื™ืฉ ื”ืจื‘ื” ืฉื™ื˜ื•ืช ืฉื•ื ื•ืช ืœื”ืฆืคื™ืŸ ืงื•ื‘ืฅ. ืœืจื•ื‘, ื–ื” ื™ืขื™ืœ ืœื”ื•ืกื™ืฃ .3

ืขืœ ืžื ืช ืฉื‘ืชื”ืœื™ืš ื”ืคืขื ื•ื— ืœื ื™ื”ื™ื• ื”ื”ืฆืคื ื”, ืกื•ื’ ื”ืืœื’ื•ืจื™ืชื, ืžื ื’ื ื•ื ื™ื ืฉื•ื ื™ื ืฉื”ื™ื• ื‘ืฉื™ืžื•ืฉ ื•ื›ื•'

ืื ื—ื ื• -. ืขื‘ื•ืจื ื•, ื”ืกืขื™ืฃ ื”ื–ื” ืœื ืžืื•ื“ ืจืœื•ื•ื ื˜ื™ ืจื™ื ืฉืืžื•ืจื™ื ืœื”ื™ื•ืช ื‘ืฉื™ืžื•ืฉืฉื’ื™ืื•ืช ื‘ื ื•ื’ืข ืœืคืจืžื˜

ืฉื•ืœื˜ื™ื ื‘ื”ืฆืคื ื”. ืื ื—ื ื• ืฉื•ืœื˜ื™ื ื‘ืคืขื ื•ื—. ืื ื—ื ื• ืฉื•ืœื˜ื™ื ื‘ืคืจืžื˜ืจื™ื ื•ื‘ืžืคืชื—/ื•ืช ืฉื‘ืฉื™ืžื•ืฉ.

ืฆื•ืคืŸ ื–ืจื ืกื™ื ื›ืจื•ื ื™ - RC4ืฆื•ืคืŸ ื”ืฆืคื ื” ืฉืงืœ ืœื™ื™ืฉื )ื•ื’ื ื ืžืฆืืช ื‘ืฉื™ืžื•ืฉ ืจื—ื‘ ืžืื•ื“ ื‘ืงืจื‘ ื ื•ื–ืงื•ืช( ื”ื™ื

ื”ื™ื” ื‘ืขื‘ืจ ื‘ืฉื™ืžื•ืฉ ื ืจื—ื‘ ื”ื•ื ื•ืชืจ ื•ืงืœ ืœื™ื™ืฉื•ื ื•ื”ื˜ืžืขื”. ืขืงื‘ ืคืฉื˜ื•ืชื• ื”ืžื™ื•ืขื“ ืœืชื•ื›ื ื”, ืคืฉื•ื˜ ื‘ื™

ืžืฉื•ืœื‘ ืขื ื”ื˜ืงืกื˜ ื‘ื™ืช ืื—ืจ ื‘ื™ืช, ื‘ืžื”ืœืš ื”ื”ืฆืคื ื”, ืžืคืชื— ื”ื”ืฆืคื ื” . WEP-ื• SSLื‘ืคืจื•ื˜ื•ืงื•ืœื™ื ื›ืžื•

.)ืžืชืžื˜ื™ืงื” ืฉืžืื•ื“ ืงืœ ืœื™ื™ืฉื, ื•ืื™ื ื” ื“ื•ืจืฉืช ืžืฉืื‘ื™ื ืจื‘ื™ื( ืฆื•ืคืŸ ื•ืจื ืื‘ื“ื•ืžื” ืœ XORืื•ืคืจื˜ื•ืจ ื‘ืืžืฆืขื•ืช

ืœืžืจื‘ื” ื”ืžื–ืœ, ืื ื• ืขืงื‘ ื—ื•ืœืฉื•ืช ืฉื”ืชื’ืœื• ื‘ื• ื”ื•ื ืื™ื ื• ื‘ื˜ื•ื— ื•ืื™ื ื• ืžื•ืžืœืฅ ืœืฉื™ืžื•ืฉ ืงืจื™ืคื˜ื•ื’ืจืคื™ ื›ื™ื•ื.ืื•ืœื,

ืœื ืžื—ืคืฉื™ื ื”ืฆืคื ื” ืฉื‘ื˜ื•ื—ื” ืœืฉื™ืžื•ืฉ ืงืจื™ืคื˜ื•ื’ืจืคื™ ืืœื ืจืง ืฉื™ื˜ื” ืœืขืจื‘ืœ ืืช ื”ืžื™ื“ืข ื”ืžื•ืขื‘ืจ ื›ืš ืฉื™ื”ื™ื”

ืช ื”ื’ื ื” ืœื–ื”ื•ืช ืื•ืชื• ื‘ืชื•ืจ ืžื™ื“ืข ืจื’ื™ืฉ ื•ืœื›ืŸ ื”ืฆื•ืคืŸ ื”ื–ื” ื™ื”ื™ื” ืžื•ืฉืœื ืขื‘ื•ืจื ื•. ืงืฉื” ืœืžืขืจื›ื•

Page 18: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

18 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ืงื™ื“ื•ื“ ืžื™ื“ืข

ืงื™ื“ื•ื“ ืžื™ื“ืข ื”ื•ื ื”ื—ืœืง ื”ื›ื™ ืงืจื™ื˜ื™ ืžื‘ื™ืŸ ื”ืฉืœื•ืฉื” ืฉื ื“ื•ืŸ ืขืœื™ื”ื. ื“ื—ื™ืกื” ื”ื™ื ื”ืœื™ืš ืื•ืคืฆื™ื•ื ืœื™

ืœื—ืœื•ื˜ื™ืŸ, ื•ื’ื ื”ืฆืคื ื” )ืœืžืจื•ืช ืฉืžื•ืžืœืฆื™ื ืžืื•ื“(. ืฉื™ืžื•ืฉ ื ื›ื•ืŸ ื‘ืงื™ื“ื•ื“ ืžื™ื“ืข ื™ื›ื•ืœ ืœืขื–ื•ืจ ืœื ื•

ืœ ื”ืžื™ื“ืข ื”ืžื•ืขื‘ืจ ื‘ืชื•ื•ืš ื•ื’ื ืœืกื™ื™ืข ื‘ื”ืกืชืจืชื• )ืื ื›ื™ ืœื ืžื”ื•ื•ื” ืชื—ืœื™ืฃ ืœื”ืงื˜ื™ืŸ ืืช ื’ื•ื“

ืฉื›ืœ ืžื™ื“ืข ื”ื•ื ื‘ืกื•ืฃ ืจืฆืฃ ืฉืœ ืื—ื“ื™ื ื•ืืคืกื™ื ื•ื›ืš ื”ื•ื ืœื”ืฆืคื ื”(. ื”ืขื™ืงืจื•ืŸ ื”ื‘ืกื™ืก ื‘ืงื™ื“ื•ื“ ืžื™ื“ืข ื”ื•ื

-. ืœื ื•, ื‘ืชื•ืจ ืื ืฉื™ื, ืœื ืงืœ ืœื”ื‘ื™ืŸ ืืช ื”ืขืงืจื•ืŸ ื”ื–ื”, ื›ื™ ื”ื”ื’ื“ืจื” ืฉืœื ื• ืœื™ืื•ื—ืกืŸ ื‘ื–ื™ื›ืจื•ืŸ ืื• ื™ืขื‘ื•ืจ ื‘ืชื•ื•ืš

ืข" ื”ืŸ ืื•ืชื™ื•ืช ื•ืกืคืจื•ืช ื“ืฆื™ืžืœื™ื•ืช. ืื ืœื ืกื— ื‘ืคืฉื˜ื•ืช, ืงื™ื“ื•ื“ ืžื™ื“ืข ื”ื•ื ืžืฉื—ืง ืฉื‘ื• "ื™ื—ื™ื“ืช ื‘ืกื™ืก ืฉืœ ืžื™ื“

ืื ื—ื ื• ืžืžืคื™ื ืจืฆืคื™ื ืฉืœ ืื—ื“ื™ื ื•ืืคืกื™ื ืœืกื˜ ืขืจื›ื™ื ืžืกื•ื™ื, ื•ื”ืžื ืฆื— ื‘ืžืฉื—ืง ื”ื•ื ื–ื” ืฉืžืฆืœื™ื— ืœื‘ื˜ื ืืช

ืื•ืชื• ืกื˜ ืขืจื›ื™ื ื‘ืื•ืคืŸ ืื•ืคื˜ื™ืžืœื™.

ืงื™ื“ื•ื“ ืžื™ื“ืข, ืœื›ืœ ืคื™ืกืช ื‘ืฉื™ื˜ืช - ืขืจื›ื™ื•ืช )ืื—ื“ ืœื›ืœ ืื—ื“(-ื—ื“-ื—ื“ืœืงื™ื“ื•ื“ ืžื™ื“ืข ืชืงื™ืŸ ื™ืฉ ื“ืจื™ืฉื” ื”ื›ืจื—ื™ืช:

. ืœื ื™ื™ืชื›ืŸ ืฉืฉื ื™ ื ืชื•ื ื™ื ื™ื›ื•ืœื™ื ืœื™ืฆื•ืจ ืืช ืื•ืชื• ืจืง ืคื™ืกืช ืžื™ื“ืข ืžืงื•ืจื™ืช ืื—ืชืžื™ื“ืข ืžืงื•ื“ื“ ื—ื™ื™ื‘ืช ืœื”ื™ื•ืช

ืžื™ื“ืข ืžืงื•ื“ื“, ื›ื™ ืื—ืจืช ืœื ื ื•ื›ืœ ืœื“ืขืช ืœืื™ื–ื” ืžื™ื“ืข ืžืงื•ืจื™ ืื ื—ื ื• ืžืชื›ื•ื•ื ื™ื ื‘ืชื”ืœื™ืš ื”ืคืขื ื•ื—. ืœื“ื•ื’ืžื:

. ื”ื•ื“ืขื” C-ื• A ,Bืฉื‘ื ื•ื™ื•ืช ืžื”ืื•ืชื™ื•ืช ื‘ื“ื•ื’ืžื ืœืžืขืœื” ื ื™ืชืŸ ืœืจืื•ืช ืžืคืชื— ืขืจื›ื™ื ืขืœ ืžื ืช ืœืงื•ื“ื“ ื”ื•ื“ืขื•ืช

" ื™ื›ื•ืœ ืœื”ื™ื•ืช 3131ื”ืจืฆืฃ ื”ืžืงื•ื“ื“ " -". ื”ื‘ืขื™ื” ืขื•ืœื” ื‘ืคืขื ื•ื— 3131" ืชืงื•ื“ื“ ืœืคื™ ื”ืžืคืชื— ื‘ืชื•ืจ "ABABื›ืžื• "

ืœื“ื•ื’ืžื”, ืฉื–ื” ืœื ื”ืžืกืจ ื”ืžืงื•ืจื™ ABC" ื™ื›ื•ืœ ืœื”ื™ื•ืช 3131ืžืชื•ืจื’ื ืœืžืกืคืจ ืืคืฉืจื•ื™ื•ืช, ืฉื›ื•ืœืŸ ืกื‘ื™ืจื•ืช )"

ืฉืœื ื ื™ืชืŸ "ืœืคืจืฉืŸ" ื”ื•ื“ืขื” ืžืงื•ื“ื“ืช ืœื™ื•ืชืจ ืžืชืจื’ื•ื ืชื•ื•ื“ื ืฉื”ืชื›ื•ื•ื ื• ืืœื™ื•(. ื›ืœ ืฉื™ื˜ืช ืงื™ื“ื•ื“ ืžื™ื“ืข ืชืงื™ื ื”

. ืื—ื“ ื•ื™ื—ื™ื“

ืฉื ืžืฆืื•ืช ื‘ืฉื™ืžื•ืฉ )ืฉื”ืžื™ื“ืข ืฉืœื ืชืืจื™ืš ืืช ื›ืžื•ืช ื”ืื•ืชื™ื•ืชืฉื™ื˜ื” ืื•ืคื˜ื™ืžืœื™ืช ืœืงื™ื“ื•ื“ ืžื™ื“ืข ื”ื™ื ืื—ืช

)ื”ืŸ ืฉืœื ืชื“ืจื•ืฉ ื”ืจื‘ื” ืžืฉืื‘ื™ืื”ืžืงื•ื“ื“ ื™ื”ื™ื” ืงืฆืจ ื™ื•ืชืจ, ืฉื•ื•ื” ื‘ืื•ืจื›ื• ืื• ื’ื“ื•ืœ ื‘ืžืงืฆืช ืžื”ืžื™ื“ืข ื”ืžืงื•ืจื™(,

DLP. ื”ืกื™ื‘ื” ืœืงืจื™ื˜ืจื™ื•ืŸ ื”ืื—ืจื•ืŸ ื”ื™ื ื›ื™ ืžืขืจื›ื•ืช ื•ืฉืชื”ื™ื” ื™ื™ื—ื•ื“ื™ืชืŸ ืจื™ืฆื”(, ืžื‘ื—ื™ื ืช ื–ื™ื›ืจื•ืŸ ื•ื”ืŸ ืžื‘ื—ื™ื ืช ื–ืž

ื•ื›ื•'. Hex ,Base64 ,Base85ื™ื•ื“ืขื•ืช ืœื–ื”ื•ืช ื•ืœืคืขื ื— ืกื•ื’ื™ ืงื™ื“ื•ื“ ืžื•ื›ืจื™ื ื›ืžื•

ืขื‘ื•ืจ ื›ืœ ืžื™ื“ืข ืฉื™ื“ื•ืข ืœื ื• ืฉื ืจืฆื” ืœื”ื•ืฆื™ื ืžืžื—ืฉื‘ ืืจื’ื•ื ื™, ื ืฉืืœ ืืช ืขืฆืžื ื• ืžื”ื™ ื”ื“ืจืš ื”ื›ื™ ื˜ื•ื‘ื” ืœืงื•ื“ื“

ืžื—ืฉื‘ )ืœืœื ืฉื™ืžื•ืฉ ื‘ื“ื—ื™ืกื”(. ื ื’ื™ื“ ืฉื”ืชื—ื‘ืจื ื• ืœืื—ื“ ื”ืžื—ืฉื‘ื™ื ืื•ืชื• ื›ืš ืฉื™ื™ืงื— ื›ืžื” ืฉืคื—ื•ืช ืžืงื•ื ืขืœ ื”

ืฉืืงืืœืืงื” ื‘ืข"ืž ื•ืื ื—ื ื• ืจื•ืฆื™ื ืœื”ื•ืฆื™ื ืžื™ื“ืข ืขืœ ื›ืจื˜ื™ืกื™ ืืฉืจืื™ ืฉืœ ืžืฉืชืžืฉื™ื. -ื‘ื‘ื ืง ื”ื“ืžื™ื•ื ื™ ื‘ื•ื

Page 19: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

19 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ื ืจืฆื” ืœืฉืื•ืœ ืืช ืขืฆืžื ื• ืžื”ื™ ื›ืžื•ืช ื”ืžื™ื“ืข ื”ื“ื™ื’ื™ื˜ืœื™ ื”ืงื˜ื ื” ื‘ื™ื•ืชืจ ืฉื™ื›ื•ืœื” ืœื”ื›ื™ืœ ืืช ืคืจื˜ื™ ื›ืจื˜ื™ืก ืืฉืจืื™

ื‘ื•ื“ื“?

ืžืกืคืจ ื›ืจื˜ื™ืก ืืฉืจืื™. ื ืจืื” ืื™ืš ืฉื™ื˜ื•ืช ืงื™ื“ื•ื“ ื ืคื•ืฆื•ืช -ืœื”ืฆื™ื’ ืืช ืื•ืชื• ืžื™ื“ืข ื ืกืชื›ืœ ืขืœ ืฉื™ื˜ื•ืช ืฉื•ื ื•ืช

. ื‘ืฆื•ืจืชื• ื”ื ื•ื›ื—ื™ืช, ืื ื—ื ื• ืžืกื›ืœื™ื ืขืœ ืžืกืคืจ ื›ืจื˜ื™ืก ืื•ืจื›ื•ื•ืขืœ ื ืจืื•ืช ื”ืžื™ื“ืขืฉื•ื ื•ืช ื™ื›ื•ืœื•ืช ืœื”ืฉืคื™ืข ืขืœ

. ื‘ืžืฆื‘ื• ื”ื ื•ื›ื—ื™, ื›ืœ ืกืคืจื” ืœื•ืงื—ืช ื‘ื™ืช ืฉืœื:ASCIIืื•ืชื™ื•ืช 32ื”ืืฉืจืื™ ื‘ืชื•ืจ

ื”ืชืžื•ื  ืžืงื•ื“ื“ ืžื™ื“ืข ืื•ืจืš ืžื™ื“ืข ืงื™ื“ื•ื“

ื‘ืชื™ื 32ืื•ืชื™ื•ืช = ASCII 32 ื˜ืงืกื˜

Decimal Coded naryBi (BCD)

ืคืฉื•ื˜ื•ืืคืก ื”ื 1 - ื˜ืงืกื˜)ืชืฆื•ื’ืช

ืฉื’ื•ื“ืœ ื›ืœ ืื—ืช ืžื”ืŸ ื”ื™ื ื‘ื™ืช( ืื•ืชื™ื•ืช

ื‘ืชื™ื 21ืื•ืชื™ื•ืช = 21

Decimal Coded Binary (BCD)

ืกื™ื‘ื™ื•ืช ื”ืŸ' 1'-ื• 1 -ื‘ื™ื ืืจื™ืช ืชืฆื•ื’ื”)

(ืื•ืชื™ื•ืช ืกืชื ืœื, ื‘ื–ื™ื›ืจื•ืŸ

ื‘ืชื™ื 9 ).( ืœื ื ื™ืชื ื•ืช ืœืชืฆื•ื’ื” ื”ืื•ืชื™ื•ืช ืžืŸ ื—ืœืง

Base64 (ื ืงืœื˜ ื”ืืฉืจืื™ ื›ืจื˜ื™ืก ืžืกืคืจ

(ASCIIื›ื˜ืงืกื˜ ื‘ืชื™ื 21ืื•ืชื™ื•ืช = 21

Base32 ืžืกืคืจ ื›ืจื˜ื™ืก ื”ืืฉืจืื™ ื ืงืœื˜(

(ASCIIื›ื˜ืงืกื˜ ื‘ืชื™ื 12ืื•ืชื™ื•ืช = 12

ืžืขืจืš ื”ืžืจื” - (Hex) 16 ื‘ืกื™ืก

)ืžืกืคืจ ื›ืจื˜ื™ืก ื”ืืฉืจืื™ ื ืงืœื˜ ื“ืฆื™ืžืœื™

ื›ืžืกืคืจ ืฉืœื(

ื‘ืชื™ื Hex =1ืื•ืชื™ื•ืช 31

(Hexdump ืชืฆื•ื’ืช)

ื‘ืชื™ื 33ืื•ืชื™ื•ืช = 33 ื“ืฆื™ืžืœื™ ืžืขืจืš ื”ืžืจื” - 36 ื‘ืกื™ืก

Page 20: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

21 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

, ืื ื—ื ื• ืขื•ืฉื™ื ASCIIื ื™ืชืŸ ืœืจืื•ืช ื›ื™ ื›ืืฉืจ ืื ื—ื ื• ืžืชื™ื™ื—ืกื™ื ืœืžืกืคืจ ื‘ืชื•ืจ ืื•ืชื™ื•ืช - ืื•ืจืš ื”ืžื™ื“ืข ื”ืžืงื•ื“ื“

, Base64 ,Base62ืกื•ื’ ืฉืœ ืžื™ื“ืข ื“ื™ื’ื™ื˜ืœื™( ื›ืžื• ืœื• ืขื•ืœ. ืฉื™ืžื•ืฉ ื‘ืงื™ื“ื•ื“ื™ื ืฉื ื•ืขื“ื• ืœืžื™ื“ืข ื‘ื™ื ืืจื™ )ื›ืœื•ืžืจ, ื›ืœ

Base85 ื•ื›ื•' ืจืง ืžืืจื™ื›ื™ื ืืช ื›ืžื•ืช ื”ืžื™ื“ืข ืฉื™ืฉ ืœื”ืขื‘ื™ืจ ื‘ืชื•ื•ืš, ื›ืืฉืจ ื”ืฉื™ื ื”ื•ื ืฉืœBase32 ืขื ื”ื’ื“ืœื”

ืœืขื•ืžืช ื”ืžื™ื“ืข ื”ืžืงื•ืจื™. x1.6ืฉืœ ืคื™

, BCDื”ืฉื™ื˜ื•ืช ื”ื™ื—ื™ื“ื•ืช ืฉื”ืฆืœื™ื—ื• ืœื”ืงื˜ื™ืŸ ืืช ื›ืžื•ืช ื”ืžื™ื“ืข ื”ืžื•ืขื‘ืจ ื”ื ืืœื• ืฉื–ื™ื”ื• ืฉืžื“ื•ื‘ืจ ื‘ืงืœื˜ ืžืกืคืจื™ )

(. ืฉื™ื˜ื•ืช ืงื™ื“ื•ื“ ืฉื™ื•ื“ืขื•ืช ืœืขื‘ื•ื“ ื”ื™ื˜ื‘ ืขื ืžืกืคืจื™ื, ืžืฆืœื™ื—ื•ืช ืœืฆืžืฆื ื›ืžืขื˜ ื‘ื—ืฆื™ ืืช 12, ื‘ืกื™ืก 32ื‘ืกื™ืก

ืœื ื”ืกืชื›ืœ 32ื”ื™ื ืฉื™ื˜ื” ืื™ื•ืžื” ืื ืื ื—ื ื• ืฉื•ืžืจื™ื ืจืง ืžืกืคืจื™ื(. ื”ืงื™ื“ื•ื“ ืœื‘ืกื™ืก ASCIIื›ืžื•ืช ื”ืžื™ื“ืข )ื›ื™

ื‘ื•ื“ื“ื•ืช, ืืœื ื‘ื”ืงืฉืจ ืฉืœ ืžืกืคืจ ื“ืฆื™ืžืœื™ ืขืฆื•ื ื‘ืื•ืจื›ื•, ASCIIืขืœ ืžืกืคืจ ื›ืจื˜ื™ืก ื”ืืฉืจืื™ ื‘ืชื•ืจ ืื•ืชื™ื•ืช

ืกืคืจื•ืช ื™ื›ืœื• ืœื”ื™ื•ืช ืžื™ื•ืฆื’ื•ืช ื‘ื‘ื™ืช ืื—ื“ )ื•ืžื›ืืŸ ื”ืฆืžืฆื•ื 2. ื›ืชื•ืฆืื” ืžื›ืš, ื‘ืžืžื•ืฆืข, 32ื•ื”ื•ืžืจ ื›ืš ืœื‘ืกื™ืก

ื‘ื—ืฆื™ ื‘ืื•ืจืš(.

ื•ืžืฉืคื—ืชื•( ืžื•ืฆื™ืื™ื ืžื™ื“ืข ืืœืคืื ื•ืžืจื™ )ืื•ืชื™ื•ืช ื•ืžืกืคืจื™ื( Base64ืงื™ื“ื•ื“ื™ ื”ืžื™ื“ืข ื”ื‘ื™ื ืืจื™ ) - ื ืจืื•ืช ืžื™ื“ืข

ืฉืžื“ื•ื‘ืจ ื‘ืžืกืคืจ ืฉืœื ื”ื•ืฆื™ืื• ืขื ื›ืžื•ืช ื›ืœืฉื”ื™ ืฉืœ "=" ื‘ืกื•ืฃ )ืœืฆื•ืจืš "ืจื™ืคื•ื“"(. ืœืขื•ืžืชื, ื”ืฉื™ื˜ื•ืช ืฉื–ื™ื”ื•

ื‘ืœื™ืœ ื‘ื™ื ืืจื™, ืฉืœื ื ื™ืชืŸ ืœื”ืขื‘ื™ืจ ืื•ืชื• ื‘ืืžืฆืขื™ื ื˜ืงืกื˜ื•ืืœื™ื™ื. ืžื•ืฆื ืืœืคืื ื•ืžืจื™ ื™ื›ื•ืœ ืœื”ื™ื•ืช ืžืื•ื“ ืžื•ืขื™ืœ

ืœืฉื™ื˜ื•ืช ืœื–ืœื™ื’ืช ืžื™ื“ืข. ืื—ื“, ืœื“ื•ื’ืžื”, ื™ื›ื•ืœ ืœืฆืœื ืขื ื”ื˜ืœืคื•ืŸ ื”ืื™ืฉื™ ืฉืœื• ืืช ื”ืžืกืš ืฉืœ ืžื—ืฉื‘ ืืจื’ื•ื ื™

ื–ื” ืœื—ืœื•ื˜ื™ืŸ ืœืคื™ ื”ืชืžื•ื ื”. ื•ื™ื›ื•ืœ ืœืฉื—ื–ืจ ืืช Base64-ืฉืžืฆื™ื’ ืงื•ื‘ืฅ ื‘ื™ื ืืจื™ ืจื’ื™ืฉ ืฉืžืงื•ื“ื“ ื‘

ืืžื” ืžื”, ืœื ืชืžื™ื“ ื ื›ื™ืจ ืืช ื”ืžื™ื“ืข ืฉืื ื—ื ื• ืจื•ืฆื™ื ืœื”ื•ืฆื™ื ืžื”ืžื—ืฉื‘ ื”ืืจื’ื•ื ื™, ืื• ืžื” ื”ืคื•ืจืžื˜ ืฉื‘ื• ื”ื•ื

ืฉืžื•ืจ. ืœืขื™ืชื™ื ืจื—ื•ืงื•ืช ื”ืงืœื˜ ืฉื ืงื‘ืœ ื™ื”ื™ื” ืจืง ืžืกืคืจ ื“ืฆื™ืžืœื™ ื˜ื”ื•ืจ )ื•ืœืจื•ื‘ ื”ื•ื ื™ื”ื™ื” ืžืขื•ืจื‘ ืขื ืื•ืชื™ื•ืช(.

ืช ื”ืงื™ื“ื•ื“ ื•ืœืžื” ื™ืฉ ืœื”ืฉืงื™ืข ื‘ื›ืš ื”ื“ื•ื’ืžื ืœืžืขืœื” ืžืฆื™ื’ื” ื”ื™ื˜ื‘ ืืช ื”ื™ืชืจื•ื ื•ืช ื‘ื‘ื—ื™ืจื” ื ื›ื•ื ื” ืฉืœ ืฉื™ื˜

ืžื—ืฉื‘ื” ืจื‘ื”, ืืš ืœืจื•ื‘ ืœื ืชื”ื™ื” ืœื ื• ื”ืจื‘ื” ืฉืœื™ื˜ื” ืขืœ ื”ืžื™ื“ืข ื”ืžืงื•ื“ื“, ื•ื ื—ืคืฉ ืงื™ื“ื•ื“ ืฉื™ื˜ื™ื‘ ื”ืŸ ืขื

ื”ืžื™ื“ืข ื•ื”ืŸ ืขื ื”ืขืจื•ืฅ ื”ืกืžื•ื™ ืฉืœื ื•.

Page 21: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

21 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ื“ื•ื’ืžืื•ืช ืžื ื•ื–ืงื•ืช ื‘ืขื‘ืจ

ื•ื•ื™ืจื•ืกื™ื ื›ืžื•Zeus ,SpyEye ,ICE IX ื•-Citadel ืฉืชื•ื›ื ื ื• ืœืžืชืงืคื•ืช ืขืœ ืจืงืข ื›ืœื›ืœื™ ืžื—ืคืฉื™ื ื‘ืขื™ืงืจ ืžื™ื“ืข

ื‘ืขืœ ื”ืฉืคืขื” ื›ืœื›ืœื™ืช ื›ืžื• ืžื™ื“ืข ืคืจื˜ื™ ืขืœ ืžืฉืชืžืฉื™ื ื•ืคืจื˜ื™ ื›ืจื˜ื™ืก ืืฉืจืื™. ื›ื™ื•ื ืžืชื™ื™ื—ืกื™ื ืืœ

ื›ื™ ื›ืœ ืื—ื“ ื™ื›ื•ืœ ืœืจื›ื•ืฉ ืื•ืชื, ืœืฉืคืฆืจ ืื•ืชื )ืœื™ืฆื•ืจ ื•ืจื™ืื ื˜ื™ื( toolkitsืžืฉืคื—ื•ืช ื”ื•ื•ื™ืจื•ืกื™ื ื”ืืœื” ื›ืืœ

ื•ืœื”ืฉืชืžืฉ ื‘ื”ื ืœืžื˜ืจื•ืชื™ื• ื”ื–ื“ื•ื ื™ื•ืช.

Flame ื™ื™ื‘ืจ ื ื’ื“ ืžื“ื™ื ื•ืช ื”ืžื–ืจื— ื”ืชื™ื›ื•ืŸ ืก-ื”ื™ื™ืชื” ื—ืœืง ืžืจื›ื–ื™ ืžืงืžืคื™ื™ืŸ ืชืงื™ืคื” ื•ืจื™ื’ื•ืœื”ื™ื ื ื•ื–ืงื” ืฉ

ืฉื ืื‘ื“ื• ื ืชื•ื ื™ื ืžืžืขืจื›ื•ืช ืžื—ืฉื‘ื™ื ืจื‘ื•ืช ื•ื ื’ืจืžื• ืฉื™ื‘ื•ืฉื™ื ืœื™ื™ืฆื•ื ื”ื ืคื˜ ืฉืœ -)ื‘ืขื™ืงืจ ืื™ืจืืŸ

ื‘ื™ืฆื•ืข ื”ื ื•ื–ืงื” ืžืชืžืงื“ืช ื‘ืื™ืกื•ืฃ ืžื™ื“ืข ื‘ื“ืจื›ื™ื ืžื’ื•ื•ื ื•ืช, ื•ื‘ื”ืŸ: ืžืขืงื‘ ืขืœ ืชืขื‘ื•ืจืช ื”ืจืฉืช,(. ื”ืžื“ื™ื ื”

ื™ื™ืจื•ื˜ ืคืขื•ืœื•ืช ืžืงืœื“ืชืฆื™ืœื•ืžื™ ืžืกืš, ื”ืงืœื˜ืช ืื•ื“ื™ื• ืœืœื ื™ื“ื™ืขืช ื”ืžืฉืชืžืฉ, ื’ื™ืฉื” ืœื”ืชืงื ื™ ื‘ืœื•ื˜ื•ืช' ื•

(keylogging).ื”ืขืชืงืช ืฉื™ื—ื•ืช ื‘ืชื•ื›ื ื•ืช ืžืกืจื™ื ืžื™ื™ื“ื™ื™ื, ื•ืขื•ื“ , Flame ื—ื™ืคืฉื” ื‘ืื•ืคืŸ ืกืคืฆื™ืคื™ ืขื‘ื•ืจ

ื‘ืขืœื™ ืชื•ื›ืŸ ืจื’ื™ืฉ. PDFืื• ืงื‘ืฆื™ AutoCADืžื™ื“ืข ืงื ื™ื™ื ื™ ื›ืžื• ืขื™ืฆื•ื‘ื™

ื ื•ื–ืงื•ืช ื›ืžื•Stuxnet ื•-Duqu ืฉืžื›ื™ืœื” ืงื•ื“ ื“ื•ืžื” ืœ(-Stuxnet ืชื•ื›ื ื ื• ืœื”ื•ืฆื™ื ืžื™ื“ืข ืžืžืขืจื›ื•ืช ืฉืœื™ื˜ื” )

( ื›ืžื• ืืœื• ืฉืฉื™ืžืฉื• ืืช ื”ืฆื ื˜ืจื™ืคื•ื’ื•ืช ื‘ื›ื•ืจ ICS( ืฉืœ ืฉื™ืจื•ืชื™ ืฉืœื™ื˜ื” ืชืขืฉื™ื™ืชื™ื™ื )SCADA) ื•ื ื™ื˜ื•ืจ

ื”ืื™ืจืื ื™.

ืžื™ื“ืข ื•ื”ืขื‘ืจืช ื”ืฆืคื ื” ืฉื™ื˜ืช ืฉื ื•ืช ืคืขื™ืœื•ืช ื ื•ื–ืงื” ืฉื

Zeus 2111 . ืงื™ื™ืžื™ื ื’ื ื’ืจืกืื•ืช ืฉืžืฉืชืžืฉื•ืช HTTP-ื›ื“ื™ ืœื”ืฆืคื™ืŸ ืžื™ื“ืข ืฉืขื•ื‘ืจ ื‘ RC4 ืืœื’ื•ืจื™ืชื

ื‘ืฉื‘ื™ืœ ืœืืžืช ืžื™ื“ืข. MD5-ื‘ ืฉื™ืžื•ืฉ(. 2131-)ื”ื—ืœ ืž P2Pื‘ืคืจื•ื˜ื•ืงื•ืœื™

Taidoor 2008 -. ื•ืจื™ืื ื˜ื™ื ืขื“ื›ื ื™ื™ื ืžืฉืชืžืฉื™ื ื’ื ื‘HTTPืฉืžืฆืคื™ืŸ ืžื™ื“ืข ืฉืขื•ื‘ืจ ื“ืจืš RC4 ืžื ื’ื ื•ืŸ

AES.

Citadel 2133-2135 ืฉืœ ืฉื™ืœื•ื‘XOR ื•-AES ืœื”ืฆืคื™ืŸ ืžื™ื“ืข ืฉืขื•ื‘ืจ ื“ืจืšHTTP

Hidden Bee 2131-2139 ื‘ ื’ื ืฉื™ืžื•ืฉ-RC4 ื‘ืฉื™ืœื•ื‘ ืขืRSA ื”ื ื•ื–ืงื”ืขืœ ืžื ืช ืœื”ืงืฉื•ืช ืขืœ ื—ื•ืงืจื™ื ืœื ืชื— ืืช.

LuckyCat 2131-2132 ื‘ืงื•ื‘ืฅ ืฉื™ืžื•ืฉ CAB ื“ื—ื•ืก ืฉืขื•ื‘ืจ ื“ืจืšTTPH

Duqu 2133-2138 ืžื•ืกืชืจืช ื‘ืชื•ืš ืงื‘ืฆื™ ืชืงืฉื•ืจืชJPEG ืื•GIF ืขื‘ืจื• ื“ืจืš ,HTTP ,HTTPS ,SMB ,TCP.

Stuxnet 2131-2138 ื‘ ืžืฉืชืžืฉ-XOR ื™ื—ื“ ืขื ืคืจื•ื˜ื•ืงื•ืœHTTP.

Flame

(SkyWiper) 2133-2132

, HTTPSื‘ื”ืฆืคื ื” ืžื‘ื•ืกืกืช ืžืคืชื— ืฆื™ื‘ื•ืจื™ ื•ืคืจื˜ื™, ืžืขื‘ื™ืจื” ืืช ื”ืžื™ื“ืข ื“ืจืš ืžืฉืชืžืฉ

.ื™ื™ืืžื•ื ื•ืืœืคื‘ืชื”ื–ื–ื” ื‘ืฆืคื ื™ืขื ืžืคืชื— ืงื‘ื•ืข ื•ื’ื XOR-ื‘ ื’ื ืžืฉืชืžืฉืช

Andromeda 2133

. RC4ื‘ืืžืฆืขื•ืช ืฆื•ืคืŸ ื”ืฆืคื ื”ืœื“ื—ื™ืกื”. Ibsenืฉืœ ื—ื‘ืจืช Aplib ื‘ืกืคืจื™ื™ืช ืžืฉืชืžืฉ

ืขืœ ืžื ืช ืœื“ืื•ื’ ืฉื”ืžื™ื“ืข ืขื‘ืจ ื‘ืชื•ื•ืš CRC32ืžืกื•ื’ ื’ื™ื‘ื•ื‘ืœื›ืœ ื”ื•ื“ืขื” ืžืฆื˜ืจืฃ

ื‘ื”ืฆืœื—ื”.

Page 22: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

22 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

Data Exfiltrationืขืฉืจืช ื”ื“ื™ื‘ืจื•ืช ืฉืœ

ืžืืžืจ 2132ื”ื™ืฉืจืืœื™ืช, ื”ื•ืฆื™ืื• ื‘ืฉื ืช SafeBreachืขืžื™ืช ืงืœื™ื™ืŸ ื•ืื™ืฆื™ืง ืงื•ื˜ืœืจ, ืฉื ื™ ื—ื•ืงืจื™ื ืžื—ื‘ืจืช

ืฉืฆืจื™ื›ื™ื ืœื”ืชืงื™ื™ื ื‘ืฉื™ื˜ื” ื•ื‘ื• ื”ื ืชื™ืืจื• ืืช ืขืฉืจืช ื”ืžืืคื™ื™ื ื™ื "Exfiltration Perfect Theืฉื ืงืจื "

ื”ืžื•ืฉืœืžืช ืœื–ืœื™ื’ืช ืžื™ื“ืข.

ื‘ื˜ื™ื—ื•ืช โ‰ : ืขืžื™ืžื•ืช 1#ื“ื™ื‘ืจ

(. ืœืขืงืจื•ืŸ ื”ื–ื” Kerckhoffsโ€™s Principle) ืงึฐืจึตืงึฐื”ื•ึนืคึฐืกื”ืฉื™ื˜ื” ื”ืžื•ืฉืœืžืช ืœื–ืœื™ื’ืช ืžื™ื“ืข ื—ื™ื™ื‘ืช ืœืขืžื•ื“ ื‘ืขืงืจื•ืŸ

ื ื•ืœื“ื• ืขื ื”ื–ืžืŸ ืžืกืคืจ ื ื™ืกื•ื—ื™ื ืฉื›ื•ืœื ืื•ืžืจื™ื ื‘ืขืจืš ืืช ืื•ืชื• ื”ื“ื‘ืจ )ืชื‘ื—ืจื• ืžื” ืฉื‘ื ืœื›ื(:

: "ืžืขืจื›ืช )ื”ืฆืคื ื”( ื—ื™ื™ื‘ืช ืœื”ื™ื•ืช ื‘ื˜ื•ื—ื” ื’ื ืื ื›ืœ (1883)ืฉืœ ืื•ื’ื•ืกื˜ื” ืงืจืงื”ื•ืคืก, ื”ื ื™ืกื•ื— ื”ืžืงื•ืจื™ .1

ื”ื—ืœืงื™ื ื‘ืžืขืจื›ืช ื™ื“ื•ืขื™ื, ืคืจื˜ ืœืžืคืชื— ื”ืกื•ื“ื™".

: "ืชื‘ื ื” ืืช ื”ืžืขืจื›ืช ืฉืœืš ืžืชื•ืš ื”ื ื—ื” ืฉืœืื•ื™ื‘ (1949ืžืงื•ืจื™ )ืฉืœ ืงืœื•ื“ ืฉืื ื•ืŸ, -ื”ื ื™ืกื•ื— ื”ืžืขื•ื‘ื“ .2

ืชืžื™ื“ ืชื”ื™ื” ื”ื™ื›ืจื•ืช ืžืœืื” ืื™ืชื”"

: "ื”ืื•ื™ื‘ ืžื›ื™ืจ ืœ ืžื™ืœื™ื ื”ืœื›ื• ืœืื™ื‘ื•ื“ ืœืื•ืจืš ื”ืฉื ื™ื(ืžืงื•ืฆืจ )ืฉืœ ืงืœื•ื“ ืฉืื ื•ืŸ, ืื‘-ื”ื ื™ืกื•ื— ื”ืžืขื•ื‘ื“ .3

ืืช ื”ืžืขืจื›ืช".

ื”ื™ื™ืฉื•ื ื‘ืกื•ื“ื™ื•ืช ืชืœื•ื™ื” ืœื”ื™ื•ืชืืžื•ืจื” ืœื ืžืขืจื›ืช ืื‘ื˜ื—ืช: "2118ืœืฉื ืช NISTื”ื ื™ืกื•ื— ืžืชื•ืš ื”ื ื—ื™ื•ืช .4

".ืžืจื›ื™ื‘ื™ื•ืกื•ื“ื™ื•ืช ื‘ ืื•

: "ืœื ื ืžืจื•ื“ )ืฉื ื‘ื“ื•ื™(, ืœืฉืžื•ืจ ื™ื—"ืœ ืกื™ื™ื‘ืจ( ื›ืชื’ื•ื‘ื” ืœืชืœืžื™ื“ 5-ื”ื ื™ืกื•ื— ืฉืœ ื›ื•ืชื‘ ื”ืžืืžืจ )ืžื•ืจื” ืœ .5

ื•ืœื”ืชืคืœืœ ืฉืœืชื•ืงืฃ ืœื ื™ื”ื™ื” ื’ื™ืฉื” ืœืงื•ื“ 2ืžืฉ ืืช ื”ืกื™ืกืžื ืฉืœื• ืขื ืงื•ื“ ืงื™ืกืจ ื‘ื”ื–ื–ื” ืฉืœ ืืฆืœ ื”ืžืฉืช

".ืœื ื ื—ืฉื‘ ืœื”ืฆืคื ื”

ืœื›ืŸ, ืขืœื™ื ื• ืœืฆืืช ืžื™ื“ื™ ื”ื ื—ื” ืฉื”ืืจื’ื•ืŸ ืžื›ื™ืจ ืืช ืฉื™ื˜ืช ื”ืขื‘ืจืช ื”ื ืชื•ื ื™ื )ืืช ื”ืขืจื•ืฅ ื”ืกืžื•ื™ ืฉื”ืฉืชืžืฉื ื• ื‘ื•

ืชืงืฉื•ืจืช ื›ื“ื™ ืœื”ืขื‘ื™ืจ ืืช ื”ื ืชื•ื ื™ื( ื•ืฉื”ื•ื ืžื•ื›ืŸ ืœืขืฆื•ืจ ืื•ืชื ื• ื‘ืจื’ืข ืฉื™ื”ื™ื” ืœื• ืื™ืžื•ืช ืฉืœื ืžื“ื•ื‘ืจ ื‘

ืœื’ื™ื˜ื™ืžื™ืช. ื”ืจืฆื™ื•ื ืœ ื”ื•ื ืฉื’ื ื‘ืžืงืจื” ื‘ื• ืฉื™ื˜ืช ื”ื”ืขื‘ืจื” ืฉืœื ื• ืžื•ื›ืจืช ืœืชื•ื›ื ื•ืช ื”ื”ื’ื ื” ื•ืœืชื•ื›ื ื•ืช ื”ื—ืกื™ืžื”,

ื”ืฉื™ื˜ื” ื ืฉืืจืช ืืคืงื˜ื™ื‘ื™ืช ื›ื™ ืœื ื ื™ืชืŸ ืœื”ื‘ื“ื™ืœ ื‘ื™ื ื” ืœื‘ื™ืŸ ืชืงืฉื•ืจืช ืœื’ื™ื˜ื™ืžื™ืช.

ื•ื ื’ื–ืจื•ืชื™ื” Web: ื™ืฉ ืœื”ืฉืชืžืฉ ืจืง ื‘ืชืงืฉื•ืจืช #2ื“ื™ื‘ืจ

( ื—ื™ื™ื‘ ืœื“ืขืช ืœืขื‘ื•ื“ ืขื ื”ืคืจื•ื˜ื•ืงื•ืœื™ื TCP/IPื›ืœ ืžื—ืฉื‘ ืฉืžื—ื•ื‘ืจ ืœืจืฉืช ื›ืœืฉื”ื™ )ืฉืžืชื‘ืกืกืช ืขืœ ืชืงืฉื•ืจืช

ื—ื™ื™ื‘ื•ืช DNSื•ื›ื•'. ื›ืคื™ ืฉืชื™ืืจืชื™ ื‘ื”ืงื“ืžื”, ืžืขืจื›ื•ืช ื‘ืกื™ืกื™ื•ืช ื›ืžื• HTTP ,DNS ,TLS/SSL -ื”ื‘ืกื™ืกื™ื™ื ื‘ื™ื•ืชืจ

DNSืœืขื‘ื•ื“ ืขืœ ืžื ืช ืฉืชื”ื™ื” ืชืงืฉื•ืจืช ืžื—ืฉื‘ื™ื ื‘ืกื™ืกื™ืช )ื—ืœ ื’ื ืขืœ ืจืฉืชื•ืช ืกื’ื•ืจื•ืช, ืคืฉื•ื˜ ืขื ืฉืจืชื™

ืคื ื™ืžื™ื™ื ืžืฉืœื”ื(.

ืจื•ื˜ื•ืงื•ืœื™ื ืฉื”ืžื—ืฉื‘ ืชื•ืžืš ื‘ื”ื )ืคืจื•ื˜ื•ืงื•ืœื™ื ื‘ืกื™ืกื™ื™ื, ื”ืฉื™ื˜ื” ื”ืžื•ืฉืœืžืช ื—ื™ื™ื‘ืช ืœื”ืฉืชืžืฉ ืจืง ื‘ืค

, FTP ,BitTorrent ,SCP ,SSHืฉืžืฉืชืžืฉ ื˜ื™ืคื•ืกื™ ื™ืขื‘ื•ื“ ืื™ืชื(, ื›ื™ ื ื•ื›ื—ื•ืชื ืฉืœ ืคืจื•ื˜ื•ืงื•ืœื™ื ืื—ืจื™ื ื‘ืจืฉืช )

Telnet ื”ืจื‘ื” ืจืฉืชื•ืช ืืจื’ื•ื ื™ื•ืช ื—ื•ืกืžื•ืช ื‘ืชื•ืจ ื‘ืจื™ืจืช ืžื—ื“ืœ -ื•ื›ื•'( ืขืœื•ืœ ืœืขื•ืจืจ ื—ืฉื“ ืจื‘. ื”ืจืฆื™ื•ื ืœ

Page 23: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

23 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ื‘ื”ื. ืฉื™ืžื•ืฉ ื‘ืคืจื•ื˜ื•ืงื•ืœื™ื ื ืคื•ืฆื™ื ืžืขืœื” ืžืฉืžืขื•ืชื™ืช ืืช ื”ืกื™ื›ื•ื™ ืคืจื•ื˜ื•ืงื•ืœื™ื ื•ืคื•ืจื˜ื™ื ืฉืื™ืŸ ืœื”ืŸ ืฉื™ืžื•ืฉ

ืฉืžื™ื“ืข ื™ื•ื›ืœ ืœืขื‘ื•ืจ ื•ืœื ืœื”ื™ื—ืกื ืขืœ ื™ื“ื™ ื—ื•ืžืช ืืฉ.

: ืื ื™ืฉ ืกืคืง, ืื™ืŸ ืกืคืง!3#ื“ื™ื‘ืจ

ื”ืฉื™ื˜ื” ื”ืžื•ืฉืœืžืช ืœื–ืœื™ื’ืช ืžื™ื“ืข ืฆืจื™ื›ื” ืœื”ื™ืžื ืข ืžื›ืœ ืคืขื™ืœื•ืช ืื• ืžืขืจื›ืช ื”ืขื‘ืจืช ื ืชื•ื ื™ื ืฉืขืœื•ืœื” ืœื”ืชืจื™ืข

ื”: ืื ื™ืฉ ืกื™ื›ื•ื™, ืืคื™ืœื• ื–ืขื™ืจ, ืฉื”ืฉื™ื˜ื” ืฉืœื›ื ืชืจืชื™ืข ืžืขืจื›ื•ืช ื”ื’ื ื”, ื’ื ืื ืจืง ืชื™ืื•ืจื˜ื™ืช )ื‘ืฆื•ืจื” ืคืฉื•ื˜

ืืœ ืชืฉืชืžืฉื• ื‘ื”(. ืื ื—ืฉื‘ืชื ืœื”ืฉืชืžืฉ ื‘ืฉืœื™ื—ืช ืžื™ื™ืœ, ื”ืขืœืื” ืœื’ื•ื’ืœ -ืžืขืจื›ืช ื”ื’ื ื” ื‘ืจืฉืช ื”ืืจื’ื•ืŸ

"ืžืขืจื›ื•ืช ื”ื”ื’ื ื” ืœื ื™ืฆืœื™ื—ื• ืœื”ื‘ื“ื™ืœ ื‘ื™ืŸ -ื“ื•ืงืก, ืฉื™ืžื•ืฉ ื‘ื˜ืงืกื˜ื™ื ืžื•ืฆืคื ื™ื ืื• ื›ืœ ื“ื‘ืจ ืฉื›ื–ื”, ื‘ืžื—ืฉื‘ื” ืฉ

ืฉื™ื˜ื” ื”ืžื•ืฉืœืžืช ืœื”ืกืชืžืš ืขืœ ื ืจืื•ืช ื”ืžื™ื“ืข ืฉืขื•ื‘ืจ ื–ื” ืœื‘ื™ืŸ ืžืฉืชืžืฉ ืœื’ื™ื˜ื™ืžื™", ืชื—ืฉื‘ื• ืฉื•ื‘. ืืกื•ืจ ืœ

ื‘ืชื•ื•ืš, ืฉื›ืŸ ืื ื—ื ื• ืจื•ืฆื™ื ืืช ื”ื™ื›ื•ืœืช ืœื”ืขื‘ื™ืจ ื›ืœ ืกื•ื’ ืžื™ื“ืข, ืœื ืžืฉื ื” ืžื” ื”ืžืจืื™ืช ืฉืœื•.

: ืžืขืจื›ื•ืช ื”ื”ื’ื ื” ืชืžื™ื“ ืžื•ืฉืœืžื•ืช4#ื“ื™ื‘ืจ

ื™ืฉ ืชืžื™ื“ ืœื”ื ื™ื— ืฉื ื™ื˜ื•ืจ ื”ืจืฉืช ื”ื•ื ืžื•ืฉืœื. ื›ืœ ื—ื‘ื™ืœื” ืขื•ื‘ืจืช ื‘ื“ื™ืงื” ืžืขืžื™ืงื”, ื‘ืคืจื•ื˜ื•ืงื•ืœื™ื ืฉื ืžืฆืื™ื

. ื›ืœ ื—ืจื™ื’ื” ืžื”ื ื•ืจืžื” ืชืชื’ืœื”. ื”ืžืขืจื›ืช ื•ื›ื•'( ,Inspection Packet DeepInspection HTTPSื‘ื›ืœ ืฉื›ื‘ื•ืชื™ื” )

ื ืžืฆืืช ื›ืจื’ืข ื‘ืชื•ืš ื”ืืจื’ื•ืŸ. ื”ืืจื’ื•ืŸ ื™ืฉืชืžืฉ ื‘ื›ืœ ื›ืœื™ ืฉื™ืฉ ืœื• ื’ื™ืฉื” ืืœื™ื• ื›ืžื• ื›ืœื™ื -ื”ื›ื™ ื˜ื•ื‘ื” ืฉืงื™ื™ืžืช

ื•ืœืžื™ื“ืช Big Data-ื•ืืฃ ืฉื™ืžื•ืฉ ื‘ื›ืœื™ื ืžืขื•ืœื ื” Whois, ื—ื™ืคื•ืฉ IP Reputationืกื˜ื˜ื™ืกื˜ื™ื™ื ืœื ื™ืชื•ื— ืชืขื‘ื•ืจื”,

ืžื›ื•ื ื”.

ื”ื“ื‘ืจ -ืช ื”ืžืขืจื›ืช, ื–ื” ืžื•ืžืœืฅ ืœืงื—ืช ืืช ื”ื’ื™ืฉื” ื”ืคืจื ื•ืื™ื“ื™ืช ื”ืจืฆื™ื•ื ืœ ืคื” ื”ื•ื ืฉื‘ืชื•ืจ ืืœื• ืฉืžื”ื ื“ืกื™ื ื

ื”ื›ื™ ื’ืจื•ืข ื™ืงืจื” ื•ื›ืœ ืžื” ืฉืขืœื•ืœ ืœื”ืฉืชื‘ืฉ, ื™ืฉืชื‘ืฉ. ื ืจืฆื” ืœื”ื ื™ื— ืฉื›ืœ ื—ื‘ื™ืœื” ื ื—ืงืจืช ื•ื ื‘ื“ืงืช ื‘ื–ืžืŸ ืืžืช,

ื’ื ืื™ื ื“ื™ื•ื•ื™ื“ื•ืืœื™ืช ื•ื’ื ื‘ื”ืงืฉืจ ืฉืœ ื”ืจืฉืช, ืฉืœ ื”ืืคืœื™ืงืฆื™ื” ื•ืฉืœ ื”ืžืฉืชืžืฉ. ืืกื•ืจ ืœื ื• ืœื”ื ื™ื— ื“ื‘ืจื™ื ื›ืžื•

. ื”ืื™ื“ื™ืืœ ืฉืœื ื• ื™ื”ื™ื” ืœื”ืจื›ื™ื‘ ื›ืœ ื—ื‘ื™ืœื” ืฉื ืฉืœื—ืช "ืขื ืคื™ื ืฆื˜ื”", "ื ื”, ืื™ืŸ ืกื™ื›ื•ื™ ืฉื”ื™ื ืชื‘ื“ื•ืง ืืช ื–ื”"

ืœืฉืœื•ื˜ ื‘ื›ืœ ื”ืขืจื›ื™ื ืฉืœื” ื›ืš ืฉืœื ื™ื”ื™ื” ืกื™ื›ื•ื™ ืฉื”ื™ื ืชืคืขื™ืœ ืžืขืจื›ื•ืช ื”ื’ื ื”.

ื–ื” ืœื ืžืกืคื™ืง! TLS/SSL: 5#ื“ื™ื‘ืจ

ืฉื ืžืฆื ื‘ื™ืŸ ืฉืชื™ ื™ื—ื™ื“ื•ืช ืงืฆื” )ื›ืžื• Proxyืฉืจืช - Termination SSLืชืžื™ื“ ื™ืฉ ืœื”ื ื™ื— ื›ื™ ื‘ืฆื“ ื”ืืจื’ื•ืŸ ืžืชื‘ืฆืข

ืฉืจืช ื•ืœืงื•ื—( ืฉืชืคืงื™ื“ื• ื”ื•ื ืœืคืขื ื— ืืช ื”ืžื™ื“ืข ื”ืžื•ืฆืคืŸ ืฉื‘ื ืžื”ืœืงื•ื— ื•ืจืง ืื– ืœื”ืขื‘ื™ืจื• ืœืฉืจืช ืขืœ ืžื ืช

Page 24: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

24 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ืฉื”ืฉืจืช ืœื ื™ืฆื˜ืจืš ืœืขืฉื•ืช ื–ืืช ื‘ืขืฆืžื• )ื•ื›ืš ื‘ืชื™ืื•ืจื™ื”, ืœืขื–ื•ืจ ืœื• ื•ืœื—ืกื•ืš ืœื• ืžืฉืื‘ื™ื(. ื”ื“ื™ื‘ืจ ืžืชื™ื™ื—ืก ืœื›ืš

-ืฉืžืฉืชืžืฉื•ืช ื‘ IDS. ื™ืฉื ืŸ ืžืขืจื›ื•ืช SSL/TLSืžื™ื“ืข ืฉื”ื•ื ืžื•ืฆืคืŸ ื‘ืืžืฆืขื•ืช ืฉื™ื™ืชื›ืŸ ืฉืœืืจื’ื•ืŸ ื™ืฉ ื’ื™ืฉื” ื’ื ืœ

SSL Termination ื‘ืฉื‘ื™ืœ ืœื ื˜ืจ ืชืงืฉื•ืจืช ืžื•ืฆืคื ืช ื‘ืชื•ืš ื”ืจืฉืช. ืžื‘ื—ื™ื ืชื ื•, ื”ืฆืคื ื” ื‘ืืžืฆืขื•ืชSSL ืื•TLS

( ืœื‘ื“ื” ืื™ื ื” ืžื’ื ื” ืขืœ ื”ืžื™ื“ืข ืฉืžื•ืขื‘ืจ.HTTPS-)ื›ืžื• ืฉื™ืžื•ืฉ ื‘

: ื”ืฆื“ ื”ืžืงื‘ืœ ื”ื•ื ืื™ื“ื™ืืœื™6#ื“ื™ื‘ืจ

ืžื—ืฉื‘ ืฉืœ ื”ืชื•ืงืฃ )ื”ืฆื“ ื”ืžืงื‘ืœ, ืฉืืœื™ื• ื™ื’ื™ืข ื”ืžื™ื“ืข( ืœื ื™ื”ื™ื” ืžื•ื’ื‘ืœ ืœืฉื•ื ื‘ืขื•ืœื ืื™ื“ื™ืืœื™, ื ืฉืืฃ ืœื›ืš ืฉื”

ืžืขืจื›ืช ืื• ืกื˜ ืฉืœ ื—ื•ืงื™ื ืฉืขืœื•ืœื™ื ืœืžื ื•ืข ืžืžื ื• ืžืœืงื‘ืœ ืืช ื”ืžื™ื“ืข ืžื”ืืจื’ื•ืŸ. ื ื’ื™ื“, ื”ืžื—ืฉื‘ ืฉืืœื™ื• ื™ื’ื™ืข

ื”ืžื™ื“ืข ืœื ืืžื•ืจ ืœื”ื™ื•ืช ื‘ื‘ื™ืช ืกืคืจ ืื• ื‘ืื•ื ื™ื‘ืจืกื™ื˜ื” ืฉืžื›ื™ืœื™ื ื—ื•ืงื™ ืจืฉืช ื ื•ืงืฉื™ื. ื”ืžื—ืฉื‘ ืฉืœ ื”ืชื•ืงืฃ ืžื•ื›ืŸ

ื˜, ื”ื•ื ื™ืงื‘ืœ ื›ืœ ืžื™ื“ืข ืœื’ื™ื˜ื™ืžื™ ืฉืžื•ืขื‘ืจ ืืœื™ื• ื•ืœื ื™ืขื‘ื™ืจ ืื•ืชื• ื“ืจืš ืฉื•ื ื—ื•ืžืช ืืฉ ืœืงื‘ืœ ืžื™ื“ืข ื‘ื›ืœ ืคื•ืจ

ื•ื•ื™ืจื•ืก ืžื˜ืขืžื•. ื™ื—ื™ื“ืช ื”ืงืฆื” ืฉืœ ื”ืชื•ืงืฃ ืชื›ื™ืœ ืชื•ื›ื ื” ืจื•ื‘ืกื˜ื™ืช ื•ืขืžื™ื“ื”, ืฉืœื ืชืงืจื•ืก -ื ื•ืกืคืช ืื• ืชื•ื›ื ืช ืื ื˜ื™

ื‘ืฉื•ื ืžืงืจื”, ืชืชืขื“ ื›ืœ ื—ื‘ื™ืœื” ื ื›ื ืกืช ื•ื‘ืฉื•ื ื“ืจืš ืœื ืชื”ื•ื•ื” ืžื›ืฉื•ืœ ืœืฉื™ื˜ืช ื–ืœื™ื’ืช ื”ืžื™ื“ืข.

ืœื ืžื•ืคื™ืข ื‘ืจืฉื™ืžื•ืช ืฉืœ ื‘ื•ื˜ื™ื ืื• -ืฃ ืœื”ื™ื•ืช ื›ืžื” ืฉื™ื•ืชืจ ืœื’ื™ื˜ื™ืžื™ ื‘ืขื™ื ื™ ื”ืื™ื ื˜ืจื ื˜ ื”ืฆื“ ื”ืžืงื‘ืœ ืฆืจื™ืš ืœืฉืื•

ื’ื‘ื•ื” ื•ืฉื”ื•ื Alexaื˜ื•ื‘. ืื ืžื“ื•ื‘ืจ ื‘ื“ื•ืžื™ื™ืŸ, ืื– ืฉื”ื•ื ืืžื™ืŸ ืขื ื“ื™ืจื•ื’ IP Reputationืกืคืืžื™ื, ืฉื™ืฉ ืœื•

ื ืจืื” ืœื’ื™ื˜ื™ืžื™.

: "ื”ืฉื’ื—ืช ืฆื“ ืฉืœื™ืฉื™" ืœื ืžื“ื‘ืจ ืืœื™ื™7#ื“ื™ื‘ืจ

ื›ืžื• ื”ืื™ื ื˜ืจื ื˜ ืฉืœ ืกื™ืŸ(, ืื• ื‘ืจืžืช "ืฆื“ ืฉืœื™ืฉื™" )ื›ืžื• ื ื™ื˜ื•ืจ ืžื—ื•ืฅ ืœืืจื’ื•ืŸ, ืื™ืŸ ื ื™ื˜ื•ืจ ืจืฉืช ื‘ืจืžื” ืืจืฆื™ืช )

ื‘ืจืžืช ืกืคืง ื”ืื™ื ื˜ืจื ื˜(. ืžื”ืจื’ืข ืฉื”ื—ื‘ื™ืœื” ืขื•ื–ื‘ืช ืืช ื”ื ืชื‘ ื”ืจืืฉื™ ืฉืœ ื”ืืจื’ื•ืŸ, ื”ื™ื ื™ื›ื•ืœื” ืœืœื›ืช ืœื›ืœ

ืžืงื•ื ื‘ืื™ื ื˜ืจื ื˜ ืœืœื ื‘ื“ื™ืงื” ื ื•ืกืคืช. ืขื ื–ืืช, ืื ื—ื ื• ื›ืŸ ื™ื•ืฆืื™ื ืžื™ื“ื™ ื”ื ื—ื” ืฉื”ืืจื’ื•ืŸ ืžื™ื™ืฉื ืžืขืจื›ื•ืช ืฉื•ื ื•ืช

(.1ืจ #ืœื ื™ื˜ื•ืจ ื•ืื‘ื˜ื—ืช ื”ืจืฉืช )ืจืื”: ื“ื™ื‘

ื”ืื‘ื˜ื—ื” ืฉืœ ื”ืืจื’ื•ืŸ ืขืฆืžื•. -ื›ืš ืื ื—ื ื• ืžืชืจื›ื–ื™ื ื‘ืžื” ืฉื—ืฉื•ื‘

: ื™ืฉ ืกื ื›ืจื•ืŸ ื–ืžืŸ ื‘ื™ืŸ ื”ืฆื“ื“ื™ื ื”ืžืชืงืฉืจื™ื8#ื“ื™ื‘ืจ

ืืคืฉืจ ืœื”ื ื™ื— ื›ื™ ื™ืฉ ืกื ื›ืจื•ืŸ ื–ืžืŸ ื‘ื™ืŸ ื”ืฆื“ื“ื™ื ืฉืžืชืงืฉืจื™ื )ื‘ื”ื‘ื“ืœ ืฉืœ ืฉื ื™ื•ืช ื‘ื•ื“ื“ื•ืช ืœื›ืœ ื”ื™ื•ืชืจ(. ื”ื“ื™ื‘ืจ

. ืžื—ืฉื‘ื™ื ืืžื•ืจื™ื ืœื“ืขืช 2123ื–ื” -ื”ื–ื” ืงืจื™ื˜ื™ ื‘ืขื™ืงืจ ื‘ื—ืœืง ืžื”ืขืจื•ืฆื™ื ื”ืกืžื•ื™ื™ื ืฉืžื‘ื•ืกืกื™ื ืขืœ ื–ืžืŸ. ื•ื’ื

ื›ื‘ืจ ืื™ืš ืœื”ื™ื•ืช ืžืกื•ื ื›ืจื ื™ื ืขื ืžืงื•ืจ ื–ืžืŸ ืืžื™ืŸ.

)ืื•ืคืฆื™ื•ื ืœื™(: ื”ืฉื™ื˜ื” ืฆืจื™ื›ื” ืœื“ืขืช ื’ื ืœืขื‘ื•ื“ ื™ื“ื ื™ืช )ืœืœื ื›ืœ ืชื•ื›ื ื”( 9#ื“ื™ื‘ืจ

-ื”ืฉื™ื˜ื” ื”ืžื“ื•ื‘ืจืช ืฆืจื™ื›ื” ืœืขื‘ื•ื“ ื’ื ืื ืื™ืŸ ืชื•ื›ื ื” ืžืขื•ืจื‘ืช )ื•ื’ื ืœื”ืฉืชื“ืœ ืฉืœื ืœืขืจื‘ ืชื•ื›ื ื•ืช ืœื

ื™ืฉ ืžืฉืช"ืค ืžืชื•ืš ื”ื—ื‘ืจื” ืฉื™ื”ื™ื” ืžื•ื›ืŸ ืœืขืฉื•ืช ื›ืจืฆื•ื ื ื• ืขืœ (. ื™ืฉื ื ืžืงืจื™ื ืฉื‘ื”ื ื‘ืžืงื•ื ื ื•ื–ืงื”, ืชืกื˜ื ื“ืจื˜ื™ื•

ืžื—ืฉื‘ื™ ื”ืืจื’ื•ืŸ, ืืš ืœื ื™ื›ื•ืœ ืœื”ื›ื ื™ืก ืชื•ื›ื ื•ืช ื—ื™ืฆื•ื ื™ื•ืช ืฉืœื ื›ื‘ืจ ืžื•ืชืงื ื•ืช )ื ื•ื‘ืข ืžืžื“ื™ื ื™ื•ืช ื‘ื™ื˜ื—ื•ืŸ ืžื™ื“ืข

ื—ืกื•ืžื™ื(. ื‘ืžืงืจื” ื›ื–ื”, ื”ืžืฉืช"ืค ื™ืฆื˜ืจืš ืœื”ืคืขื™ืœ ืืช ื”ืฉื™ื˜ื” ืฉืœื ื• ื‘ืื•ืคืŸ ื™ื“ื ื™, USBืงืœืืกื™ืช ื›ืžื• ื—ื™ื‘ื•ืจื™

ืชืงื ื™ื ื‘ืžืขืจื›ืช ื”ื”ืคืขืœื”.ื‘ืืžืฆืขื•ืช ื”ื›ืœื™ื ืฉื™ืฉ ื‘ืจืฉื•ืชื•, ื”ืžื•

Page 25: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

25 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

Commandื›ืœ ืื—ื“ ื™ื›ื•ืœ ืœืคืชื•ื— -ืฉืชื™ืืจืชื™ ืžืขืœื” ื›ืŸ ืขื•ื ื” ืขืœ ื”ื“ื™ื‘ืจ ื”ื–ื” pingื”ืฉื™ื˜ื” ืฉืœ ืคืงื•ื“ืช

Prompt ืื• ื˜ืจืžื™ื ืœ ื•ืœื”ืชื—ื™ืœ ืœืฉืœื•ื— ื—ื‘ื™ืœื•ืชICMP ืœืœื ืงื•ื“ ืื• ืชื•ื›ื ื” ืฉื”ื•ื ื—ื™ื™ื‘ ืœื”ื—ื“ื™ืจ -ืืœ ื”ืชื•ืงืฃ

ืžืœื›ืชื—ื™ืœื”.

: ืฉื™ื‘ื•ืฉ ืืงื˜ื™ื‘ื™ ื–ื” ืื•ืคืฆื™ื”11#ื“ื™ื‘ืจ

ืฉืจืฉืช ื”ืืจื’ื•ืŸ ืชื‘ืฆืข ืฉื™ื‘ื•ืฉ ืืงื˜ื™ื‘ื™ ืœื ืชื•ื ื™ื ื”ืžื•ืขื‘ืจื™ื ื‘ืžื˜ืจื” ืœืขืฆื•ืจ ืืช ื™ืฉ ืืคืฉืจื•ืช ืœื ืžื‘ื•ื˜ืœืช

ื”ืขืจื•ืฅ ื”ืกืžื•ื™. ื”ืฉื™ื‘ื•ืฉ ื”ืืงื˜ื™ื‘ื™ ื™ื›ื•ืœ ืœื”ื™ื•ืช ื›ืœ ื“ื‘ืจ ืžืžื ื™ืคื•ืœืฆื™ื” ืฉืœ ืฉื“ื•ืช ื‘ื—ื‘ื™ืœื•ืช ืื• ื‘ืชื•ื›ื ืŸ, ื”ืคืœืช

ื–ื” ืฉื”ืžืขืจื›ื•ืช ื‘ืืจื’ื•ืŸ ืœื -ื—ื‘ื™ืœื•ืช ืฉืžื’ื™ืขื•ืช ืžืชื”ืœื™ืš ืžืกื•ื™ื ื•ื›ื•'. ื‘ื“ื•ืžื” ืœื‘ืขื™ื™ืช ื”ืืกื™ืจื™ื ืœืžืขืœื”

ื•ื™, ืœื ืžื•ื ืข ืžื”ืŸ ืžืœื”ืจื•ืก ืื•ืชื•.ืžื•ืฆืื•ืช ืžื” ื”ืขืจื•ืฅ ื”ืกืž

ื—ื•ืงื™ื ื ื•ืขื“ื• ืฉื™ืฉื‘ืจื• ืื•ืชื?

ื ืกื›ื™ื ืขืœ ื›ืš ืฉื”ื“ื™ื‘ืจื•ืช ื”ืžืชื•ืืจื•ืช ื ืฉืžืขื•ืช ืžืื•ื“ ืงื™ืฆื•ื ื™ื•ืช, ืืš ื”ืŸ ืžืฉืžืฉื•ืช "ืกืคืจ ื”ื“ืจื›ื”" ื™ืขื™ืœ

ื›ืฉืื ื—ื ื• ืžืชื—ื™ืœื™ื ืœืคืชื— ืฉื™ื˜ื” ืœื–ืœื™ื’ืช ืžื™ื“ืข. ื‘ืืจื’ื•ื ื™ื ื’ื“ื•ืœื™ื ื‘ืขืœื™ ืื‘ื˜ื—ื” ื˜ื•ื‘ื”, ื ื•ื›ืœ ืœื™ื™ืฉื ื”ืจื‘ื” ืžืŸ

ื‘ื” ืฉืชื”ื™ื” ืขืžื™ื“ื”. ืœืขื•ืžืช ื–ืืช, ื‘ืืจื’ื•ื ื™ื ื‘ื™ื ื•ื ื™ื™ื ืื• ืงื˜ื ื™ื, ื ื•ื›ืœ ืœื™ื™ืฉื ื”ื“ื™ื‘ืจื•ืช ื‘ืฉื‘ื™ืœ ืœื™ืฆื•ืจ ืฉื™ื˜ื” ื˜ื•

ื—ืœืง ืžืŸ ื”ื“ื™ื‘ืจื•ืช )ื›ื™ ื™ื™ืฉื•ื ืฉืœ ื™ื•ืชืจ ืžื›ืš ื™ื”ื™ื” ื‘ื–ื‘ื•ื– ืžืฉื•ื•ืข ืฉืœ ื–ืžืŸ ื•ืฉืœ ื”ืžืฉืื‘ื™ื ืฉืขื•ืžื“ื™ื ืœืจืฉื•ืชื ื•(.

Page 26: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

26 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

(Data Exfiltrationื“ื•ื’ืžืื•ืช ืœืฉื™ื˜ื•ืช ืœื–ืœื™ื’ืช ืžื™ื“ืข )

ืจืฉื™ืžื” ืžืœืื” ืฉืœ ื›ืœ ื”ืฉื™ื˜ื•ืช ืœื‘ื™ืฆื•ืข ืื—ืช ื”ื‘ืขื™ื•ืช ืฉืขืœื• ื‘ืขืช ื›ืชื™ื‘ืช ื”ืžืืžืจ ื”ื–ื” ื”ื™ื ืฉืœื ืงื™ื™ืžืช

ื–ืœื™ื’ืช ืžื™ื“ืข. ื”ืกื™ื‘ื” ืœื›ืš ื”ื™ื ื›ื™ ื™ืฉื ืŸ ืื™ื ืกื•ืฃ ื›ืืœื”, ื•ื”ืŸ ืžื•ื’ื‘ืœื•ืช ืจืง ืขืœ ื™ื“ื™ ื”ื“ืžื™ื•ืŸ ื•ื”ื™ื›ื•ืœื•ืช ืฉืœ ื”ืชื•ืงืคื™ื.

ื›ืขืช, ืืฆื™ื’ ืขื ื–ืืช, ืžืจื‘ื™ืชืŸ ื™ืกืชืžื›ื• ืขืœ ืคืจื•ื˜ื•ืงื•ืœื™ ืชืงืฉื•ืจืช ืžื‘ื•ืกืกื™ื ื•ืงื™ื™ืžื™ื, ืื• ืขืœ ืขืงืจื•ื ื•ืช ื‘ืกื™ืกื™ื™ื.

ื”ื™ื• ื‘ืฉื™ืžื•ืฉ ื‘ืขื‘ืจ ืขืœ ื™ื“ื™ ื ื•ื–ืงื•ืช, ื•ื—ืœืงืŸ ื›ื‘ืจ ืœื ืจืœื•ื•ื ื˜ื™ื•ืช ื›ื™ื•ื. ื—ืœืงืŸ -ืžืกืคืจ ืฉื™ื˜ื•ืช ืœื‘ื™ืฆื•ืข ื–ืœื™ื’ืช ืžื™ื“ืข

ื”ืžื˜ืจื” ืฉืœ ื”ื—ืœืง ื”ื–ื” ื‘ืžืืžืจ ื”ื™ื ืœืชืช ืœื›ื ื”ืฉืจืื” ื•ื›ืžื• ื›ืŸ ื’ื ื›ืœื™ื ื‘ืกื™ืกื™ื™ื ืฉื‘ื”ื ืชื•ื›ืœื• ืœื”ืฉืชืžืฉ

ื”ืขืงืจื•ื ื•ืช ื”ื‘ืกื™ืกื™ื™ื ื”ืžื•ื“ื’ืžื™ื ื‘ืฉื™ื˜ื•ืช ื”ืœืœื• ื™ื›ื•ืœื™ื ืœื”ืชืงื™ื™ื -ื›ื“ื™ ืœื™ืฆื•ืจ ืฉื™ื˜ื•ืช ื–ืœื™ื’ื” ืžืฉืœื›ื. ื–ื›ืจื•!

ืกืžื•ื™.ื‘ื›ืœ ืคืจื•ื˜ื•ืงื•ืœ ืื• ืขืจื•ืฅ

IPv4( ื‘ืคืจื•ื˜ื•ืงื•ืœ Type of Service) TOS -ืฉื™ื ื•ื™/ื”ื•ืกืคืช ืฉื“ื” -ืขืจื•ืฅ ืกืžื•ื™ ืžื‘ื•ืกืก ืื—ืกื•ืŸ

ืขื‘ื•ืจ ื”ื’ื“ืจืช ืื™ื›ื•ืช ืฉื™ืจื•ืช. TOS ื•ืชืฉื ืงืจื ืกื™ื‘ื™ื•ืช 9( ืžืงืฆื” IPืคืจื•ื˜ื•ืงื•ืœ ื”ืื™ื ื˜ืจื ื˜ ), RFC1349-ื›ืžื•ื’ื“ืจ ื‘

ื”ื™ื ื ืขื‘ื•ืจ ื”ื’ื“ืจืช ืงื“ื™ืžื•ืช, ื›ืœื•ืžืจ ื›ื›ืœ ืฉื”ืขืจืš ื’ื‘ื•ื” ื™ื•ืชืจ 1-1ื”ื‘ื™ื˜ื™ื ื”ืจืืฉื•ื ื™ื ื”ืžื™ื™ืฆื’ื™ื ืขืจื›ื™ื ืฉืœ 1

ื”ื™ื”ืฉื”ื™ ืžื”ื•ื•ื™ื ืฉื™ืœื•ื‘ ื‘ื™ืŸ ืžื—ื™ืจ, TOSื‘ืฉื“ื” ื•ืชื”ื‘ืื”ืกื™ื‘ื™ื•ืช 1ืขืจื›ื™ ื›ืš ื”ืจืฉืช ื ื•ืชื ืช ืงื“ื™ืžื•ืช ืœื—ื‘ื™ืœื”.

(delay) :ื•ืืžื™ื ื•ืช. ืœื“ื•ื’ืžื”

1111 - ืื™ื›ื•ืช ืฉื™ืจื•ืช ืจื’ื™ืœื”

1113 - ืžื—ื™ืจ ื ืžื•ืš

1131 - ื›ื•ืช ื’ื‘ื•ื”ื”ืื™

3111 - ื”ืฉื”ื™ื™ื” ื ืžื•ื›ื”

.1ื—ื™ื™ื‘ ืœื”ื™ื•ืช ื‘ืขืœ ืขืจืš TOSื”ื‘ื™ื˜ ื”ืื—ืจื•ืŸ ื‘ืฉื“ื”

ืžืกืคืจ ืžื—ืงืจื™ื ื”ืฆื™ืขื• ืืช ื”ืฉื“ื” ื”ื–ื” ื‘ืชื•ืจ ืขืจื•ืฅ ืกืžื•ื™. ืขื‘ื•ืจ ื›ืœ ื—ื‘ื™ืœื” ืฉื ืฉืœื—ืช, ืชื•ืงืฃ ื™ื›ื•ืœ ืœื ืฆืœ ืืช ื›ืœ

ื›ื“ื™ ืœื ืœืขื•ืจืจ ื—ืฉื“ 1ืกื™ื‘ื™ื•ืช( ืื• ืœื ืฆืœ ื—ืœืง ืžืžื ื• )ื›ืžื• ืœื”ืฉืื™ืจ ืืช ื”ืกื™ื‘ื™ืช ื”ืื—ืจื•ื ื” 9ื”ืฉื“ื” )

ืกื™ื‘ื™ื•ืช(. ืขื ื–ืืช, ื™ืฉื ื ืžืกืคืจ ื—ืกืจื•ื ื•ืช ืœืฉื™ื˜ื”: 1-ื•ืœื”ืฉืชืžืฉ ืจืง ื‘

. ื‘ื ื•ืกืฃ, ืขื™ื•ื•ืช ืฉืœ ื‘ืกืคืง ืฉื”ื™ื ืฉื™ื˜ื” ืจืœื•ื•ื ื˜ื™ืช ืœื”ื™ื•ืืžืื– ืฉื”ืฉื™ื˜ื” ื”ื–ื• ื”ืชื’ืœืชื” )ืœืคื ื™ ืขืฉื•ืจ(, ืื ื™ .1

ื›ืžืขื˜ ืชืžื™ื“ ืฉื•ืœื—ื™ื ืืช Windowsืžื—ืฉื‘ื™ื ืขื -ื”ืฉื“ื” ื”ื–ื” ื”ื•ื ื‘ืจื•ืจ ื‘ื™ื•ืชืจ ื‘ืกื‘ื™ื‘ื•ืช ืžืกื•ื™ืžื•ืช

.TOS-ื‘ 1ื”ืขืจืš

ื•ื›ืš ืœื—ืกืœ ืœื—ืœื•ื˜ื™ืŸ 1ื›ืš ืฉื™ื”ื™ื” ืขื ื”ืขืจืš ืืช ื”ืขืจืš ืฉืœ ื”ืฉื“ื”ื™ื›ื•ืœื•ืช ืœื“ืจื•ืก ืฉื™ื ื•ื™ ื”ื’ื“ืจื•ืช ื‘ืจืฉืช .2

ืืช ื”ืขืจื•ืฅ ื”ืกืžื•ื™.

, ื•ืœื ื ื™ืชืŸ ืœื‘ืฆืข ื–ืืช ื‘ืœืขื“ื™ื”. ื–ื” ืขืœื•ืœ ืœื”ื™ื•ืช ื‘ืขื™ื™ืชื™ ืื ื“ื•ืจืฉ ืชื•ื›ื ื” ื™ื™ื—ื•ื“ื™ืชืฉื™ื ื•ื™ ืฉืœ ื”ืฉื“ื” ื”ื–ื” .3

ืขืœ ื”ืžืขืจื›ืช ืฉืœ ื”ืฉื•ืœื—. DLPืžื•ืชืงื ื™ื ืคืชืจื•ื ื•ืช

Page 27: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

27 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ืจ(. ื‘ืžืงื•ื ื”ื”ื’ื“ืจื” )ืื ื›ื™ ื ืชืžืš ื—ืœืงื™ืช ืžืคืืช ืชืื™ืžื•ืช ืœืื—ื•ืื™ื ื• ืจืœื•ื•ื ื˜ื™ ื”ืฉื“ื” ื”ื–ื” ื›ื‘ืจ .4

ื”ืกื™ื‘ื™ื•ืช ื”ืจืืฉื•ื ื•ืช ื”ืŸ 2 -ื”ื ื•ื›ื—ื™ืช, ืžื—ืœืงื™ื ืžื—ื“ืฉ ืืช ื”ืฉื“ื” ื”ื–ื” ืœืฉื ื™ ืฉื“ื•ืช ืฉื•ื ื™ื

Point Code Services Differentiated ืžื•ื’ื“ืจ ื‘(-RFC2474ืฉืขื•ื“ ืชื•ืžืš ื‘ืคื•ืจืžื˜ ื”ื™ืฉืŸ, ื• )-ื”ืกื™ื‘ื™ื•ืช 2

( ืฉืื™ื ื• ืชื•ืžืš ื‘ืคื•ืจืžื˜ ื”ื™ืฉืŸ.RFC3168-)ืžื•ื’ื“ืจ ื‘ Notification Congestion icitExplื”ืื—ืจื•ื ื•ืช ื”ืŸ

IPv4( ื‘ืคืจื•ื˜ื•ืงื•ืœ Identification) IP-IDืฉื“ื” -ืฉื™ืžื•ืฉ ื‘ืžื•ื ื”/ืกื•ืคืจ -ืขืจื•ืฅ ืกืžื•ื™ ืžื‘ื•ืกืก ืชื–ืžื•ืŸ

ืกื™ื‘ื™ื•ืช, ืฉืžืฉืžืฉ ื‘ืžืงื•ืจ 32ื‘ื’ื•ื“ืœ Identificationืœืฉื“ื” ื”ืฆื™ืข ืฉื™ืžื•ืฉ George Danezis, 2119ื‘ืฉื ืช

(, ื‘ืชื•ืจ ืฉื“ื” ืคื•ื˜ื ืฆื™ืืœื™ ืœื‘ื™ืฆื•ืข ื–ืœื™ื’ืช ืžื™ื“ืข. tationFragmen IPืœืฆืจื›ื™ ื—ืœื•ืงื” ื•ื”ืจื›ื‘ื” ืžื—ื“ืฉ ืฉืœ ื—ื‘ื™ืœื•ืช )

ื”ืžื˜ืจื” ืฉืœ ื”ืฉื“ื” ื”ื–ื” ื”ื™ื ืœืชืช ืœื—ื‘ื™ืœื•ืช ืขืจื›ื™ื ื™ื™ื—ื•ื“ื™ื™ื ื›ืš ืฉื™ื”ื™ื” ื ื™ืชืŸ ืœื”ืจื›ื™ื‘ ืื•ืชื ืžื—ื“ืฉ ื‘ืžืงืจื”

ื›ืœ ืคืขื ืฉื”ื•ื ืžื•ืฆื™ื ื—ื‘ื™ืœื”, ืžืกืคืจ ื”ื–ื™ื”ื•ื™ ืฉื”ื•ื ื ื•ืชืŸ ืœื• ืขื•ืœื” ื‘ืื—ื“ -ื”ืฆื•ืจืš. ื“ืจืš ื”ืคืขื•ืœื” ืฉืœื• ืคืฉื•ื˜ื”

ื•ื‘ืจื•ืช ื“ืจื›ื• ื™ืฉ ืžืกืคืจ ื™ื™ื—ื•ื“ื™ ื›ืœืฉื”ื•(.ืืœืฃ ื—ื‘ื™ืœื•ืช ืฉืข 25)ื•ื›ืš ืžื‘ื˜ื™ื— ืฉืœื›ืœ

', 3ื›ืœ ืคืขื ืฉื”ืฉื•ืœื— ืจื•ืฆื” ืœื”ืขื‘ื™ืจ ืืช ื”ื‘ื™ื˜ ' - Scan Idle-ื”ื‘ืกื™ืก ืžืื—ื•ืจื™ ื”ืชืงืฉื•ืจืช ื”ื–ื• ืžืื•ื“ ื“ื•ืžื” ืœ

ื•ื ืžืงื‘ืœ ืœื ืžืฉื ื” ื”ืชื•ื›ืŸ(. ื”ืชื’ื•ื‘ื” ืฉื” - HTTPืชืงืฉื•ืจืช -)ื‘ื“ื•ื’ืžื” ืœืžืขืœื” IPื”ื•ื ืฉื•ืœื— ืœืฉืจืช ื—ื‘ื™ืœืช

)ื›ืš ืฉืชืงืฉื•ืจืช ืฉืชื’ื™ืข ื‘ืขืชื™ื“ ืœื ืชืงื‘ืœ ืืช ืื•ืชื• ืžืกืคืจ ื›ืžื• 3-ื‘ IP-ID-ื’ื•ืจืžืช ืœืฉืจืช ืœื”ืขืœื•ืช ืืช ืขืจืš ื”

', ื”ื•ื ืœื ืฉื•ืœื— ื›ืœื•ื ืœืฉืจืช 1ื™ื™ื—ื•ื“ื™ื•ืช(. ืื ื”ืฉื•ืœื— ืจื•ืฆื” ืœื”ืขื‘ื™ืจ ืœืžืงื‘ืœ ืืช ื”ื‘ื™ื˜ ' -ื”ื—ื‘ื™ืœื” ื”ื ื•ื›ื—ื™ืช

'.1' ื•ืœืื—ืจ ืžื›ืŸ ืฉืœื™ื—ื” ืฉืœ ื‘ื™ื˜ '3ืžืœื›ืชื—ื™ืœื”. ื‘ืชืžื•ื ื”: ืฉืœื™ื—ื” ืฉืœ ื‘ื™ื˜ '

ืขืœ ื™ื“ื™ ื’ื™ืฉื” ืœืฉืจืช, ื•ื‘ื•ื“ืง ื”ืื ื”ืขืจืš ืฉื”ื•ื ืžืงื‘ืœ IP-ID-ืฆื™ื“ื•, ื‘ื•ื“ืง ื‘ื–ืžื ื™ื ืงื‘ื•ืขื™ื ืืช ืขืจืš ื”ื”ืชื•ืงืฃ, ืž

ืžื”ืขืจืš ื”ืื—ืจื•ืŸ ืฉื”ื•ื ืงื™ื‘ืœ. ืื ื”ืขืจืš 2-ืื• ื‘ 3-ื’ื“ื•ืœ ื‘

ืžื”ืขืจืš ื”ืื—ืจื•ืŸ ื”ื™ื“ื•ืข ืœื•, ืื– ืืฃ ืื—ื“ 3-ืฉื”ื•ื ืงื™ื‘ืœ ื’ื“ื•ืœ ื‘

'. 1ืœื ื‘ื™ืฆืข ื‘ืงืฉื•ืช ืœืฉืจืช ื‘ื–ืžืŸ ื”ื–ื” ื•ื”ืฉื•ืœื— ืžืชื›ื•ื•ืŸ ืœืขืจืš '

ืžื”ืขืจืš ื”ืื—ืจื•ืŸ ืฉื™ื“ื•ืข 2-ื‘ืœ ื’ื“ื•ืœ ื‘ืื•ืœื, ืื ื”ืขืจืš ืฉื”ื•ื ืงื™

ืœื•, ืื– ื‘ื™ืŸ ื”ืจื’ืข ืฉื‘ื• ื”ื•ื ื”ืชื—ื‘ืจ ืœืื—ืจื•ื ื” ื•ืขื“ ืœื”ื•ื•ื”,

ืžืฉืชืžืฉ ื ื•ืกืฃ ืฉืœื— ื‘ืงืฉื” ืœืฉืจืช )ื‘ื”ื ื—ื” ืฉื”ืฉื•ืœื— ื•ื”ืžืงื‘ืœ

ื”ื ืฉื ื™ ื”ืžื—ืฉื‘ื™ื ื”ื™ื—ื™ื“ื™ื ืฉื ื™ื’ืฉื™ื ืœืฉืจืช, ื–ื” ืื•ืžืจ

'(.3ืฉื”ืฉื•ืœื— ื‘ื™ืฆืข ื‘ืงืฉื” ืœืฉืจืช, ืžืกืžืŸ ืืช ื”ืขืจืš '

ื•ื’ืžื” ื”ื˜ืงื˜ื™ืงื” ื”ื–ื• ื ื—ืฉื‘ืช ืœืฉื™ืคื•ืจ ืžืฉืžืขื•ืชื™ ื‘ื”ืฉื•ื•ืื” ืœื“

ืฉืœ IP-, ื‘ืขื™ืงืจ ื‘ื’ืœืœ ืฉืื™ืŸ ื‘ื” ืชืงืฉื•ืจืช ื™ืฉื™ืจื” ืืœ ื”TOSืฉืœ

ื”ืชื•ืงืฃ. ื‘ืžืงื•ื, ืฉืจืช ืคื•ืคื•ืœืจื™ ืฆื“ ืฉืœื™ืฉื™ )ื›ืžื• ืืชืจ ื—ื“ืฉื•ืช ืœื“ื•ื’ืžื”( ื™ื›ื•ืœ ืœื”ื™ื•ืช ื‘ืฉื™ืžื•ืฉ, ื›ืœ ืขื•ื“ ื”ืฉืจืช

ื‘ืื—ื“. IP-IDืžื›ื™ืœ ืืช ื”ื™ื›ื•ืœืช ืœื”ื’ื“ื™ืœ ืขืจืš ื’ืœื•ื‘ืืœื™ ืฉืœ

Page 28: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

28 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ืขืœื” ื”ื’ื“ื•ืœื•ืช ื ื•ืงื˜ื•ืช ื‘ืื—ื“ , ืืš ื”ื™ื•ื ื›ืœ ืžืขืจื›ื•ืช ื”ื”ืค2119ื”ืฉื™ื˜ื” ื”ื–ื• ื”ื™ื™ืชื” ืื•ืœื™ ืจืœื•ื•ื ื˜ื™ืช ื‘ืฉื ืช

ืžื”ืฆืขื“ื™ื ื”ื‘ืื™ื ื‘ืชื•ืจ ื‘ืจื™ืจืช ืžื—ื“ืœ:

ื™ืฆื™ืจืช ืขืจืšIP-ID .ืฉืžื‘ื•ืกืก ืขืœ ืคื•ื ืงืฆื™ื” ืงืจื™ืคื˜ื•ื’ืจืคื™ืช

ื™ืฆื™ืจืช ืขืจืšIP-ID ืฉื•ื ื” ืœื›ืœ ืชืงืฉื•ืจืช ื‘ื ืคืจื“ )ื”ืกืคื™ืจื” ื‘ื™ืŸ ื”ืฉืจืช ืœื‘ื™ืŸ ื”ืฉื•ืœื— ื”ื™ื ืœื ืื•ืชื” ืกืคื™ืจื”

ืœื ืกืคื™ืจื” ื’ืœื•ื‘ืืœื™ืช(. -ื›ืžื• ื‘ื™ืŸ ื”ืฉืจืช ืœื‘ื™ืŸ ื”ืžืงื‘ืœ

ืš ืงื‘ื•ืข(, ื›ืžื• ืœืคื™ ืฉืœื™ื—ืช ื—ื‘ื™ืœื•ืช ืื˜ื•ืžื™ื•ืช )ืขืจRFC6864ืฉืžื’ื“ื™ืจ ืฉ ,-IP-ID ื™ื›ื•ืœ ืœื”ื™ื•ืช ื‘ืขืœ ื›ืœ ืขืจืš

ื•ืœื›ืŸ ืžืื•ืคืก ืจื•ื‘ ื”ื–ืžืŸ.

ื”ื–ื” ืžืœื‘ื“ ื”ืฆื“ื“ื™ื ื”ืžืชืงืฉืจื™ื. ืžืกืชืžื›ืช ืขืœ ื›ืš ืฉืืฃ ืื—ื“ ืœื ื™ืฉืชืžืฉ ื‘ืขืจื•ืฅื‘ื ื•ืกืฃ ืœื›ืš, ื”ืฉื™ื˜ื” ื”ื–ื•

ืื• ื›ืœ ื›ืœื™ ืื•ื˜ื•ืžื˜ื™ ืื—ืจ ื™ื‘ืฆืข ื‘ืงืฉื” ืœืฉืจืช )ื‘ื™ืŸ ืื ื‘ื˜ืขื•ืช ืื• ื‘ื›ื•ื•ื ื”( ืขืœ ืžื ืช scrapperืžืกืคื™ืง ืฉื‘ื•ื˜,

ืฉื”ืชืงืฉื•ืจืช ืชื”ื™ื” ืžืœืื” ื‘ื˜ืขื•ื™ื•ืช )ืื™ืŸ ืขืžื™ื“ื•ืช ืœืจืขืฉื™ื ื‘ืชืงืฉื•ืจืช(.

(URL Shortenersืฉื™ืžื•ืฉ ื‘ืžืงืฆืจื™ ืœื™ื ืงื™ื ) - ืฉื™ืžื•ืฉ ื‘ืžื•ื ื”/ืกื•ืคืจ -ืขืจื•ืฅ ืกืžื•ื™ ืžื‘ื•ืกืก ืชื–ืžื•ืŸ

ืฉื™ืฉ ืœื”ื ืืช ื”ื™ื›ื•ืœืช ืœืฉืžื•ืจ ื•ืœื”ืฆื™ื’ ืืช ื›ืžื•ืช URLื”ืฉื™ื˜ื” ื”ื‘ืื” ืžื‘ื•ืกืกืช ืขืœ ืฉื™ืจื•ืชื™ ืงื™ืฆื•ืจ ื›ืชื•ื‘ื•ืช

ื‘ื“ื•ื’ืžื” ืฉืœื™, ืื‘ืœ ื”ืฉื™ื˜ื” ื”ื–ืืช ื—ืœื” ื’ื bit.ly-ืจื‘ื”(. ืืฉืชืžืฉ ื‘ื”ื›ื ื™ืกื•ืช ืœื›ืœ ืงื™ืฉื•ืจ )ืชื›ื•ื ื” ื ืคื•ืฆื” ืœื”

ืขืœ ืฉื™ืจื•ืชื™ื ื ื•ืกืคื™ื ืขื ื”ืชืืžื•ืช ืงืœื•ืช. ื”ืฉื•ืœื— ื•ื”ืžืงื‘ืœ ืฆืจื™ื›ื™ื ืœื”ืกื›ื™ื ืขืœ ืœื™ื ืง ืžืงื•ืฆืจ )ืขื“ื™ืฃ ืื—ื“ ืฉืœื

ืคื•ืคื•ืœืจื™ ื‘ืžื™ื•ื—ื“(. ื–ื” ืœื ืžืฉื ื” ืœืืŸ ื”ืงื™ืฉื•ืจ ืžืคื ื”.

ื™ืฉ ืœืคืชื•ื— bit.lyืขืœ ืžื ืช ืœื™ืฆื•ืจ ืงื™ืฉื•ืจื™ื ื‘ืืชืจ :ื”ืขืจื”

ืžืฉืชืžืฉื™ื ื™ื•ืฆืจืช ืฉื‘ื™ืœ ืžืฉืชืžืฉ ื‘ื—ื™ื ื. ืคืชื™ื—ืช

ืคื™ืจื•ืจื™ ืœื—ื ืฉืœื ืชืžื™ื“ ื ืจืฆื” ืœื™ืฆื•ืจ. ืงื™ื™ืžื™ื ืฉื™ืจื•ืชื™ื

ื ื•ืกืคื™ื ื‘ืื™ื ื˜ืจื ื˜ ืฉืžืกืคืงื™ื ืฉื™ืจื•ืช ื“ื•ืžื”, ื•ืœื ื“ื•ืจืฉื™ื

ื”ืจืฉืžื”.

ืžืกืคืงืช ืคืื ืœ ืฉืžืจืื” ืืช bit.lyื‘ืจื’ืข ื™ืฆื™ืจืช ืงื™ืฉื•ืจ,

(, ื”ื—ืœื•ืงื” Total Clicksื›ืžื•ืช ื”ื›ื ื™ืกื•ืช ืœืงื™ืฉื•ืจ ื”ืžืงื•ืฆืจ )

ืฉื‘ื”ื ืฉืœ ื›ืžื•ืช ื”ื›ื ื™ืกื•ืช ืœืคื™ ื™ืžื™ื, ื”ืฉื™ื˜ื•ืช ื”ืฉื•ื ื•ืช

( referrer.documentื ื™ื’ืฉื• ืœืงื™ืฉื•ืจ )ืžื‘ื•ืกืก ืขืœ

ื•ื”ืžื™ืงื•ืžื™ื ืžื”ื ื ื™ื’ืฉื• )ื›ื ืจืื” ืžื‘ื•ืกืก ืขืœ ืฉื™ืจื•ืช

GeoIP ืฉื™ืจื•ืชื™ื ืฉื•ื ื™ื ื™ืฉืžืจื• ื•ื™ืฆื™ื’ื• ืืช ื”ืžื™ื“ืข ื‘ืฆื•ืจื” .)

ืชื.ืฉื•ื ื”, ืืš ื”ื ืชื•ื ื™ื ื”ืœืœื• ื ืคื•ืฆื™ื ื‘ืžืจื‘ื™

', ืขืœื™ื• ืœื’ืฉืช ืœืงื™ืฉื•ืจ ื”ืžืงื•ืฆืจ )ื•ื›ืš ืœื”ืขืœื•ืช ืืช 3ืžื‘ื—ื™ื ืช ื”ืฉื•ืœื—, ืขืœ ืžื ืช ืœื”ืขื‘ื™ืจ ืœืชื•ืงืฃ ืืช ื”ื‘ื™ื˜ '

', ื”ื•ื ืœื ืขื•ืฉื” ื›ืœื•ื. 1(. ืื ื”ืฉื•ืœื— ืจื•ืฆื” ืœื”ืขื‘ื™ืจ ืืช ื”ื‘ื™ื˜ '3-ื”ืžื•ื ื” ืฉืœ ื›ืžื•ืช ื”ื›ื ื™ืกื•ืช ื‘

[bit.ly]ื”ืžื™ื“ืข ื”ืื ืœื™ื˜ื™ ืฉืžื•ืคื™ืข ืขื‘ื•ืจ ืงื™ืฉื•ืจ ืฉืœ ืžืฉืชืžืฉ ื—ื™ื ืžื™ ื‘ืืชืจ

Page 29: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

29 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

', ื”ืชืงืฉื•ืจืช ืฉืœ ื”ืฉื•ืœื— ืชื™ืจืื” ื‘ืขืจืš ื›ืš )ืžื•ื ื” ื”ื›ื ื™ืกื•ืช ืžืชื—ื™ืœ3133ืขืœ ืžื ืช ืœืฉืœื•ื— ืืช ืจืฆืฃ ื”ื‘ื™ื˜ื™ื '

(:1ืžืขืจืš

ื›ืœ ืฉืชื™ ืฉื ื™ื•ืช(. -ื”ืชื•ืงืฃ, ืžื‘ื—ื™ื ืชื•, ื‘ื•ื“ืง ื‘ืžืจื•ื•ื—ื™ื ืงื‘ื•ืขื™ื ืฉืœ ื–ืžืŸ ืืช ื›ืžื•ืช ื”ื›ื ื™ืกื•ืช )ื‘ื“ื•ื’ืžื” ืœืžืขืœื”

'. ืื ืขืจืš ื”ืžื•ื ื” ืœื ื”ืฉืชื ื” ืœืื•ืจืš ื—ืœื•ืŸ ื”ื–ืžืŸ 3, ืื– ื”ืชื•ืงืฃ ืžืกืžืŸ ืืช ื”ื‘ื™ื˜ '3-ืื ืขืจืš ื”ืžื•ื ื” ืขืœื” ื‘

'.1ื”ืžื•ืงืฆื‘, ื”ืฉื•ืœื— ืœื ื‘ื™ืฆืข ื‘ืงืฉื” ืœืฉืจืช ื•ืœื›ืŸ ื”ืชื•ืงืฃ ืžืกืžืŸ ืืช ื”ื‘ื™ื˜ '

, ื•ืฉื”ืฉื™ืžื•ืฉ ื‘ืฉื™ืจื•ืช ืžื•ื›ืจ ื•ื ืคื•ืฅ ื‘ื”ื—ืœื˜ ืžื•ืขื™ืœื” 3-8ืœื˜ืขื•ืŸ ื›ื™ ื”ืฉื™ื˜ื” ื”ื–ื• ืžืžืœืืช ืืช ื“ื™ื‘ืจื•ืช ื ื™ืชืŸ

ื•ื›ื•'(. ืื•ืœื, Alexa ,IP Reputationื‘ื‘ื“ื™ืงื•ืช ื”ืœื’ื™ื˜ื™ืžืฆื™ื” ืฉืžืคืขื™ืœื•ืช ืžืขืจื›ื•ืช ื”ื”ื’ื ื” ื”ืืจื’ื•ื ื™ื•ืช )ื“ื™ืจื•ื’

ืžืกืชืžื›ืช ืขืœ ื›ืš ืฉืืฃ ืื—ื“ ืœื ืœืฉื™ื˜ื” ื™ืฉ ืžืกืคืจ ื—ืกืจื•ื ื•ืช ื‘ืจื•ืจื™ื. ื‘ื“ื•ืžื” ืœืฉื™ื˜ื” ื”ืงื•ื“ืžืช, ื”ืฉื™ื˜ื” ื”ื–ื•

ืœื—ืกื•ื ืืช ื›ืœ ื”ื‘ืงืฉื•ืช ื”ื–ื” ืžืœื‘ื“ ื”ืฆื“ื“ื™ื ื”ืžืชืงืฉืจื™ื. ื‘ื ื•ืกืฃ, ืงืœ ืžืื•ื“ ืขื‘ื•ืจ ืืจื’ื•ืŸ ืคืฉื•ื˜ ื™ื™ื›ื ืก ืœืงื™ืฉื•ืจ

ืฉืœ ืžืงืฆืจ ื ื™ืชืŸ ืœืขืงื•ืฃ ืืช ื”ืžื•ื ื”(. ืœื‘ืกื•ืฃ, 31#ื•ื›ืš ืœื”ืจื•ืก ืืช ื”ืขืจื•ืฅ ื”ืกืžื•ื™ )ื“ื™ื‘ืจ ly.bit-ื”ื™ื•ืฆืื•ืช ืœ

ื”ืœื™ื ืงื™ื ืขืœ ื™ื“ื™ ื”ื•ืกืคืช ื”ืกื™ืžืŸ '+' ื‘ืกื•ืฃ ื”ืงื™ืฉื•ืจ, ืœืงื‘ืœืช ื”ืืชืจ ื”ื‘ื:

ื” ื—ื•ืฉืคืช ืืช ื”ืงื™ืฉื•ืจ ื”ืืจื•ืš ืืœื™ื• ื”ืžืขืจื›ืช ืžืขื‘ื™ืจื”, ื•ื’ื ืœื ื ืกืคืจืช ื‘ืžื•ื ื” ื›ืœืœ. ื ื™ืชืŸ ื”ื›ื ื™ืกื” ืœืงื™ืฉื•ืจ ื”ื–

'(, ืชื—ืœืฅ ืืช +, ื”ืžืขืจื›ืช ืชื™ื›ื ืก ืœืงื™ืฉื•ืจ )ืขื ื”ืื•ืช 'bit.ly-ืœื™ื™ืฉื ืžืขืจื›ืช ืฉืขื‘ื•ืจ ื›ืœ ื‘ืงืฉื” ืฉื™ื•ืฆืืช ืœ

Page 30: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

31 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ืฉืชืขื‘ื™ืจ ืืช ื”ืžืฉืชืžืฉ ืœื“ืฃ ื”ืžื™ื•ืขื“ ืœืœื ืกืคื™ืจื” HTTP 301ื”ืงื™ืฉื•ืจ ื”ืืจื•ืš ื•ืชื—ื–ื™ืจ ืื•ืชื• ื™ื—ื“ ืขื ืชื’ื•ื‘ืช

ื”ืจื•ืก ืืช ื”ืขืจื•ืฅ ื”ืกืžื•ื™ ืžื‘ืœื™ ืœืคื’ื•ืข ื‘ืชืคืงื•ื“ ืฉืœ ื”ืืชืจ(.ื‘ืžื•ื ื” )ื•ื›ืš ืช

ื–ืžืŸ ื”ืชื—ื‘ืจื•ืช ืื—ืจื•ืŸ ืœืืชืจ - ืฉื™ืžื•ืฉ ื‘ืžื•ื ื”/ืกื•ืคืจ -ืขืจื•ืฅ ืกืžื•ื™ ืžื‘ื•ืกืก ืชื–ืžื•ืŸ

ื”ืจื‘ื” ืžืขืจื›ื•ืช ืžื™ื™ืœ ื•ืจืฉืชื•ืช ื—ื‘ืจืชื™ื•ืช ืžืฆื™ื’ื•ืช "ื–ืžืŸ ื”ืชื—ื‘ืจื•ืช ืื—ืจื•ืŸ" ื›ืืฉืจ ืžืฉืชืžืฉ ืžืชื—ื‘ืจ ื‘ื”ืฆืœื—ื”

ื›ื•ืœ ืœื”ืชื—ื‘ืจ ื•ืœื”ืชื ืชืง ื‘ื–ืžื ื™ื ืœืฉื™ืจื•ืช. ื”ืชื›ื•ื ื” ื”ื–ื• ื™ื›ื•ืœื” ืœืฉืžืฉ ื‘ืชื•ืจ ืขืจื•ืฅ ืกืžื•ื™, ื›ืืฉืจ ื”ืฉื•ืœื— ื™

ืืกื˜ืจื˜ื’ื™ื™ื, ื•ื”ืชื•ืงืฃ ื™ื›ื•ืœ ืœืงืจื•ื ืืช ื”ื–ืžื ื™ื ื”ืœืœื• ื•ืœืคืขื ื— ืืช ื”ืžื™ื“ืข. ืœืฉื ื›ืš, ื”ืฉื•ืœื— ื•ื”ืžืงื‘ืœ ืฆืจื™ื›ื™ื

ืœืฉืชืฃ ื‘ื™ื ื™ื”ื ืืช ื ืชื•ื ื™ ื”ื”ืชื—ื‘ืจื•ืช )ืœืจื•ื‘ ืฉื ืžืฉืชืžืฉ ื•ืกื™ืกืžื( ืžื‘ืขื•ื“ ืžื•ืขื“.

[ื‘ืขื‘ืจ ืžื—ื•ื‘ืจื™ื ื•ืฉื”ื™ื• ื›ืขืช ืฉืžื—ื•ื‘ืจื™ื ืžื›ืฉื™ืจื™ื ืจืฉื™ืžืช: WhatsApp-ื• ื’ื•ื’ืœ]

', ื”ืฉื•ืœื— ืžืชื—ื‘ืจ ืœืžืฉืชืžืฉ 3ื˜ื•ืช ื”ืื—ืจื•ืช ืฉืžื‘ื•ืกืกื•ืช ืขืœ ืชื–ืžื•ืŸ, ืขืœ ืžื ืช ืœื”ืขื‘ื™ืจ ืืช ื”ื‘ื™ื˜ 'ื‘ื“ื•ืžื” ืœืฉื™

' ื”ื•ื ืœื ืขื•ืฉื” ื›ืœื•ื. ื”ืชื•ืงืฃ, ืžืžื›ืฉื™ืจ ืื—ืจ, ื‘ื•ื“ืง ืืช ืฉืขืช ื”ื”ืชื—ื‘ืจื•ืช 1ื‘ื–ืžืŸ ืžืกื•ื™ื ื•ืขืœ ืžื ืช ืœื”ืขื‘ื™ืจ '

ื”ืื—ืจื•ื ื” ืœืืชืจ ื•ืžืงื‘ืœ ืืช ื”ื‘ื™ื˜ื™ื ืžืชื•ืš ื”ืจืฉืช ื”ืืจื’ื•ื ื™ืช.

:ื”ืฉื™ื˜ื” ื”ื–ืืช ื”ื™ื ืงืฆืช ื‘ืขื™ื™ืชื™ืช, ื•ื–ืืช ืžื›ืžื” ืกื™ื‘ื•ืช

lackืฉื™ื›ื•ืœื™ื ืœื”ื™ื•ืช ืœืื“ื ื‘ื•ื“ื“ ืœืืชืจ ื™ื—ื™ื“ ืžื‘ืœื™ ืœื”ืขืœื•ืช ื—ืฉื“ ) ืžื’ื‘ืœื” ืœื›ืžื•ืช ื”ืžืฉืชืžืฉื™ืื™ืฉ .1

scale)

, ืฉื›ืŸ ื–ื” ืขืœื•ืœ ืœื”ื™ื•ืช ืงืฉื” ืœื”ืกื‘ื™ืจ ืœืžื” ืื“ื ืžืชื—ื‘ืจ ืœืžืฉืชืžืฉ ื‘ืชื“ื™ืจื•ืช ื›ื” 3#ืžืคืจ ืืช ื“ื™ื‘ืจ .2

ื’ื‘ื•ื”ื” ืžื‘ืœื™ ืœืขืฉื•ืช ื”ืจื‘ื”.

ืจื™ื ื•ืฉื”ืชื—ื‘ืจื• ืฉืœ ื›ืœ ื”ืžื›ืฉื™ืจื™ื ื”ืžื—ื•ื‘ IP-ืฉืžืฆื™ื’ื™ื ื’ื ืืช ื›ืชื•ื‘ืช ื” Gmailื™ืฉื ื ืืชืจื™ื ื›ืžื• .3

ืฉืœ ื”ืžื›ืฉื™ืจ ืฉืœ ื”ืชื•ืงืฃ ืžื”ืฆื“ ื”ืฉื ื™ ื•ื–ื” ืขืœื•ืœ ืœื—ืฉื•ืฃ ืื•ืชื•(. IP-ื‘ืขื‘ืจ )ื•ื›ืš ื’ื ืืช ื›ืชื•ื‘ืช ื”

ืื• ืชื•ื›ื ื•ืช ืžื™ื™ืœ, ื•ืœื›ืŸ ื ื™ืชืŸ ืœื—ืกื•ื ืื•ืชื ืœื ืืžื•ืจื™ื ืœื’ืฉืช ืœืจืฉืชื•ืช ื—ื‘ืจืชื™ื•ืชื‘ืจืฉืช ืืจื’ื•ื ื™ืช ืกื’ื•ืจื” .4

(.31#ืœื—ืœื•ื˜ื™ืŸ )ื“ื™ื‘ืจ

ื”ืชืขืกืงื•ืช ืขื ืžื˜ืžื•ืŸ -ืขืจื•ืฅ ืกืžื•ื™ ืžื‘ื•ืกืก ืื—ืกื•ืŸ

Page 31: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

31 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ื–ื” -ืข ืœืชื•ื›ื ื•ืช ื•ืœืฉืจืชื™ื ืžืœื—ื–ื•ืจ ืขืœ ืื•ืชื• ื“ื‘ืจ ืคืขืžื™ื ืจื‘ื•ืช ื‘ื˜ื•ื•ื— ื–ืžืŸ ืงืฆืจ, ื•ื‘ืฆื“ืง ื–ื™ื›ืจื•ืŸ ืžื˜ืžื•ืŸ ืžืกื™ื™

ื”ื™ื” ืืœื‘ืจื˜ ืื™ื™ื ืฉื˜ื™ื™ืŸ ืฉืืžืจ ืคืขื ืฉื”ื”ื’ื“ืจื” ืœืื™ ืฉืคื™ื•ืช ื”ื™ื ืœืขืฉื•ืช ืืช ืื•ืชื• ื”ื“ื‘ืจ ืฉื•ื‘ ื•ืฉื•ื‘ ื•ืœืฆืคื•ืช

ืœืชื•ืฆืื•ืช ืฉื•ื ื•ืช, ื•ืžื—ืฉื‘ื™ื ืืžื•ืจื™ื ืœื”ื™ื•ืช ืฉืคื•ื™ื™ื. ืื ืžืกืคืจ ืžืฉืชืžืฉื™ื ื–ืงื•ืงื™ื ืœืื•ืชื• ื“ืฃ ืื™ื ื˜ืจื ื˜, ืื™ืŸ

ืฉืจืช ื™ื™ื’ืฉ ืœืžืกื“ ื ืชื•ื ื™ื, ื™ื‘ืฆืข ื‘ื• ืฉืื™ืœืชืช ื—ื™ืคื•ืฉ, ื™ื•ืฆื™ื ืืช ื”ืžื™ื“ืข, ื™ืขื‘ื“ ืื•ืชื•, ื™ืฆื™ื‘ ืื•ืชื• ืกื™ื‘ื” ืฉื”

ืžื˜ืžื•ืŸ ืžื ื’ื ื•ืŸ ืžื’ื“ื™ืจ HTTP, ืคืจื•ื˜ื•ืงื•ืœ ื›ืŸืœื•ืื– ื™ื—ื–ื•ืจ ืขืœ ื”ืชื”ืœื™ืš ื›ืœ ืคืขื ืžื—ื“ืฉ. HTMLื‘ืžืขื‘ื“ ืชื‘ื ื™ื•ืช

ื™ื— ืืš ืœื ื™ื˜ืจ ืœื”ื™ืžื ืข ืžืžืฆื‘ ืฉื‘ื• ื”ื“ืคื“ืคืŸ ื™ืฆื™ื’ ืžื™ื“ืข ืฉืื™ื ื• ืขื“ื›ื ื™ ื•ืœื™ื™ืฉื ื‘ืฉืจืช ื•ื‘ืœืงื•ื—, ืฉืžื˜ืจืชืฉื ื™ืชืŸ

.ืืช ื”ืฉืจืช ื™ื•ืชืจ ืžื›ืคื™ ืฉืฆืจื™ืš

ื”ืฉื™ื˜ื” ื”ื–ืืช ืžื ืฆืœืช ืืช ื”ื™ื›ื•ืœืช ืฉืœ ืžื ื’ื ื•ื ื™ ืžื˜ืžื•ืŸ ืฉื•ื ื™ื "ืœื”ื“ืœื™ืฃ" ืืช ื”ื–ืžืŸ ื”ืžื“ื•ื™ืง ืฉื‘ื• ืื•ื‘ื™ื™ืงื˜ ื ื›ื ืก

ืฉืžื™ืจื”(. ืœื“ื•ื’ืžื, ื‘ืจื’ืข ื˜ืขื™ื ืช ื“ืฃ ืื™ื ื˜ืจื ื˜ ืืฉืจ ื ื™ื’ืฉื• ืืœื™ื• ื‘ืขื‘ืจ )ื‘ื—ืœืง /ืœืžื˜ืžื•ืŸ ืžืœื›ืชื—ื™ืœื” )ื–ืžืŸ ื™ืฆื™ืจื”

ืžืŸ ื”ืฉืจืชื™ื(, ื”ืฉืจืช ื™ื›ื•ืœ ืœื”ื’ื™ื‘ ืขื ื”ืชื’ื•ื‘ื” ื”ื‘ืื”:

Date ื”ื•ื ืชืืจื™ืš ื”ื‘ืงืฉื” ื”ื ื•ื›ื—ื™ )ื”ื–ืžืŸ ื”ื ื•ื›ื—ื™ ืœืคื™ ื”ืฉืจืช(, ื•-Age ืžื•ื’ื“ืจ ืœืคื™ ื›ืžื•ืช ื”ืฉื ื™ื•ืช ืžื”ืจื’ืข

ื–ืžืŸ ื”ืžื—ื™ื™ื” ื”ืžืงืกื™ืžืœื™ -ื ื™ืชืŸ ืœืจืื•ืช ืžื™ื“ืข ืจืœื•ื•ื ื˜ื™ ื ื•ืกืฃ Cache-Control-ืฉื”ื“ืฃ ื ื›ื ืก ืœืžื˜ืžื•ืŸ ืœืจืืฉื•ื ื”. ื‘

1ื ื”: ื ืฉืืจื• ืœื• )ืœืคื™ ื”ืชืžื• max-age-ื™ื’ื™ืข ืœ Ageืขื“ ืฉื”ืขืจืš ืฉืœ -ืฉื ื™ื•ืช. ื›ืœื•ืžืจ 111ืฉืœ ื”ื“ืฃ ื‘ืžื˜ืžื•ืŸ ื”ื•ื

ืฉื ื™ื•ืช(, ืื ื”ืœืงื•ื— ื™ื‘ืงืฉ ืืช ืื•ืชื” ื‘ืงืฉื” ืฉื ื™ืช, ื”ื•ื ื™ืงื‘ืœ ื‘ื“ื™ื•ืง ืืช ืื•ืชื” ืชื’ื•ื‘ื” ืžืฆื“ ื”ืฉืจืช 31-ื“ืง' ื•

(. 111Not Modified)ืื• ื™ืงื‘ืœ ืงื•ื“

ื”ื“ืง' ื”ืœืœื•, ืคื’ ืชื•ืงืคื” ืฉืœ ื”ืชื’ื•ื‘ื”, ื•ื”ื™ื ื ืžื—ืงืช ืžื–ื™ื›ืจื•ืŸ ื”ืžื˜ืžื•ืŸ. ื”ืžืฉืชืžืฉ ื”ื‘ื ืฉื™ื‘ืงืฉ ืืช 5ื‘ืชื•ื

ืœืชื’ื•ื‘ื” ื›ื™ ื”ืฉืจืช ื™ืฆื˜ืจืš ืœื’ืฉืช ืฉื ื™ืช ืœืžืกื“ ื”ื ืชื•ื ื™ื, ืœื‘ืฆืข ืืช ืื•ืชื” ื‘ืงืฉื” ื™ืฆื˜ืจืš ืœื—ื›ื•ืช ืงืฆืช ื™ื•ืชืจ ื–ืžืŸ

ื”ืฉืื™ืœืชื”, ื•ื›ื•'.

Page 32: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

32 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

"ืžื•ื˜ืžืŸ ื‘ืฉืจืช" ืื• "ืœื ืžื•ื˜ืžืŸ ื‘ืฉืจืช ืขื“ื™ื™ืŸ" ื•ืœืฉื•ืœื— ื™ืฉ -ื ื™ืชืŸ ืœื”ื‘ื“ื™ืœ ื‘ื™ืŸ ืฉื ื™ ืžืฆื‘ื™ื ืฉืœ ืืชืจ ืžืกื•ื™ื

URLื™ื›ื•ืœืช ืœืฉืœื•ื˜ ื‘ื›ืš. ื ื•ื›ืœ ืœื”ืจื›ื™ื‘ ืžื–ื” ืขืจื•ืฅ ืกืžื•ื™. ืจืืฉื™ืช, ืขืœ ืฉื ื™ ื”ืฆื“ื“ื™ื ืœื”ืกื›ื™ื ืขืœ ื›ืชื•ื‘ืช

ืžืฉื•ืชืคืช.

ืื ื”ื•ื ืžืขื•ื ื™ื™ืŸ ืœืฉืœื•ื— ืืช - HTTPืœื— ื™ื›ื•ืœ ืœืฉืœื•ื˜ ื‘ืžืฆื‘ื™ ื”ืžื˜ืžื•ืŸ ื”ืžืชื•ืืจื™ื ื‘ืืžืฆืขื•ืช ื‘ื™ืฆื•ืข ื‘ืงืฉื•ืช ื”ืฉื•

ื“ืง'( ื•ืื 5ืืœ ื”ื“ืฃ )ื”ืฉืจืช ืขื•ื‘ืจ ืœืžืฆื‘ "ืžื•ื˜ืžืŸ ื‘ืฉืจืช" ืœืžืฉืš HTTP', ื™ื”ื™ื” ืขืœื™ื• ืœื‘ืฆืข ื‘ืงืฉืช 3ื”ื‘ื™ื˜ '

', ื”ื•ื ืœื ืฆืจื™ืš ืœืขืฉื•ืช ื›ืœื•ื.1ื”ื•ื ืžืขื•ื ื™ื™ืŸ ืœืฉืœื•ื— ืืช ื”ื‘ื™ื˜ '

. ืื ื”ื“ืฃ ืฉื”ื•ื ืงื™ื‘ืœ ืžื”ืฉืจืช ื”ื’ื™ืข Ageื™ื, ื•ื‘ื•ื“ืง ืืช ื”ืขืจืš ืฉืœ ื”ืžืงื‘ืœ ื ื›ื ืก ืœืืชืจ ื‘ื–ืžื ื™ื ืงื‘ื•ืข

(, ืื– ื–ื” ืื•ืžืจ ืฉื”ืฉื•ืœื— ื ื›ื ืก ืœื“ืฃ ื”ื–ื” ื‘ืขื‘ืจ )ื‘ื”ื ื—ื” ืฉืืฃ ืžืฉืชืžืฉ ืื—ืจ ื ื™ื’ืฉ ืœื“ืฃ Age > 0ืžื”ืžื˜ืžื•ืŸ )

'. ืื—ืจืช, ื”ืฉื•ืœื— ืœื ื ื›ื ืก ื‘ื–ืžืŸ ื”ื–ื” ืืœ ื”ื“ืฃ, ื•ื”ื•ื 3ื”ื–ื” ืžืœื‘ื“ ื”ืฉื•ืœื— ื•ื”ืžืงื‘ืœ(, ื•ื”ื•ื ืžืกืžืŸ ืฉื”ื•ื ืงื™ื‘ืœ '

'. 1ืžืกืžืŸ ืฉื”ื•ื ืงื™ื‘ืœ '

ืฉืขื•ื‘ื“ื•ืช ืขื ืžื˜ืžื•ืŸ )ื•ื‘ืขื™ืงืจ ืžื˜ืžื•ืŸ ืฉืœ ืฆื“ ืฉืœื™ืฉื™( ื”ืŸ ืžื•ืฉืœืžื•ืช ืขื‘ื•ืจ ื”ืฉื™ืžื•ืฉ ืฉืœื ื• ื›ื™ ื”ืŸ ืœื ืฉื™ื˜ื•ืช

ืžื›ื™ืœื•ืช ืชืงืฉื•ืจืช ื™ืฉื™ืจื” ื‘ื™ืŸ ื”ืชื•ืงืฃ ืœื‘ื™ืŸ ื”ืžื—ืฉื‘ ื”ืืจื’ื•ื ื™. ื”ืจืขื™ื•ืŸ ื”ืžืจื›ื–ื™ ืžืื—ื•ืจื™ื”ืŸ ื”ื•ื ืฉื”ืฉื•ืœื— "ืžืฉื ื”

"ืžื‘ื•ืกืกืช ืื—ืกื•ืŸ" -ืžื˜ืžื•ืŸ( ื•ืœื›ืŸ ื”ืฉื™ื˜ื” ื ื—ืฉื‘ืช ืœ -ืฉืœื™ืฉื™ )ื‘ืžืงืจื” ื”ื–ื” -ืžืฆื‘ ื‘ืื•ืคืŸ ื–ืžื ื™" ื‘ืฉืจืช ืฆื“

ืœืžืจื•ืช ืฉืชื–ืžื•ืŸ ื’ื ื”ื•ื ืงืจื™ื˜ื™ ืคื”.

ื•ืกื™ืช ื‘ืœื‘ื“( )ื‘ืจ ืžืืžืจื•ืฉื•ืช' ืžืื•ื ื™ื‘ืจืกื™ื˜ืช ืžื™ื ืกืง ืฉื‘ืจื•ืกื™ื” ื›ืชื‘ื• Denis Kolegov, 2131: ื‘ืฉื ืช ื”ืจื—ื‘ื”

ื‘ืชื•ืจ ืฉื ื™ ETagื•ืขืœ Last-Modifiedืขืœ ืฉื™ืžื•ืฉ ื‘ืžื˜ืžื•ืŸ ื‘ืชื•ืจ ืขืจื•ืฅ ืกืžื•ื™. ื”ืžืืžืจ ืฉื ื“ื’ืฉ ืขืœ ื›ื•ืชืจื•ืช

ื›ืฉืžื™ื“ืข ืžื’ื™ืข -ื”ื™ื ื—ืœืง ืžืžื ื’ื ื•ืŸ ืœืื™ืžื•ืช ืžื™ื“ืข ืฉื ืžืฆื ื‘ืžื˜ืžื•ืŸ ETagืขืจื•ืฆื™ื ืกืžื•ื™ื™ื ืคื•ื˜ื ืฆื™ืืœื™ื. ื›ื•ืชืจืช

)ื’ื™ื‘ื•ื‘ ื›ืœืฉื”ื•( ืื•ืชื• ื”ืœืงื•ื— ืฉื•ืžืจ. ETagืžื”ืฉืจืช, ื”ื•ื ื™ื›ื•ืœ ืœื—ื–ื•ืจ ืขื ืขืจืš

, ื”ื•ื ื™ื›ื•ืœ ืœืงื‘ื•ืข ืื ื”ืงื•ื‘ืฅ ื”ื ื•ื›ื—ื™ ืฉื™ืฉ ืœื• ื‘ืžื˜ืžื•ืŸ ืขื“ื™ื™ืŸ ื˜ืจื™ URLืœื”ื‘ื, ื›ืฉื”ืœืงื•ื— ืจื•ืฆื” ืœืงืœื•ื˜ ืืช ืื•ืชื•

(. ืื ื”ืงื•ื‘ืฅ ื˜ืจื™, ื”ืœืงื•ื— ื™ื˜ืขืŸ ืืช ื”ืžื™ื“ืข ืฉืฉืžื•ืจ ืœื• ื‘ืžื˜ืžื•ืŸ. Expire-ื• Cache-Control)ื‘ืขื–ืจืช ื›ื•ืชืจื•ืช

. If-None-Matchืื ื”ืงื•ื‘ืฅ ืื™ื ื• ื˜ืจื™, ื”ืœืงื•ื— ื™ื›ื•ืœ ืœืฉืœื•ื— ืœืฉืจืช ื‘ืงืฉื” ืฉืžื›ื™ืœื” ืืช ื›ื•ืชืจืช

ืฉืœ ETag-ืื ื™ืฉ ื’ืจืกื” ื—ื“ืฉื” ื™ื•ืชืจ ืœืงื•ื‘ืฅ )ืื ื” -ื”ื›ื•ืชืจืช ื”ื–ื• ืื•ืžืจืช ืœืฉืจืช ืœืขืฉื•ืช ืื—ื“ ืžืฉื ื™ ื“ื‘ืจื™ื

ื”ืžืชืื™ื ืœื•. ืื ืื™ืŸ ETag-ื”ื›ื•ืชืจืช ื‘ืชื’ื•ื‘ื” ืœื ืชื•ืืžืช ืœื‘ืงืฉื”( ืื– ื”ืฉืจืช ื™ื—ื–ื™ืจ ืืช ื”ืงื•ื‘ืฅ ื”ื—ื“ืฉ, ื•ื”

ืคื™ื™ื ื™ื . ื”ืžื ื’ื ื•ืŸ ื”ื–ื” ื‘ื”ื—ืœื˜ ืžื›ื™ืœ ืืช ื”ืžืHTTP 304 Not Modifiedื’ืจืกื” ื—ื“ืฉื” ื™ื•ืชืจ ืœืงื•ื‘ืฅ, ื™ื•ื—ื–ืจ

ืฉืื ื• ืžื—ืคืฉื™ื ื‘ืฉื‘ื™ืœ ืขืจื•ืฅ ืกืžื•ื™.

Page 33: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

33 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

Air-Gapื•ืžื—ืฉื‘ื™ QRืงื•ื“ -ืขืจื•ืฅ ืกืžื•ื™ ืคื™ื–ื™

ื›ื™ื•ื, ืœื›ืœ ืื—ื“ ืžืื™ืชื ื• ื™ืฉ ืžืฆืœืžื•ืช ืื™ื›ื•ืชื™ื•ืช ื‘ื›ื™ืก ื”ืงื˜ืŸ. ืžื›ืฉื™ืจื™ ื”ื˜ืœืคื•ืŸ ื”ืื™ืฉื™ื™ื ืฉืœื ื• ื™ื›ื•ืœื™ื ืœืกื™ื™ืข

ืžืฆืœืžื•ืช( ื•ืžื™ืงืจื•ืคื•ื ื™ื. -, ืžืฆืœืžื” )ืื• ื›ื™ื•ื Wi-Fiื‘ื‘ื™ืฆื•ืข ื–ืœื™ื’ืช ืžื™ื“ืข ื‘ืืžืฆืขื•ืช ื›ืœื™ื ื›ืžื• ืื ื˜ื ื•ืช

[Source: @rohane via Twenty20]

ื”ื“ื•ื’ืžื ื”ื›ื™ ืคืฉื•ื˜ื” ืœื”ื•ืฆืืช ืžื™ื“ืข ืžืžื—ืฉื‘ ืคื™ื–ื™ ื”ื™ื ืฆื™ืœื•ื ืคื™ื–ื™ ืฉืœ ื”ืžืกืš ืฉืžืฆื™ื’ ืžื™ื“ืข ืจื’ื™ืฉ. ื›ืžื•ื‘ืŸ,

ืฉืฉื—ื–ื•ืจ ืฉืœ ืžื™ื“ืข ื›ื–ื” ื™ื›ื•ืœ ืœื”ื™ื•ืช ืงืฆืช )ืžืื•ื“!( ืžืชื™ืฉ, ื•ื”ื™ื ืœื ืชืขื‘ื•ื“ ื”ื™ื˜ื‘ ืขื ืžื™ื“ืข ืฉื”ื•ื ืœื ื˜ืงืกื˜

ื›ืชื‘ ื“"ืจ ืžืจื“ื›ื™ ื’ื•ืจื™ ืžืื•ื ื™ื‘ืจืกื™ื˜ืช ื‘ืŸ ื’ื•ืจื™ื•ืŸ , 2138)ื›ืžื• ืžื™ื“ืข ื‘ื™ื ืืจื™( ืื‘ืœ ื–ื” ืืคืฉืจื™ ื‘ื™ื•ืชืจ. ื‘ืฉื ืช

ืขืœ ืžื ืช ืœื™ื™ืขืœ ืืช ื”ืœื™ืš ื”ืฉื—ื–ื•ืจ, ื•ืœืงืœื•ื˜ ื’ื ืžื™ื“ืข ื‘ื™ื ืืจื™. QRื•ื‘ื• ืชื™ืืจ ืื™ืš ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืงื•ื“ื™ ืžืืžืจ

ืกื™ื‘ื™ื•ืช(. ืื 9ื•ืชื™ื•ืช )ื›ืœ ืื•ืช ื”ื™ื ื 2,851( ื™ื›ื•ืœ ืœื”ื›ื™ืœ ืขื“ ISO/IEC 18004:2015)ืœืคื™ ืกื˜ื ื“ืจื˜ QRืงื•ื“

ืจืง ืื•ืชื™ื•ืช ื’ื“ื•ืœื•ืช, ื•ืขื•ื“ ืกื™ืžื ื™ื( ืื– ืชื•ื›ืœื• ืœืฉืžื•ืจ ืขื“ A-Z, 1-8ืชืฉืชืžืฉื• ืจืง ื‘ืื•ืชื™ื•ืช ืืœืคืื ื•ืžืจื™ื•ืช )

ื‘ื•ื“ื“, ืชื”ื™ื” ืฆื•ืจืš ื‘ืจื–ื•ืœื•ืฆื™ื” ื˜ื•ื‘ื” QRืกื™ื‘ื™ื•ืช ืœื›ืœ ืื•ืช(. ื›ื›ืœ ืฉื™ื•ืชืจ ืžื™ื“ืข ื ืžืฆื ื‘ืงื•ื“ 5.5ืื•ืชื™ื•ืช ) 1,282

ืœื”ื™ื•ืช ื’ื“ื•ืœ ื™ื•ืชืจ ืขืœ ืžื ืช ืฉืžื™ื“ืข ืœื ื™ืœืš ืœืื™ื‘ื•ื“. ื™ื•ืชืจ ืœืžืฆืœืžื”, ืื• ืฉื’ื•ื“ืœ ื”ืชืžื•ื ื” ื”ืžื•ืฆื’ ื™ืฆื˜ืจืš

Reed-Solomonื”ืกื˜ื ื“ืจื˜ ืžื›ื™ืœ ื’ื ื›ืœื™ื ืœืชื™ืงื•ืŸ ืงื•ื“, ื•ืžืืคืฉืจ ืœืฉื—ื–ืจ ื—ืœืง ืžื”ืžื™ื“ืข ืื ื ืื‘ื“. ืืœื’ื•ืจื™ืชื

, ื‘ื”ืขื‘ืจืช ืชืžื•ื ื•ืช ื‘ืžืฉื™ืžื•ืช WiMax)ื•ื’ื ื‘ื“ื™ืกืงื™ื, QRื”ื•ื ืืœื’ื•ืจื™ืชื ืœืชื™ืงื•ืŸ ืงื•ื“ ืฉื ืžืฆื ื‘ืฉื™ืžื•ืฉ ื‘ืงื•ื“ื™

Voyger ืฉืœ ื ืืกื, ื•ื‘ื—ืœืง ืžืžืขืจื›ื•ืชRAID - .)ื‘ืืžืช ื›ืžืขื˜ ื‘ื›ืœ ืžื“ื™ื•ื ืคื™ื–ื™ ืฉืขื•ืกืง ื‘ืžื™ื“ืข

Mืžื”ืžื™ื“ืข ื™ื›ื•ืœ ืœื”ื™ื•ืช ืžืฉื•ื—ื–ืจ(, ืจืžื” 1%) Lื‘ืืœื’ื•ืจื™ืชื ืžื•ื’ื“ืจื•ืช ืืจื‘ืข ืจืžื•ืช ืฉืœ ืชื™ืงื•ืŸ ืงื•ื“: ืจืžื”

ืฉื—ืœืงื ืงืจื•ืขื™ื ื•ื‘ื›ืœ ื–ืืช ื”ืฆืœื™ื—ื• ืœืคืขื ื— QR(. ื™ืฆื ืœื™ ืœืจืื•ืช ืงื•ื“ื™ 11%) H( ื•ืจืžื” 25%) Q(, ืจืžื” 35%)

ืื ืืชื ืžืขื•ื ื™ื™ื ื™ื ื‘ืจืžื•ืช ืฉื—ื–ื•ืจ ื’ื‘ื•ื”ื•ืช, ื›ืœ -' ืื—ื“ ืžื”ื ื‘ื”ืฆืœื—ื” ืืช ื”ืžื™ื“ืข. ืœืืœื’ื•ืจื™ืชื ื™ืฉ ืจืง ืงืืฅ

.ื”ืื™ื–ื•ืŸ ื‘ื™ืŸ ืืžื™ื ื•ืช ื”ืขื‘ืจืช ื”ืžื™ื“ืข ืœืงื™ื‘ื•ืœืช ืฉืœื• -ื™ืฆื˜ืจืš ืœื”ื›ื™ืœ ื”ืจื‘ื” ืคื—ื•ืช ืžื™ื“ืข. ื›ืจื’ื™ืœ QRืงื•ื“

Page 34: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

34 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

. ื”ื•ื ื”ืฆื™ืข ืฉืชื™ ืฉื™ื˜ื•ืช ืœื”ืฆื’ืช ื”ืงื•ื“ ืขืœ ื”ืžื—ืฉื‘ QRื‘ืžืืžืจ, ื“"ืจ ื’ื•ืจื™ ืžืฆื™ื’ ื™ื•ืชืจ ืžืฉื™ืžื•ืฉ ืคืฉื•ื˜ ืœืงื•ื“ื™

-ืขืœ-ืื ื•ืฉื™ืช. ืฉื™ื˜ื” ืื—ืช ื”ื™ื ื”ื˜ืžืขืช ื”ืชืžื•ื ื” ื‘ืกื’ื ื•ืŸ "ื‘ื”ื™ืจ ื”ืืจื’ื•ื ื™ ื‘ืฆื•ืจื” ืฉืชื”ื™ื” ืงืฉื” ืœื”ื‘ื—ื ื” ืœืขื™ืŸ

ืฉื—ื•ืจ" ื›ืš ืขื™ืŸ ืื ื•ืฉื™ืช ืชื—ื•ื•ื” ืงื•ืฉื™ ืœืงืœื•ื˜ ืืช ื”ื”ื‘ื“ืœ ื‘ื™ืŸ ื”ื’ื•ื•ื ื™ื. ื”ืฉื™ื˜ื” ื”ืฉื ื™ื™ื” ื”ื™ื -ืขืœ-ืœื‘ืŸ" ืื• "ื›ื”ื”

ืžืฉืชืชืคื™ื, 11(. ื‘ื ื™ืกื•ื™ ืฉืœ ื‘ืœื•ืš ื—ื•ืงืฉื™ืžื•ืฉ ื‘ืจื™ืฆื•ื“ ื‘ืงืฆื‘ ื’ื‘ื•ื” ื™ื•ืชืจ ืžืฉื”ืžื•ื— ืฉืœื ื• ืžืกื•ื’ืœ ืœืงืœื•ื˜ )ืœืคื™

ืฉื—ื•ืจ". ื›ืœ ืชืžื•ื ื” ื ื‘ื“ืงื” ื›ืฉื”ื™ื -ืขืœ-ืœื‘ืŸ" ื•ื’ื ื‘ืกื’ื ื•ืŸ "ื›ื”ื”-ืขืœ-ื’ื•ืจื™ ื”ืฆื™ื’ ืžืกืคืจ ืชืžื•ื ื•ืช ื’ื ื‘ืกื’ื ื•ืŸ "ื‘ื”ื™ืจ

ืžื”ืื ืฉื™ื ื”ืฆืœื™ื—ื• ืœื–ื”ื•ืช ืืช 2.5%ืคืขืžื™ื ื‘ืฉื ื™ื™ื”. ืจืง 11ืคืขืžื™ื ื‘ืฉื ื™ื™ื”, ื•ืžืจืฆื“ืช 21ืกื˜ื˜ื™ืช, ืžืจืฆื“ืช

ื”ืชืžื•ื ื•ืช ื”ืกื˜ื˜ื™ื•ืช.

ื™ื“ืข ืœืื•ื“ื™ื• ื•ืœื”ืฉืชืžืฉ ื‘ืจืžืงื•ืœื™ื ืฉืœ ื”ืžื—ืฉื‘ ืขืœ ืžื ืช ืœืฉื“ืจ ืื•ืชื• ื‘ืื•ืคืŸ ื“ื•ืžื”, ื ื™ืชืŸ ืœืืคื ืŸ ืืช ื”ืž

ืฉืžืฉืชืžืฉ ื‘ืืคื ื•ืŸ 2139ื‘ืฉื ืช ื›ืชื‘ ืžืืžืจ)ื•ื‘ืžื™ืงืจื•ืคื•ืŸ ืฉืœ ื”ื˜ืœืคื•ืŸ ื›ื“ื™ ืœืงืœื•ื˜ ืื•ืชื•(. ื“"ืจ ืžืจื“ื›ื™ ื’ื•ืจื™

ืกื•ื ื™ื™ื -ืืœ ืชื“ืจื™ื ืื•ืœื˜ืจื” ( ืขืœ ืžื ืช ืœืงื•ื“ื“ ืžื™ื“ืขAudio Frequency Shifting Keyingืชื“ืจื™ื )-ืžืฉื ื”

(39KHz 21ืขื“KHz.ื•ืœืฉื“ืจ ืื•ืชื ื“ืจืš ืจืžืงื•ืœื™ื ืฉืœ ืžื—ืฉื‘ )

Page 35: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

35 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ื”ืชื•ืงืฃื ืงื•ื“ืช ืžื‘ื˜ื• ืฉืœ

ืžื”ืคืจืกืคืงื˜ื™ื‘ื” ืฉืœ ื”ืชื•ืงืฃ, ื ืกืชื›ืœ ืขืœ ืžืขืจื›ืช ื‘ืกื™ืกื™ืช ืฉื‘ื ื™ืชื™ ืฉืžื•ืฆื™ืื” ืžื™ื“ืข

. ื ืขื‘ื•ืจ ืขืœ ื›ืœ ื”ืชื”ืœื™ืš, ืžื”ื—ืงื™ืจื” ืฉืœ ื”ืคืจื•ื˜ื•ืงื•ืœ ื•ื”ื’ื“ืจืช DNSื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœ

ืœืคื ื™ ื›ืžื” ื—ื•ื“ืฉื™ื ื ืชืงืœืชื™ ื•ืฉ ื‘ืขืจื•ืฅ ืกืžื•ื™ ื”ื ื›ื•ืŸ.ืฉื™ื˜ืช ืงื™ื“ื•ื“ ื”ืžื™ื“ืข ื•ืขื“ ืœืฉื™ืž

ืฉื ืจืื• ืœื ื”ื’ื™ื•ื ื™ื•ืช. ืžื—ืงื™ืจื” ืฉืขืฉื™ืชื™, DNSื‘ืขื‘ื•ื“ื” ืฉืœื™ ื‘ืžืกืคืจ ืขืฆื•ื ืฉืœ ื‘ืงืฉื•ืช

ืคืชื•ื— ืฉื”ืฉืชืžืฉื• ื‘ื• ื”ืชื•ืงืคื™ื, ื•ืืฃ ื”ืฆืœื—ืชื™ ืœืคืขื ื— ืืช -ืžืฆืืชื™ ืืช ื”ื›ืœื™ ืงื•ื“

ื”ื ืชื•ื ื™ื ืฉื”ื•ืขื‘ืจื• )ื›ื™ ื”ืชื•ืงืคื™ื ืœื ืฉื™ื ื• ื”ืจื‘ื” ืžื”ื’ื“ืจื•ืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ(. ื—ืฉื‘ืชื™

ื‘ืกื•ืจื“ ืฉื”ื™ื” ืœื™ ื›ืœ ื›ืš ืงืœ ืœื”ื‘ื™ืŸ ืืช ื”ืชื•ื›ืŸ ืฉื”ื•ืขื‘ืจ ื‘ืชื•ื•ืš, ื•ื›ืš ืขืœื” ืœืขืฆืžื™ ืฉื–ื” ื

Dataืžืขืจื›ืช ืžื•ื“ื•ืœืจื™ืช ืฉื ื•ืชื ืช ืœืžืฉืชืžืฉ ืฉืœื™ื˜ื” ื˜ื•ื˜ืืœื™ืช ืขืœ ื‘ื™ืฆื•ืข -ื”ืจืขื™ื•ืŸ

Exfiltration ื‘ืืžืฆืขื•ืชDNS ื›ืš, ื›ืœ ืžืฉืชืžืฉ ื™ื›ื•ืœ ื‘ืงืœื•ืช ืœื™ืฆื•ืจ ืคื•ืจืžื˜ ืžืฉืœื• ืœืงื™ื“ื•ื“ .

ื“ ื”ื’ืฉืช ื”ื›ืชื‘ื” ืœื ื”ืกืคืงืชื™ ืœืกื™ื™ื ืืช ื“ื•ืžื™ื™ื ื™ื, ืืคื™ืœื• ืžื‘ืœื™ ืœื“ืขืช ืœื›ืชื•ื‘ ืงื•ื“. ืœืžืจื‘ื” ื”ืฆืขืจ, ืขื“ ืœืžื•ืข

ืคืฉื•ื˜ ืฉื™ื•ื“ืข ืœื ืฆืœ ืืช ื”ืคื™ืฆ'ืจื™ื ืฉื”ืกืคืงืชื™ ืœื›ืชื•ื‘ ืขื“ ื›ื”(. ืœืžืจื•ืช CLIื›ืœ ื”ืžืขืจื›ืช )ื•ื ืืœืฆืชื™ ืœื›ืชื•ื‘ ื›ืœื™

ืืช ื”ืงื•ื“ ืœื›ืœื™ ืฉื‘ื ื™ืชื™ )ื•ืฉื ื“ื‘ืจ ืฉืื ื™ ืœื ืžื‘ื˜ื™ื—, ื™ื™ืชื›ืŸ ืฉื‘ืขืชื™ื“ ืื ื™ ืืกื™ื™ื ืืช ื”ืคื™ืชื•ื—, ื•ืืขืœื” ืื•ืชื•.

. ื‘ืขืžื•ื“ ื”ื’ื™ื˜ื”ืื‘ ืฉืœื™ืขืœื™ื•( ื ื™ืชืŸ ืœืžืฆื•ื

?Domain Name Systemืžื” ื–ื”

ื”ื™ื ืžืขืจื›ืช ืžื‘ื•ื–ืจืช DNSืžืขืจื›ืช -ื‘ืฉื‘ืข ืฉื•ืจื•ืช DNSืื ื”ื™ื™ืชื™ ืฆืจื™ืš ืœืกื›ื ืืช ื”ืžื”ื•ืช ืฉืœ ืžืขืจื›ืช

ื•ื”ื™ืจืจื›ื™ืช ืฉืœ ืžื—ืฉื‘ื™ื, ืฉืชืคืงื™ื“ื ื”ืงื•ืœืงื˜ื™ื‘ื™ ื”ื•ื ืœืขืงื•ื‘, ืœืฉืœื•ื˜ ื•ืœื”ื’ื“ื™ืจ ืฉืžื•ืช ืœื›ืชื•ื‘ื•ืช ืื™ื ื˜ืจื ื˜

DNSื•ืช ื“ื•ืžื™ื™ืŸ(. ืื ื—ื ื•, ื”ืฆืจื›ื ื™ื, ื–ืงื•ืงื™ื ืœืžืขืจื›ื•ืช )ื”ื™ื“ื•ืขื•ืช ื‘ืชื•ืจ ื›ืชื•ื‘

)ื›ืžื• IP"( ืœื›ืชื•ื‘ื•ืช example.comื›ื“ื™ ืฉื ื•ื›ืœ ืœื”ืžื™ืจ ื›ืชื•ื‘ื•ืช ืจืฉืช )ื›ืžื• "

ืœื›ืœ ืืชืจ ืฉื ืจืฆื” IP"(. ื›ืš, ืœื ื ืฆื˜ืจืš ืœืฉื ืŸ ื›ืชื•ื‘ื•ืช 81.391.232.11"

ืœื”ื™ื›ื ืก ืืœื™ื•. ื‘ืชื™ ืขืกืง ืฆืจื™ื›ื™ื ืœื”ื’ื“ื™ืจ ื›ืชื•ื‘ื•ืช ื“ื•ืžื™ื™ืŸ ื›ื—ืœืง ืžื”ืžื™ืชื•ื’

ืฉืœื˜ื™ ื—ื•ืฆื•ืช "ืœืขื•ื“ ืžื™ื“ืข: ื’ืฉื• ืœืืชืจ ืฉืœื ื• ืฉืœื”ื )ื›ื™ ืื™ ืืคืฉืจ ืœืฉื™ื ืขืœ

DNS"(. ืžืคืชื—ื™ ืฉื™ืจื•ืชื™ื ื“ื™ื’ื™ื˜ืœื™ื™ื ื–ืงื•ืงื™ื ืœืžืขืจื›ื•ืช 81.391.232.11

ื‘ืฉื‘ื™ืœ ืœื‘ืฆืข ืื™ื–ื•ืŸ ืขื•ืžืกื™ื ื‘ื™ืŸ ืžืกืคืจ ืฉืจืชื™ื.

ืื—ืช ื•ื ืžืฆื ืขื™ืžื ื• ืžืื– ืฉื ื•ืช ื”ืฉืžื•ื ื™ื ื”ืžื•ืงื“ืžื•ืช ื•ื”ื™ื  DNS-ื” ืคืจื•ื˜ื•ืงื•ืœ

, 3891ื‘ืฉื ืช Paul Mockapetrisืข"ื™ ื”ื”ืฆืขื” ื”ืžืงื•ืจื™ืช ืœืคืจื•ื˜ื•ืงื•ืœ ื ื›ืชื‘ื” ื ื˜. ื™ืŸ ืฉืœ ื”ืื™ื ื˜ืจื™ืžืื‘ื ื™ ื”ื‘ื 

ืฉื ื™ื(. ื”ืžืขืจื›ืช ืขื‘ืจื” ืฉื™ื ื•ื™ื™ื 11ืžืกืžื›ื™ื ืฉื•ื ื™ื ืœื™ืชืจ ื“ื™ื•ืง, ืœืื•ืจืš 22) RFCืžืกืžื›ื™ ื•ื”ื•ื’ื“ืจื” ื‘ืžืกืคืจ

ืžื”ื™ืจื•ืช, -(" ืฉืœื•ืฉื” ื“ื‘ืจื™ื IETF) ื”ืื™ื ื˜ืจื ื˜ ืฉืœ ื”ื”ื ื“ืกื™ ื”ืžืฉื™ืžื” ื›ื•ื—ืจื‘ื™ื, ื›ืืฉืจ ื‘ืจืืฉ ืžืขื™ื™ื ื™ื• ืฉืœ "

ื™ืขื™ืœื•ืช ื•ืชืื™ืžื•ืช ืœืื—ื•ืจ.

ืœืžืขืจื›ืช, ื•ืขืฉื” ืฉื™ื ื•ื™ื™ื ื”ื“ืจื’ืชื™ื™ื ืžืื•ื“, ื›ืš ืฉืžืจื‘ื™ืช ื”ืžื›ืฉื™ืจื™ื ื•ื”ื—ื‘ืจื•ืช ื›ืœ ืžืกืžืš ืฉื ื›ืชื‘ ื”ื•ืกื™ืฃ ื ื“ื‘ืš

ื™ื›ืœื• ืœื”ืกืชื’ืœ ื•ืœื”ืชืื™ื ืืช ืขืฆืžืŸ ืœืื•ืจืš ื–ืžืŸ.

[ Team Fortress 2ืžืงื•ืจ:]

Page 36: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

36 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ืฉื ื™ื•ืช( ืืช ื›ืœ ื”ืชื”ืœื™ืš ื”ืžื•ืจื›ื‘ ืฉืœ 2-ื“ืง' )ื• 2-" ืฉืžืกื‘ื™ืจ ื‘DNS Made Easy Videosื™ืฉ ืกืจื˜ื•ืŸ ื ื”ื“ืจ ืฉืœ "

:DNS, ืžื”ื‘ืงืฉื” ืฉืœ ื”ืžื—ืฉื‘ ื•ืขื“ ืœืงื‘ืœืช ืชืฉื•ื‘ื” ืžืฉืจืช DNSืื™ืš ืขื•ื‘ื“ ืคืจื•ื˜ื•ืงื•ืœ

DNS Explained | DNS Made Easy Videos

ืฉืื—ืจืื™ DNS". ืžื“ื•ื‘ืจ ื‘ืฉืจืช NameServer"-ื”ื—ืœืง ื”ื—ืฉื•ื‘ ื‘ืคืจื•ื˜ื•ืงื•ืœ ืฉืžืขื ื™ื™ืŸ ืื•ืชื ื• ื”ื•ื ืชืคืงื™ื“ื• ืฉืœ ื”

ื›ื•ื ื•ืช ื•ืืžื™ืชื™ื•ืช ืžืขื•ืจืขืจืช ืœืชืช ืชืฉื•ื‘ื•ืช ื -(, ื•ื‘ืื•ืชื• ืื–ื•ืจ ื”ื•ื ื”ืกื›ืžื•ืช ื”ื‘ืœืชื™Zoneืขืœ ืื–ื•ืจ ืžืกื•ื™ื )

ืฉืžื—ื–ื™ืง DNS-(. ืœื“ื•ื’ืžื”, ืฉืจืช ื”authoritative answers -ืœื‘ืงืฉื•ืช ืฉืœ ืœืงื•ื—ื•ืช )ืชืฉื•ื‘ื•ืช ืกืžื›ื•ืชื™ื•ืช

-ื”ื•ื ืฉืจืช ืกืžื›ื•ืชื™ ืฉืื—ืจืื™ ืขืœ ื›ืœ ื“ื•ืžื™ื™ืŸ ืฉื ื’ืžืจ ื‘ -" com.ื‘ืชื•ื›ื• ืืช ื›ืœ ื”ื“ื•ืžื™ื™ื ื™ื ืฉืื—ืจืื™ื™ื ืขืœ "

".com ."

ืฉืžื•ื’ื“ืจ DNSื ื•ืกืคืช, ืฉืจืช ื›ืœ ืชืฉื•ื‘ื” ืฉื”ื•ื ื™ื—ื–ื™ืจ ื”ื™ื ืชืฉื•ื‘ื” ืืžื™ืชื™ืช ื•ื ื›ื•ื ื”, ืœื›ืœ ื”ื“ืขื•ืช. ื“ื•ื’ืžื”

" ืื—ืจืื™ ืขืœ ื›ืœ ื‘ืงืฉื” ืฉืงืฉื•ืจื” ืœื“ื•ืžื™ื™ืŸ ื”ืžืชื•ืืจ google.com( ืฉืœ "Nameserver)ืงื™ืฆื•ืจ ืฉืœ NSื›ืฉืจืช

(google.comื’ื™ืฉื” ืœ .)-"maps.google.com ืœืžืฉืœ, ืชืขื‘ื•ืจ ื’ื ื“ืจืš ื”ืฉืจืช ื”ืื—ืจืื™ ืขืœ ื›ืœ ื›ืชื•ื‘ื•ืช ,"

".com" ื•ื’ื ื“ืจืš ื”ืฉืจืช ืฉืœ "google.com ืขืœ ืžื ืช ืœืงื‘ืœ ื›ืชื•ื‘ืช "IP .ื‘ืขื™ืงืจื•ืŸ, ื›ืœ ืื—ื“ ื™ื›ื•ืœ ืœืงื ื•ืช ืžื“ื•ื™ืงืช

ื“ื•ืžื™ื™ืŸ -ื•ื™ื›ื•ืœ ืœืฉืœื•ื˜ ื‘ื›ืœ ืชืช Nameserverืฉื™ืฉืžืฉ ื‘ืชื•ืจ DNSื›ืชื•ื‘ืช ื“ื•ืžื™ื™ืŸ, ืœื”ื’ื“ื™ืจ ืœื” ื›ืชื•ื‘ืช ืœืฉืจืช

ื“ื•ืžื™ื™ืŸ ื“ื™ื ืืžื™ื™ื, ืฉื ื™ืชืŸ ืœืงืœื•ื˜ ื•ืœืขื‘ื“.-ืžืกื™ื™ืข ืœื ื• ื’ื ืœื”ื’ื“ื™ืจ ืชืชื™ NS-ืฉืžื’ื™ืข ืœื›ื™ื•ื•ื ื•. ื”ืฉื™ืžื•ืฉ ื‘

ื›ืชื•ื‘ื•ืช ื“ื•ืžื™ื™ืŸ

ื”ื ืžืฆืื™ื ื”ืืชืจื™ื ืžืฉืืจ ืื•ืชื• ืฉืžื‘ื“ื™ืœ, ื”ืื™ื ื˜ืจื ื˜ ืจืฉืชื‘ ืืชืจ ืฉืœ ื™ื™ื—ื•ื“ื™ ืฉืื”ื•ื ( ืžืชื—ื ืฉื) ื“ื•ืžื™ื™ืŸ

ืœื’ืฉืช ื‘ืฉื‘ื™ืœ ืœืงื‘ืœ ืืช ื”ืžื™ื“ืข DNSืžืขืจื›ืช ื”ื“ื•ืžื™ื™ื ื™ื ืขื•ื–ืจืช ืœื ื• ืœื”ืชืžืฆื ื•ืœื“ืขืช ืœืื™ื–ื” ืฉืจืช .ื‘ืจืฉืช

ืžืขื™ืŸ ืžืคืช ื“ืจืš ืœืžื™ื“ืข ืฉืื ื—ื ื• ืžื—ืคืฉื™ื. -ืฉืื ื—ื ื• ืฆืจื™ื›ื™ื

ืœื• ื”ื›ืคื•ืคื™ื ื™ื ื™ืื”ื“ื•ืžื™ ื•ื‘ื›ืœ ืฉืœื•ื‘ื“ื•ืžื™ื™ืŸ ืœื”ืฉืชืžืฉ ื™ื›ื•ืœื“ื•ืžื™ื™ืŸ ื‘ืขืœ. ืฉื™ื˜ืชื™ื• ื”ื™ืจืืจื›ื™ ืžื‘ื ื”ื”ืžืชื—ื ืœืฉื

ื”ืฉืœื™ื˜ื” ื‘ืขืœ ,ืœืžืฉืœ. ืœืื—ืจื™ื ื‘ื—ืœืงื ืื• ื‘ื›ื•ืœื ื”ืฉืœื™ื˜ื” ืืช ืœื”ืขื‘ื™ืจ ืื•, (Subdomains-)ื”ื™ื“ื•ืขื™ื ื›

ื•ื‘ืขืœ, cloudfront.net ืœืžืฉืœ, ืœื• ื”ื›ืคื•ืฃ ืชื—ื•ื ืฉื ืœืจืฉื•ื ืื—ื“ ืœื›ืœ ืžืืคืฉืจ" net.ืฉืื—ืจืื™ ืขืœ ื”ืžืชื—ื "

ืœืืคืฉืจ ืื•, ืœื• ื•ืคื™ืื”ื›ืค ื”ืชื—ื•ื ื•ื‘ืฉืžื•ืช ื‘ื• ืœื”ืฉืชืžืฉ ื™ื›ื•ืœ cloudfront.net ื”ืžืฉื ื™ ื”ืชื—ื•ื ื‘ืฉื ื”ืฉืœื™ื˜ื”

(.ืขื•ืฉื” ืฉื”ื•ื ืžื” ื’ื ื•ื–ื”) ื‘ื”ื ืœื”ืฉืชืžืฉ ืœืื—ืจื™ื

[ | ITGeared.comHow DNS Works]ืžืงื•ืจ:

Page 37: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

37 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ืจืžืช. ื•ืคื•ื—ืชืช ื”ื•ืœื›ืช ื›ืœืœื™ื•ืช ื“ืจื’ืช ื”ืžืฆื™ื™ื ื•ืช, ื‘ื ืงื•ื“ื•ืช ื”ืžื•ืคืจื“ื•ืช, ืจืžื•ืช ื‘ืžืกืคืจ ืžืžื—ืจื•ื–ื•ืช ืžื•ืจื›ื‘ ื“ื•ืžื™ื™ืŸ

ื”ืจืžื” ื”ื™ื( Top Level Domain - TLD ื”ืžื›ื•ื ื” - ื‘ื™ื•ืชืจ ื”ื™ืžื ื™ืช ื”ืจืžื”) ื”ืกื™ื•ืžืช ืื• ื”ืขืœื™ื•ื ื” ื”ืžืชื—ื

ืžืกืžืŸ ืืช ื™ืฉืจืืœ. il. ื‘ืžืงืจื” ืฉืœ ื”ื“ื•ื’ืžื” ืœืžืขืœื”, ื‘ื™ื•ืชืจ ื”ื›ืœืœื™ืช

ืœื‘ืกื•ืฃ, ืฉื ื”ื“ื•ืžื™ื™ืŸ ืขื•ื–ืจ ืœื ื• .(co.ื‘ื—ื‘ืจื” ืžืกื—ืจื™ืช ) ืžื“ื•ื‘ืจ ื›ื™ ืžืฆื™ื™ื ืช( ืžื™ืžื™ืŸ) ื™ื”ื™ื”ืฉื  ื”ืžืชื—ื ืจืžืช

:Digital Whisperืœื“ืขืช ืœืื™ื–ื” ื—ื‘ืจื” ืžืกื—ืจื™ืช ื™ืฉืจืืœื™ืช ืžืชื›ื•ื•ื ื™ื:

Internationalized Domain Name - IDN ื•ื›ืš ืžืืคืฉืจ ืžืื ื’ืœื™ืช ืฉื•ื ื” ื‘ืฉืคื”( ืžืชื—ื ืฉื) ื“ื•ืžื™ื™ืŸ ืฉื ื”ื•ื(

ื‘ืื•ื ื™ื‘ืจืกื™ื˜ื” 3889 ื‘ืฉื ืช ื”ื—ืœ IDNs-ื” ืฉืœ ื”ื˜ื›ื ื•ืœื•ื’ื™ื” ืคื™ืชื•ื—. "(comื—ืจื•ื–.ืืช ืงื™ื•ืžื ืฉืœ ืืชืจื™ื ื›ืžื• "

. Punycode-ื” ื”ื•ื IETF-ื” ืืจื’ื•ืŸ ื™ื“ื™ ืขืœ IDNs ื•ืจืขื‘ ื›ืกื˜ื ื“ืจื˜ ืฉื”ื•ืกื›ื ื”ืงื™ื“ื•ื“. ืกื™ื ื’ืคื•ืจ ืฉืœ

ื‘ืžื“ื™ื ื•ืช ื”ืื™ื ื˜ืจื ื˜ ืฉืœ ื”ื—ื“ื™ืจื” ืื—ื•ื– ื”ืขืžืงืช ืขื ื ื“ืจืฉ ื›ืฉื™ืจื•ืช ืžืงื•ืžื• ืืช ืชื•ืคืก IDNs-ื‘ ื”ืฉื™ืžื•ืฉ

.ืื‘ื™ืกื•ื“ ืœื˜ื™ื ื™ื•ืช ืฉืื™ื ืŸ ื‘ืื•ืชื™ื•ืช ื”ื™ื ื‘ื”ืŸ ื ื›ืชื‘ืช ื•ื”ืฉืคื”, ืžืื ื’ืœื™ืช ืฉื•ื ื” ื”ืžืงื•ืžื™ืช ืฉืฉืคืชื

ื‘ืกื•ืฃ )ืœืฆื•ืจืš ืชืื™ืžื•ืช ืžืงืกื™ืžืœื™ืช ืœืื—ื•ืจ( ื•ื ื™ืชืŸ ASCII-ื’ื ืžืชื•ืจื’ืžื™ื ืœ Punycodeืฉืžื•ืช ื“ื•ืžื™ื™ืŸ ื‘ืคื•ืจืžื˜

".--xnืœื–ื”ื•ืช ืื•ืชื ืœืคื™ ื”ืชื—ื™ืœื™ืช "

[ Seobility Wiki -What is Punycode? Definition and Explanation]ืžืงื•ืจ:

Page 38: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

38 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ืžื’ื“ื™ืจ ืžืกืคืจ 1.1.2", ืกืขื™ืฃ Specification And Implementation - Names Domain: 1035 Rfcืœืคื™ "

ื”ื’ื‘ืœื•ืช:

ืฉืœ ืื•ืจื›ื• label ื‘ื•ื“ื“ ืžืงื•ื“ื“ ืžื™ื“ืข ืื•ืจืš - ื‘ื“ื•ืžื™ื™ืŸ ื‘ื•ื“ื“ (ืชื ืงื•ื“ื• ืฉืชื™ ื‘ื™ืŸ ืฉื ืžืฆื ื”ืžื™ื“ืข - ."XXXX )".

ื‘ืื•ืจื›ื•. ืชื•ื•ื™ื 21 ืขืœ ื™ืขืœื” ืœื

ืชื•ื•ื™ื 251 ืžืขืœ ื™ืขืœื” ืœื ื”ื›ื•ืœืœ ื”ืžื™ื“ืข ืื•ืจืš - ื“ื•ืžื™ื™ืŸื›ืœ ื” ืฉืœ ื”ืžืงืกื™ืžืœื™ ืื•ืจื›ื•.

ื’ื•ื“ืœ ื—ื‘ื™ืœืชUDP ืžืคืจื•ื˜ื•ืงื•ืœDNS ื’ื ืž(-RFC 1035 )- ื’ื•ื“ืœื” ืฉืœ ื”ื•ื“ืขืชUDP ืœื ืชื”ื™ื” ื’ื“ื•ืœื” ืž-

.TCPื•ืœ ื‘ืชื™ื. ื‘ืžื™ื“ื” ื•ืชื—ืจื•ื’ ืžื”ื’ื•ื“ืœ, ื”ื”ื•ื“ืขื” ืชื™ืืœืฅ ืœืขื‘ื•ืจ ื“ืจืš ืคืจื•ื˜ื•ืง 532

ื•ืกืคืจื•ืช ื‘ืื ื’ืœื™ืช ืื•ืชื™ื•ืช ืจืง ื™ื›ืœื•ืœ ืขืฆืžื• ื”ื“ื•ืžื™ื™ืŸ -ื”ื’ื‘ืœื•ืช ืขืœ ื”ืื•ืชื™ื•ืช (1-8A-Za-z ,)ื”ืื•ืช ื›ืืฉืจ

ื‘ืžืงื•ื (--) ื‘ืจืฆืฃ ืคืขืžื™ื™ื ืœื”ื•ืคื™ืข ื™ื›ื•ืœื” ืื™ื ื” ื–ื• ืื•ืช ื•ื’ื( -) ืžืงืฃ ื”ื™ื ืžืœื‘ื“ื ื”ืžื•ืชืจืช ื”ื™ื—ื™ื“ื”

-google' ืœื“ื•ื’) ื‘ืกื•ืคื• ืื•( google.com-' ืœื“ื•ื’) ื“ื•ืžื™ื™ืŸ ื‘ืชื—ื™ืœืช, (Punycode-ื”ืฉืœื™ืฉื™ ื•ื”ืจื‘ื™ืขื™ )ืฉืžื•ืจ ืœ

.com .)ื”ืชืงื ื” ืฉืœ ื™ื•ืชืจ ืžื•ืงื“ืžืช ื’ืจืกื” ,RFC 952 ,ื‘ืกืคืจื•ืช ื•ื™ืกืชื™ื™ื ื™ืชื—ื™ืœ ื’ื ืฉื“ื•ืžื™ื™ืŸ ืื™ืฉืจื” ืœื ,

)ืขื•ืงื‘ื™ื ืขื“ื™ื™ืŸ?(. RFC 1123-ืืš ื–ื” ื”ืฉืชื ื” ื‘

ื”ื’ื“ืจืช ื”ืžื™ื“ืข ื”ืžื•ืขื‘ืจ

ื”ื™ื ืืคื™ื•ืŸ ื”ืžื™ื“ืข ืฉื ืจืฆื” ืœื”ืขื‘ื™ืจ. ื›ืžื•ื‘ืŸ, DNSื”ืฉืœื‘ ื”ืจืืฉื•ืŸ ื‘ื‘ื ื™ื™ืช ืฉื™ื˜ื” ืžืฉืœื ื• ืœื”ืขื‘ืจืช ืžื™ื“ืข ื“ืจืš

ื”ืžืชื•ืืจื•ืช ืžืขืœื” ื”ืŸ ืžืื•ื“ ื ื•ืงืฉื•ืช. ื ืฆื˜ืจืš ืœื”ืชืžื•ื“ื“ ืขื ื›ืœ ื”ื’ื‘ืœื” ื‘ื ืคืจื“, ืชื•ืš ืฉืžื™ืจื” ืขืœ ืฉื”ื”ื’ื‘ืœื•ืช

.ืœืงื•ื“ื“ ื•ืœื”ืขื‘ื™ืจ ืขื ื”ืฉื™ื˜ื” ืฉืœื ื• ื›ืœ ืžื™ื“ืข ื‘ื™ื ืืจื™ื”ื™ื›ื•ืœืช

ื•ืžืงืฃ | ื”ืคืชืจื•ืŸ: ืงื™ื“ื•ื“ ืžื™ื“ืข ื‘ื‘ืกื™ืก ืื—ืจ A-Z ,1-9ื”ื‘ืขื™ื”: ืžื•ื’ื‘ืœ ืจืง ืœืื•ืชื™ื•ืช

ืชืžืฉ ื‘ื”ืŸ )ืื• ื™ื•ืชืจ ื ื›ื•ืŸ, ื”ื‘ืขื™ื” ื”ืจืืฉื•ื ื” ืฉื ืจืฆื” ืœื”ืชืžื•ื“ื“ ืื™ืชื” ื”ื™ื ื‘ืขื™ื™ืช ื”ืื•ืชื™ื•ืช ืฉื ื™ืชืŸ ืœื”ืฉ

ื”ืื•ืชื™ื•ืช ืฉืื ื—ื ื• ืœื ื™ื›ื•ืœื™ื ืœื”ืฉืชืžืฉ ื‘ื”ืŸ(. ืขืœ ืžื ืช ืœื”ืขื‘ื™ืจ ื›ืœ ืกื•ื’ ืฉืœ ืžื™ื“ืข, ื ืฆื˜ืจืš ืžืขืจื›ืช ืฉืชืงื•ื“ื“

ื›ืœ ืžื™ื“ืข ื‘ื™ื ืืจื™ ืœืื•ืชื™ื•ืช ืฉื ื™ืชืŸ ืœื”ืชืžื•ื“ื“ ืื™ืชืŸ. ื ื•ื›ืœ ืœื™ืฆื•ืจ ืžืขืจื›ืช ืงื™ื“ื•ื“ ืฉืชืขืฉื” ื–ืืช, ืืš ืขื“ื™ื™ืŸ ื™ืฉ

ืฉื ืขื‘ื•ืจ ืขืœ ื”ื”ื’ื‘ืœื•ืช ื”ืกืคืฆื™ืคื™ื•ืช ื™ืฉ ื™ื•ืชืจ ืžื“ื™ ื”ื’ื‘ืœื•ืช ืžืกื‘ื™ื‘ ืœืื•ืช ื”ื–ืืช, ื•ื™ื™ืชื›ืŸ -ื‘ืขื™ื” ืขื ื”ืžืงืฃ

Page 39: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

39 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

-a( ืื•ืชื™ื•ืช 22ื’ื“ื•ืœื•ืช, ) A-Z( ืื•ืชื™ื•ืช 22ืืœื™ื”. ืœื›ืŸ, ืœืงื—ืชื™ ืืช ื”ื”ื—ืœื˜ื” ืœื•ื•ืชืจ ืขืœ ื”ืžืงืฃ, ื•ืœืขื‘ื•ื“ ืจืง ืขื )

z ืื•ืชื™ื•ืช(: 22 -)ืกื”"ื› 1-8( ืกืคืจื•ืช 31)-ืงื˜ื ื•ืช ื•

ื ืฆืœ ืืช ื›ืœ ื”ืื•ืชื™ื•ืช ื”ืžื•ืชืจื•ืช ื‘ื›ืชื•ื‘ืช ื“ื•ืžื™ื™ืŸ )ืœืžืขื˜ ื”ืžืงืฃ(. ื–ื” , ื”ืžBase62ื‘ืงื™ื“ื•ื“ ืขืœ ื›ืŸ, ื”ืฉืชืžืฉืชื™

ืคื•ืชืจ ืืช ื”ื‘ืขื™ื” ื”ืžืชื•ืืจืช, ื•ืžืืคืฉืจ ืœื ื• ืœื”ืขื‘ื™ืจ ื›ืœ ืกื•ื’ ืฉืœ ืžื™ื“ืข ืฉื™ืขื‘ื•ืจ ืืช ื”ืœื™ืš ื”ืงื™ื“ื•ื“ ื”ืžืชื•ืืจ.

. ื›ืœื•ืžืจ, ืขืœ ืžื ืช 34%-ื”ื•ื ืžื’ื“ื™ืœ ืืช ืื•ืจืš ื”ืžื™ื“ืข ื‘ -ืขื ื–ืืช, ื—ื™ืกืจื•ืŸ ืžืฉืžืขื•ืชื™ ืงื™ื™ื ื‘ืงื™ื“ื•ื“ ื”ื–ื”

ืชื•ื•ื™ื. ื ื™ืชืŸ ืœื—ืฉื‘ ืืช ื”ื™ื—ืก ื‘ื™ืŸ ืื•ืจืš ื”ืžื™ื“ืข ื”ืžืงื•ื“ื“ ืœืื•ืจืš 311ื ืฆื˜ืจืš ื‘ืชื™ื ื‘ืฉื™ื˜ืช ื”ืงื™ื“ื•ื“, 311ืœื™ื™ืฆื’

)ื›ื™ ืœื›ืœ ื‘ื™ืช 252ืฉืœ ื”ื‘ืกื™ืกื™ื ืฉืœื”ื. ื™ื—ื™ื“ืช ื”ื‘ืกื™ืก ืฉืœ ื‘ื™ืช ื”ื•ื ln-ื”ืžื™ื“ืข ื”ื’ื•ืœืžื™ ืœืคื™ ื”ื™ื—ืก ื‘ื™ืŸ ืขืจื›ื™ ื”

22)ื›ื™ ืœื›ืœ ืื•ืช ื™ืฉ ืจืง 22(, ื•ื™ื—ื™ื“ืช ื”ื‘ืกื™ืก ื‘ืงื™ื“ื•ื“ ื”ื—ื“ืฉ ื”ื•ื 0xFFืขื“ 0x00-ืž :ืืคืฉืจื•ื™ื•ืช 252ื™ืฉ

ืืคืฉืจื•ื™ื•ืช(:

ln(256)

ln(62)โ‹… 100% = 134.3%

ื”ื‘ืขื™ื”: ืœืžื” ืœืคืขืžื™ื ื–ื” ืขื•ื‘ื“ ื•ืœืคืขืžื™ื ืœื?

pingื‘ืžืขืจื›ื•ืช ืœื™ื ื•ืงืก. ื’ื digื•ืขื Windowsื‘ืžืขืจื›ื•ืช nslookupื”ืฉื™ืžื•ืฉ ื‘ืงื™ื“ื•ื“ ื”ื–ื” ืขื•ื‘ื“ ื”ื™ื˜ื‘ ืขื

ืœื›ืชื•ื‘ื•ืช ื”ื“ืจื•ืฉื•ืช. ืขื ื–ืืช, ื”ื•ืคืชืขืชื™ ืœื’ืœื•ืช DNS)ื‘ืฉืชื™ ืžืขืจื›ื•ืช ื”ื”ืคืขืœื”( ื”ืฆืœื™ื— ืœื”ื•ืฆื™ื ื‘ืงืฉื•ืช

)ื•ื—ื•ื–ืจืช ืขืœ ืขืฆืžื” ืžืกืคืจ ืคืขืžื™ื(. RFC-ื“ืจื™ืฉื” ืฉืงื™ื™ืžืช ื‘ืชื•ืš ืื—ื“ ืžืžืกืžื›ื™ ื”ืฉื”ื ืื™ื ื ืžืžืœืื™ื

Page 40: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

41 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

":Clarification Insensitivity Case DNS: RFC4343ืžืชื•ืš "

" ื•ื“ื•ืžื™ื ืœื•. ื”ืกื™ื‘ื” Google.com" ,"google.com" ,"GooGlE.coMื‘ื”ื’ื“ืจื”, ืœื ืืžื•ืจ ืœื”ื™ื•ืช ื”ื‘ื“ืœ ื‘ื™ืŸ "

ื•ืœื ืžื•ืฉืคืข ืžืื•ืชื™ื•ืช ื’ื“ื•ืœื•ืช ืื• Case-insensitiveืืžื•ืจ ืœื”ื™ื•ืช DNSื”ื”ื’ื™ื•ื ื™ืช ืœื›ืš ื”ื™ื ื›ื™ ืคืจื•ื˜ื•ืงื•ืœ

)ืื•ืชื™ื•ืช lowercase-ื”ืžืจืช ื›ืœ ื”ื“ื•ืžื™ื™ืŸ ืœ -ื“ื•ืจืฉ ืœื‘ืฆืข ื”ืœื™ืš ืฉืœ "ื ื•ืจืžืœื™ื–ืฆื™ื”" RFC4343ืงื˜ื ื•ืช.

ื•ื›ื ื•ืช ื”ืœืœื• ืืžื ื ืœื ืžื‘ืฆืขื•ืช ืืช ื”ื ื•ืจืžืœื™ื–ืฆื™ื”, ื’ื“ื•ืœื•ืช ื”ื•ืคื›ื•ืช ืœืงื˜ื ื•ืช, ื•ืกืคืจื•ืช ื ืฉืืจื•ืช ืœืœื ืฉื™ื ื•ื™(. ื”ืช

ืื‘ืœ ื™ืฉ ืกื™ื›ื•ื™ ื’ื‘ื•ื” ืžืื•ื“ ืฉื‘ืจืฉืช ืืจื’ื•ื ื™ืช ืฉืžื•ื’ื“ืจืช ื”ื™ื˜ื‘ ื›ืŸ ื™ืชื‘ืฆืข ื”ืœื™ืš ื›ื–ื”. ืขืœ ื›ืŸ, ื ืฆื˜ืจืš ืœื”ื’ื“ื™ืจ

ืžื—ื“ืฉ ืืช ื”ืงื™ื“ื•ื“ ืฉืœื ื•, ื‘ืฆื•ืจื” ืฉืชืขื‘ื•ืจ ืืช ื”ืžืขืจื›ืช ื”ื–ื•.

1-8( ืกืคืจื•ืช 31)-ื•ืงื˜ื ื•ืช a-z( ืื•ืชื™ื•ืช 22)-ื ื™ืฆื•ืจ ืืช ื”ืงื™ื“ื•ื“ ืžื—ื“ืฉ. ื›ืขืช, ื”ืงื™ื“ื•ื“ ื™ืฆื˜ืจืš ืœื”ื™ื•ืช ืžื•ืจื›ื‘ ืž

ืื•ืชื™ื•ืช(: 12 -)ืกื”"ื›

, ืืฉืจ ืžื ืฆืœืช ืืช ื›ืœ ื”ืื•ืชื™ื•ืช Base36 -ืื•ืชื™ื•ืช, ื ืงื‘ืœ ืืช ืฉื™ื˜ืช ื”ืงื™ื“ื•ื“ ื”ื—ื“ืฉื” ืฉืœื ื• 22ืขื ื•ื™ืชื•ืจ ืขืœ

ื”ืžื•ืชืจื•ืช ื‘ื›ืชื•ื‘ืช ื“ื•ืžื™ื™ืŸ )ื—ื•ืฅ ืžืžืงืฃ(, ื•ืฉืชืขื‘ื•ืจ ืžืขืจื›ื•ืช ืฉืขื•ืฉื•ืช ื ื•ืจืžืœื™ื–ืฆื™ื” ืœื“ื•ืžื™ื™ืŸ. ืœืขื•ืžืช ืฉื™ื˜ืช

ืœืขื•ืžืช ื”ืžื™ื“ืข ื”ื‘ื™ื ืืจื™ 61%-ื’ื“ื™ืœื” ื‘ื™ื“ืข, ื•ื‘ืื•ืจืš ื”ืž 35%-ื”ืงื™ื“ื•ื“ ื”ืงื•ื“ืžืช, ืžื“ื•ื‘ืจ ื‘ื’ื“ื™ืœื” ื‘

.ื”ืžืงื•ืจื™

ื”ื™ื›ื•ืœืช ืœื”ื’ื“ื™ืจ ื‘ืขืฆืžื ื• ืืช ืฉื™ื˜ืช ื”ืงื™ื“ื•ื“ ื—ืฉื•ื‘ื” ืœื™ ืžืื•ื“ ื‘ืคืจื•ื™ืงื˜ ื”ื–ื”, ื•ืขืœ ื›ืŸ ื›ืชื‘ืชื™ ื‘ืกืคืจื™ื™ื” ืžื—ืœืงื”

" ืฉื ื•ืชื ืช ืœืžืฉืชืžืฉ ืฉืœื™ื˜ื” ืžืœืื” ืขืœ ื™ืฆื™ืจืช ื›ืœ ืงื™ื“ื•ื“, ื‘ื›ืœ ื‘ืกื™ืก ื•ื‘ื›ืœ ืื•ืจืš. ื‘ืชื•ืš ื”ื›ืœื™ Alphabetื‘ืฉื "

, ืžืฉืชืžืฉ ื™ื›ื•ืœ ืœื”ื’ื“ื™ืจ ืื™ืœื• ืื•ืชื™ื•ืช ื”ื•ื ืจื•ืฆื” ื‘ืฉื™ื˜ืช ื”ืงื™ื“ื•ื“ ืฉืœื• ื•ื‘ืื™ื–ื” ืกื“ืจ )ืขื DNSExfilืฉืœื™,

ืฉืชื•ืืจ ืœืžืขืœื” )ืขื‘ื•ืจ ืืœื• ืฉื™ืขื‘ื“ื• ืขื Base62ืืคืฉืจื•ืช ืœืืงืจืื™ื•ืช(. ื›ืš, ื™ื”ื™ื” ื ื™ืชืŸ ืœืขื‘ื•ื“ ื’ื ืขื ืงื™ื“ื•ื“

nslookup ืื•dig ื’ื ืขื ืงื™ื“ื•ื“ ,)Base36 ืขื ืžืขืจื›ื•ืช ืฉืžื‘ืฆืขื•ืช ื ื•ืจืžืœื™ื–ืฆื™ื”( ื•ื’ื )ืขื‘ื•ืจ ืืœื• ืฉืžืชืžื•ื“ื“ื™ื

Page 41: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

41 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ืขื ื›ืœ ืงื™ื“ื•ื“ ืื—ืจ ืฉืชืจืฆื• )ื›ื•ืœืœ ืฉื™ื ื•ื™ ืกื“ืจ ื”ืื•ืชื™ื•ืช ื‘ืื•ืคืŸ ืืงืจืื™(. ื”ืžืขืจื›ืช ืžื›ื™ืœื” ืืžืฆืขื™ ื”ื’ื ื” ืฉื™ื•ื“ืขื™ื

ืœื”ืชืจื™ืข ืžืฉืชืžืฉื™ื ืฉื™ื ืกื• ืœื”ืฉืชืžืฉ ื‘ืงื™ื“ื•ื“ ืœื ืชืงื™ืŸ )ื›ืžื• ืœื”ืฉืชืžืฉ ื‘ืื•ืชื” ืื•ืช ืคืขืžื™ื™ื(.

Bitcoin-ืžืขืชื™ืงื™ื ืž - Base32-ื• Base58ื‘ื•ื ื•ืก: ืงื™ื“ื•ื“

Satoshi NakamotoืŸ ืžื” ื™ืฆื ืœื™ ืœื”ืชื‘ื•ื ืŸ ื‘ืงื•ื“ ืžืงื•ืจ ืฉืœ ืคืจื•ื™ืงื˜ ืฉื›ืชื‘ื• ืงื‘ื•ืฆืช ื.ื ืฉื™ื ืฉื ืงืจืื™ื ืœืคื ื™ ื–ืž

( base58.h. ื‘ืงื•ื‘ืฅ ืกืคืฆื™ืคื™ )ืœืงื•ื“ ื”ืžืงื•ืจ ืฉืœ ื”ืžื˜ื‘ืข ื”ืžื‘ื•ื–ืจ ื‘ื™ื˜ืงื•ื™ืŸืื ื™ ืžืชื›ื•ื•ืŸ, ื›ืžื•ื‘ืŸ, - 2118ื‘ืฉื ืช

ื”ื™ื“ื•ืข, Base64ื‘ืžืงื•ื ื‘ืงื™ื“ื•ื“ Base58ืœืžืฆื•ื ื”ืขืจื” ืฉืžืกื‘ื™ืจื” ืœืžื” ื”ื ื”ื—ืœื™ื˜ื• ืœื”ืฉืชืžืฉ ื‘ืงื™ื“ื•ื“ ื ื™ืชืŸ

" ื‘ื’ืœืœ ื”ื™ื›ื•ืœื•ืช ื”ืื™ื“ื™ืืœื™ื•ืช ืฉืœื• ืœืงื•ื“ื“ ื›ืœ ืžื™ื“ืข ื‘ื™ื ืืจื™ ื•ื”ืฉื™ืžื•ืฉ ื”ื ืจื—ื‘ ASCII Armorืฉืงื™ื‘ืœ ืืช ื”ืฉื "

ื‘ื•:

ื”ื•ื ื˜ื•ื‘ ื™ื•ืชืจ )ื‘ืฉื‘ื™ืœ ื‘ื™ื˜ืงื•ื™ืŸ(: Base58-ื”ื ื”ืขืœื• ืžืกืคืจ ื˜ืขื ื•ืช ื”ื’ื™ื•ื ื™ื•ืช ืœืžื” ืฉื™ืžื•ืฉ ื‘

ืžืฉืชืžืฉื™ื ื™ื›ื•ืœื™ื ืœื”ืขื‘ื™ืจ ืžื˜ื‘ืขื•ืช ื‘ื™ื˜ืงื•ื™ืŸ ื–ื” ืœื–ื” ื‘ืืžืฆืขื•ืช ืฉื™ืžื•ืฉ ื‘ืืจื ืงื™ - ื•ื—ื•ืช ื•ื™ื–ื•ืืœื™ืชื 

ืื•ืชื™ื•ืช(, ื•ื›ืชื•ื‘ืช ื”ืืจื ืง ืขืฆืžื” ื™ื›ื•ืœื” 22-15ื‘ืื•ืจืš Base58-ื‘ื™ื˜ืงื•ื™ืŸ )ืฉื”ื›ืชื•ื‘ืช ืฉืœื”ื ืžืงื•ื“ื“ื•ืช ื‘

$ ื‘ื‘ื™ื˜ืงื•ื™ืŸ, 311ืœืขื‘ื•ืจ ื‘ื™ืŸ ื”ืฆื“ื“ื™ื ื‘ืืžืฆืขื™ื ื“ื™ื’ื™ื˜ืœื™ื™ื ื•ืคื™ื–ื™ื™ื ื›ืื—ื“. ืื ืืœื™ืก ืจื•ืฆื” ืฉื‘ื•ื‘ ื™ืขื‘ื™ืจ ืœื”

ื”ื™ื ื™ื›ื•ืœื” ืœืฉืœื•ื— ืœื• ืืช ื›ืชื•ื‘ืช ื”ืืจื ืง ืฉืœื” ื‘ืืžืฆืขื•ืช ืžื™ื™ืœ, ื”ื•ื“ืขื•ืช ื•ื•ืื˜ืฆืืค, ืื• ื‘ื“ืฃ ืžื•ื“ืคืก )ืื•

ื”ื ืคื•ืฅ ืฉืื™ืชื• ื›ืชื•ื‘ ื”ืžืืžืจ ื”ื–ื”( ื™ื”ื™ื” ืงืฉื” Arialืœื›ืชื•ื‘ ื‘ื›ืชื‘ ื™ื“ื”(. ื‘ื—ืœืง ืžืŸ ื”ืคื•ื ื˜ื™ื )ื›ืžื• ื”ืคื•ื ื˜

ื•ื›ืš ื—ื•ืกืš ืืช ืื™ื ื• ืžืฉืชืžืฉ ื›ืœืœ ื‘ืื•ืชื™ื•ืช ื”ืœืœื•, Base58'. ืœื›ืŸ, ืงื™ื“ื•ื“ O'-', ื•I' ,'l' ,'1ืžืื•ื“ ืœื”ื‘ื“ื™ืœ ื‘ื™ืŸ '

ืกืจื™ืฃ ื™ื›ื•ืœื™ื -ืคื•ื ื˜ื™ื ืžืกื•ื’ ืกื ืก - Arialื”ื‘ืœื‘ื•ืœ ื”ื ืคื•ืฅ )ื–ื” ื“ื™ ื—ื›ื ืœืžืขืŸ ื”ืืžืช(. ื•ื–ื” ืœื ืจืง ืืฆืœ

ื›ื™ ื”ืฉื™ืžื•ืฉ ื‘ื”ื ื‘ื ื•ื™ ืขืœ ื”ื™ื›ื•ืœืช ื”ืžื•ื—ื™ืช ืฉืœื ื• ืœื–ื”ื•ืช ืžื™ืœื™ื ืฉืœืžื•ืช ืœื”ื™ื•ืช ืžืื•ื“ ืžื‘ืœื‘ืœื™ื ื•ื™ื–ื•ืืœื™ืช

ืชื™ื ืœื ืžืฉืชืžืฉื™ื )ื‘ืžืงื•ื ื‘ืœื™ืœ ืื•ืชื™ื•ืช ืืจื•ืš ื›ืžื• ืืจื ืงื™ ื‘ื™ื˜ืงื•ื™ืŸ(. ื–ืืช ื’ื ืื—ืช ื”ืกื™ื‘ื•ืช ืœืžื” ืžืชื›ื 

ืกืจื™ืฃ, ื›ื™ ืงื•ื“ ืœื ื—ื™ื™ื‘ ืœื”ื™ื•ืช ื”ื’ื™ื•ื ื™ ื‘ืžื‘ื ื” ื”ืžื™ืœื•ืœื™ ืฉืœื•, ื•ืœื ื—ื™ื™ื‘ ืœื”ื™ื•ืช ืžืฉื”ื• ืฉืื ื—ื ื• -ื‘ืคื•ื ื˜ื™ื ืกื ืก

ืื•ืช )ื›ื“ื™ ืœื–ื”ื•ืช ืฉื’ื™ืื•ืช ื›ืชื™ื‘ ื˜ื•ื‘ ื™ื•ืชืจ(. -ืื—ืจ-ืงื•ืจืื™ื ื‘ืžืงืฉื” ืื—ืช, ืืœื ืื•ืช

!ื‘ื ื•ืกืฃ ืœืื•ืชื™ื•ืช -ืื•ืชื™ื•ืช ืฉื”ืŸ ืœื ืืœืคืื ื•ืžืจื™ื•ืช = ืคื™ื›ืกื”A-Z ื’ื“ื•ืœื•ืช ื•ืงื˜ื ื•ืช, ืงื™ื“ื•ื“Base64 ืžื›ื™ืœ

' ื•ืืช '=', ืฉื™ื›ื•ืœื™ื ืœื”ื™ื•ืช ื‘ืขื™ื™ืชื™ื™ื. ื–ื” ืœื ืคืฉื•ื˜ ืœื‘ืฆืข ื‘ื“ื™ืงืช ืงืœื˜ ืœืื•ืชื™ื•ืช ื”ืœืœื•. ื‘ืืชืจ \ื’ื ืืช '+', '

Blockchain.com ื ื™ืชืŸ ืœืจืื•ืช ืืช ื”ืžื™ื“ืข ืขืœ ื›ืœ ื›ืชื•ื‘ืช ื‘ื™ื˜ืงื•ื™ืŸ ื‘ืืžืฆืขื•ืช ื”ื›ื ืกืชื” ืœืงื™ืฉื•ืจ ื‘ืฆื•ืจื” ,

ื”ื‘ืื”:

Page 42: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

42 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ืžืฉืžืฉ \ื” ื‘ืื•ืชื” ื“ืจืš )ื›ื™ , ื”ืงื™ืฉื•ืจ ื”ื–ื” ืœื ื”ื™ื” ืžื–ื“ื”\ืื ื›ืชื•ื‘ื•ืช ื‘ื™ื˜ืงื•ื™ืŸ ื”ื™ื• ืžืขืจื‘ื•ืช ืืช ื”ืื•ืช

(. ื–ื” ื”ื™ื” ื”ื•ืคืš ืœืงืฉื” ืžืฉืžืขื•ืชื™ืช ืœื”ื•ืฆื™ื ืœืคื•ืขืœ ืžืขืจื›ืช URL-ืœื”ืคืจื™ื“ ื‘ื™ืŸ ืฉื ื™ ื—ืœืงื™ื ืฉื•ื ื™ื ื‘

" ื•ื–ื” ื‘ื“ื™ื•ืง ืžื” ืฉืขืฉื• !Keep it Stupid Simpleื”ื•ื ืคืฉื•ื˜: " KISSืงื™ืฉื•ืจื™ื ื“ื™ื ืืžื™ืช ื›ื–ืืช. ืขืงืจื•ืŸ

ืชื™ืช, ืœื”ื™ืฆืžื“ ืœื”ื™ืคื˜ืจ ืžื›ืœ ืื•ืช ืฉืขืœื•ืœื” ืœื”ื™ื•ืช ื‘ืขื™ื™ -ื‘ื”ืœื™ืš ื”ื—ืฉื™ื‘ื” ืžืื—ื•ืจื™ ื›ืชื•ื‘ื•ืช ื”ืืจื ืง

ืœื“ื‘ืจื™ื ื”ืคืฉื•ื˜ื™ื ืฉืขื•ื‘ื“ื™ื )ืื•ืชื™ื•ืช ื•ืžืกืคืจื™ื ื‘ืœื‘ื“(.

ืื ืฉื™ื ื‘ืขื•ืœื ืžืชื—ืœืงื™ื ืœืฉืœื•ืฉ: ืืœื• ืฉืžืกืžื ื™ื ื˜ืงืกื˜ - ืœื—ื™ืฆื” ื›ืคื•ืœื” ืขื ื”ืขื›ื‘ืจ ืฆืจื™ื›ื” ืœืกืžืŸ ื”ื›ืœ

ืงืœื™ืง ื›ื“ื™ ืœืกืžืŸ -ืขืœ ื™ื“ื™ ื”ื—ื–ืงืช ื”ื›ืคืชื•ืจ ื”ืฉืžืืœื™ ื•ื’ืจื™ืจืช ื”ืขื›ื‘ืจ )ืื•ื™ ื•ื•ื™ ื–ืžื™ืจ!(, ืืœื• ืฉืœื•ื—ืฆื™ื ื“ืื‘ืœ

ืขื ืžืงืฉื™ ื”ืžืงืœื“ืช ื›ื“ื™ ืœืกืžืŸ ื›ืœ ื˜ืงืกื˜ Ctrl-ื• Shift-ืชืžืฉื™ื ื‘ื—ืœืง ืžื”ื˜ืงืกื˜ )ืื•ืงื™ื™( ื•ืืœื• ืฉืžืฉ

(super-ultra-meta-pro ื›ืฉื–ื” ืžื’ื™ืข ืœื”ืขื‘ืจืช ื›ืกืคื™ื, ื”ื™ื•ืฆืจื™ื ืฉืœ ื‘ื™ื˜ืงื•ื™ืŸ ืจื•ืฆื™ื ืœื•ื•ื“ื ืฉื ืขืชื™ืง ืืช .)

ื›ืœ ื›ืชื•ื‘ืช ื”ืืจื ืง. ื–ื• ืœื ื‘ืขื™ื” ืœืกื•ื’ ื”ืจืืฉื•ืŸ ืฉืœ ื”ืื ืฉื™ื )ืฉืœื•ืงื— ืœื”ื ืžืฉืžืขื•ืชื™ืช ื”ืจื‘ื” ื–ืžืŸ, ืื•

ืื• ื”ืจื•ื•ื— ื‘ืกื•ืฃ(, ื•ืœื ื‘ืขื™ื” ืœืกื•ื’ ื”ืื—ืจื•ืŸ ืฉืœ ื”ืื ืฉื™ื )ืฉื‘ืื•ืคืŸ ื›ื ืจืื” ืžืขืชื™ืงื™ื ื’ื ืืช ื™ืจื™ื“ืช ื”ืฉื•ืจื”

ืงืœื™ืง ืขืœ -ื“ืื‘ืœ -(. ืื•ืœื, ื–ืืช ื›ืŸ ื‘ืขื™ื” ืœืกื•ื’ ื”ืืžืฆืขื™ ืฉืœ ื”ืื ืฉื™ื Shiftืžืกืžื ื™ื ื˜ืงืกื˜ ืขื ื™ื›ื™ืจื•ืจื’

ื˜ืงืกื˜ ืžืกืžืŸ ืžื™ืœื” ืื—ืช )ื›ืœื•ืžืจ, ื”ื•ื ืžื—ืคืฉ ืœืฉื ื™ ื”ืฆื“ื“ื™ื ืจื•ื•ื—ื™ื ืื• ืชื•ื•ื™ื ืฉืื™ื ื ืื•ืชื™ื•ืช ืื• ืžืกืคืจื™ื

ืงืœื™ืง ืขื ื”ืขื›ื‘ืจ ืœื ื”ื™ื™ืชื” -ื™ื˜ืงื•ื™ืŸ ื”ื™ื• ืžื›ื™ืœื•ืช ืกื™ืžื ื™ ืคื™ืกื•ืง, ื“ืื‘ืœื•ืžืกืžืŸ ืขื“ ืืœื™ื”ื(. ืื ื›ืชื•ื‘ื•ืช ื‘

' ืื• '='(. \ื”ื™ื” '+', ' Base64-ืžืกืžื ืช ืืช ื›ืœ ื”ื›ืชื•ื‘ืช ืืœื ืจืง ืขื“ ืœืกื™ืžืŸ ื”ืžื™ื•ื—ื“ )ืฉืื ื”ื™ื” ืžื“ื•ื‘ืจ ื‘

ืœื•ื•ืชืจ ืขืœ ื”ืกื™ืžื ื™ื ื”ืžื™ื•ื—ื“ื™ื. -ืื– ื”ืคืชืจื•ืŸ ื”ืžืชื‘ืงืฉ

ืœื‘ืกื™ืก ื”ื–ื”, ืฉืื™ื ืŸ ื ื›ืชื‘ื• ืžืกืคืจ ื’ืจืกืื•ืช. Base32ื‘ืื•ืคืŸ ื“ื•ืžื”, ื ื™ืชืŸ ืœื”ื—ื™ืœ ืืช ืื•ืชืŸ ืขืงืจื•ื ื•ืช ืขืœ

(. ื“ื•ื’ืžื” human-readableืžืฉืชืžืฉื•ืช ื‘ืื•ืชืŸ ืื•ืชื™ื•ืช ืžื‘ืœื‘ืœื•ืช ื•ื”ืŸ ืขื ืงืจื™ืื•ืช ื˜ื•ื‘ื” ื™ื•ืชืจ ืœืขื™ืŸ ืื ื•ืฉื™ืช )

'. ืกื“ืจ ื”ืื•ืชื™ื•ืช 2'-' ื•vืงื˜ื ื”l( 'L ' ,)ืืš ืœื ืžื›ื™ืœื” ืืช ' 8-ื• 9, 3, ืฉืžื›ื™ืœื” ืืช ื”ืื•ืชื™ื•ืช z-base-32ืœื›ืš ื”ื™ื

ื’ื ืฉื•ื ื”, ืœื›ืš ืฉืื•ืชื™ื•ืช ืฉืงืœ ื™ื•ืชืจ ืœื”ื‘ื“ื™ืœ ื‘ื™ื ื™ื”ืŸ ื™ื•ืคื™ืขื• ื‘ืชื“ื™ืจื•ืช ื’ื‘ื•ื”ื” ื™ื•ืชืจ ืžืื—ืจื•ืช. ื–ื” ืžืงืœ

ืžืฉืžืขื•ืชื™ืช ืขืœ ืžืฉืชืžืฉ ืœื”ืขืชื™ืง ืคื™ื–ื™ืช ืžื—ืจื•ื–ืช ืžืงื•ื“ื“ืช ื‘ื‘ืกื™ืก ื”ื–ื” ื•ืœื‘ื“ื•ืง ืฉื”ื•ื ื›ืชื‘ ื–ืืช ืœืœื

ืฉื’ื™ืื•ืช.

12ื”ืฉืชืžืฉื• ื‘ืžืกืคืจื™ื ืฉืงื•ื“ื“ื• ื‘ื‘ืกื™ืก Nintendoืฉืœ ื—ื‘ืจืช 81-: ืžืกืคืจ ืžืฉื—ืงื™ื ื‘ืฉื ื•ืช ื”ื‘ื•ื ื•ืก ืœื‘ื•ื ื•ืก

. ื”ื™ืฆืจื ื™ืช ื”ื™ืคื ื™ืช ื”ื—ืœื™ื˜ื” ืœื”ื•ืจื™ื“ ืžื”ื’ื“ืจืช ื”ืงื™ื“ื•ื“ ืืช NESื‘ืชื•ืจ ืกื™ืกืžืื•ืช ื‘ืชื•ืš ื”ืžืฉื—ืงื™ื ื‘ืงื•ื ืกื•ืœื•ืช

(, ื›ื“ื™ ืœืžื ื•ืข ืžื”ืกื™ืกืžืื•ืช ื”ืžืงื•ื“ื“ื•ืช ืฉื™ื•ืฆืื•ืช ืžืœื‘ื˜ื ืงืœืœื•ืช ื‘ืื ื’ืœื™ืช. ื›ืœ AEIOUื›ืœ ืื•ืชื™ื•ืช ื”ืชื ื•ืขื” )

ืื—ื“ ื•ืžื” ืฉื”ื•ื ืฆืจื™ืš ืžืงื™ื“ื•ื“...

ื™ ืœื ืจื•ืื” ืกื™ื‘ื” ืœืžื” ื ื•ื—ื•ืช ื•ื•ื™ื–ื•ืืœื™ืช ื—ืฉื•ื‘ื” ื‘ืžื™ื•ื—ื“, ื›ืš ืฉืื ื—ื ื• ื™ื›ื•ืœื™ื ืœื”ืฉืื™ืจ ืœืฆื•ืจืš ื”ืคืจื•ื™ืงื˜ ืฉืœื ื• ืื 

ืืช ื”ืื•ืชื™ื•ืช ื”ืžื‘ืœื‘ืœื•ืช. ืขื ื–ืืช, ืื ืชื—ืœื™ื˜ื• ืœื”ืขื‘ื™ืจ ืืช ื›ืชื•ื‘ื•ืช ื”ื“ื•ืžื™ื™ืŸ ื‘ื“ืจืš ืื—ืจืช ืฉื›ื•ืœืœืช ืฉื›ืชื•ื‘

Base32ืื• Base58ื™ื“ื ื™ )ืœื ื™ื•ื“ืข ืœืžื” ืฉืชืขืฉื• ืืช ื–ื” ืื‘ืœ ืื•ืงื™ื™(, ืื•ืœื™ ื›ืŸ ืชืฉืงืœื• ืœื”ืฉืชืžืฉ ื‘ืงื™ื“ื•ื“

ื‘ืฉื‘ื™ืœ ื›ืš.

Page 43: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

43 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ื™ื—ื™ื“? label-ื”ื‘ืขื™ื”: ืื™ืš ื™ื•ื“ืขื™ื ื›ืžื” ืžื™ื“ืข ื ื›ื ืก ื‘

ื‘ื•ื“ื“ื™ื. ื›ืืžื•ืจ, labels-ื‘ืขื™ื” ื ื•ืกืคืช ืฉืขืœืชื” ื‘ืชื›ื ื•ืŸ ื”ืงื™ื“ื•ื“ ื”ื™ื ืฉื™ื˜ืช ื”ื—ืœื•ืงื” ืฉืœ ื”ืžื™ื“ืข ื”ืžืงื•ื“ื“ ืœ

ืชื•ื•ื™ื, ื•ื”ืชืœื‘ื˜ืชื™ ื‘ื™ืŸ ืฉืชื™ ื“ืจื›ื™ื ืœื—ืœืง ืืช ื”ืžื™ื“ืข: ืงื™ื“ื•ื“ ื•ื—ืœื•ืงื” ืื• 21ืืžื•ืจ ืœื”ื™ื•ืช ืขื“ labelืื•ืจื›ื• ืฉืœ

21)ืงื™ื“ื•ื“ ื•ื—ืœื•ืงื”( ืชืงื•ื“ื“ ืืช ื›ืœ ื”ืžื™ื“ืข ื•ืจืง ืื– ืชื—ืœืง ืื•ืชื• ืœืงื‘ื•ืฆื•ืช ืฉืœ ื—ืœื•ืงื” ื•ืงื™ื“ื•ื“. ื”ื“ืจืš ื”ืจืืฉื•ื ื”

ืœื‘ื“ื• ื”ื•ื ืงื™ื“ื•ื“ ืœื’ื™ื˜ื™ืžื™, ื•ืœื›ืŸ ืœื ื ื™ืชืŸ ืœืชืจื’ื ืืช ื”ืžื™ื“ืข ืœืœื ืื™ืกื•ืฃ labelืชื•ื•ื™ื )ื›ืืฉืจ ืื™ืŸ ื”ื‘ื˜ื—ื” ืฉื›ืœ

ื›ืœ ื”ืžื™ื“ืข ืงื•ื“ื(. ื”ื“ืจืš ื”ืฉื ื™ื™ื” )ื—ืœื•ืงื” ื•ืงื™ื“ื•ื“( ื“ื•ืจืฉืช ืœืžืฆื•ื ื›ืžื” ื‘ืชื™ื ื ื™ืชืŸ ืœืงื•ื“ื“ ืขื“ ืœืงื‘ืœืช ืžื™ื“ืข

ืชื•ื•ื™ื, ืœืงื•ื“ื“ ืืช ื”ื—ืœืง ื”ื–ื” ืฉืœ ื”ื”ื•ื“ืขื” ื•ืจืง ืื– ืœื”ื›ื ื™ืก ืื•ืชื• ืœื›ืชื•ื‘ืช ื”ื“ื•ืžื™ื™ืŸ ืฉื ืจื›ื™ื‘. 21ื•ืจืš ืžืงื•ื“ื“ ื‘ื

ื‘ื—ืจืชื™ ื‘ืกื•ืฃ ื‘ืฉื™ื˜ื” ื”ืฉื ื™ื™ื” )ื—ืœื•ืงื” ื•ืงื™ื“ื•ื“(, ื‘ืขื™ืงืจ ื‘ืฉื‘ื™ืœ ื”ื™ื›ื•ืœืช ืฉืœื™ ืœืฉื—ื–ืจ ื—ืœืงื™ื ืžื”ื”ื•ื“ืขื” )ื•ื›ืš

ืœื ืœืื‘ื“ ืืช ื›ื•ืœื” ืื ืœื ืงื™ื‘ืœืชื™ ืืช ื›ื•ืœื”(.

ื” ืื•ืชื™ื•ืช ืื ื™ ื™ื›ื•ืœ ืœืงื•ื“ื“ ืขื“ ืฉืื•ืจืš ื”ืžื™ื“ืข ื”ืคืชืจื•ืŸ ื”ืจืืฉื•ืŸ ืฉืœื™ ื”ื™ื” ืœื”ืฉืชืžืฉ ื‘ืœื•ืœืื”, ืœื‘ื“ื•ืง ื›ืž

)ื•ืœื ื™ื—ืจื•ื’ ืžืžื ื•(. ืœืื—ืจ ืžื›ืŸ, ื”ื™ื™ืชื™ ืžืงื•ื“ื“ ืจืง ืืช ืื•ืชืŸ ืื•ืชื™ื•ืช, ืžื•ืกื™ืฃ ืื•ืชืŸ 21ื”ืžืงื•ื“ื“ ื™ื’ื™ืข ืœืื•ืจืš

ืœื“ื•ืžื™ื™ืŸ ื•ืžืกื™ืจ ืื•ืชืŸ ืžื”ื”ื•ื“ืขื”. ืœื”ืœืŸ ื—ืœืง ืžื”ืงื•ื“ ืฉืžืชืืจ ืืช ื”ื”ืœื™ืš:

ืจ ืืช ืื•ืจืš ื”ื“ื•ืžื™ื™ืŸ ืฉื•ืž domain_lenืฉื•ืžืจ ื‘ืชื•ื›ื• ืืช ื”ืžื™ื“ืข ืฉื™ืฉ ืœืงื•ื“ื“. ืžืฉืชื ื” messageืžืฉืชื ื”

ืชื•ื•ื™ื, ืžืฆืืชื™ ืœื ื›ื•ืŸ ืœื”ื’ื‘ื™ืœ 251ื”ืกื•ืคื™. ืœืžืจื•ืช ืฉื›ืชื‘ืชื™ ืœืžืขืœื” ืฉืื•ืจืš ื“ื•ืžื™ื™ืŸ ื™ื›ื•ืœ ืœื”ื’ื™ืข ืœืžืงืกื™ืžื•ื ืฉืœ

ืื ื™ืฉ - label-ืชื•ื•ื™ื ื•ืœืกืคืง ืžืจื•ื•ื— ื‘ื™ื˜ื—ื•ืŸ. ื”ืฉืœื‘ ื”ืจืืฉื•ืŸ ื”ื•ื ืžืฆื™ืืช ื”ืื•ืจืš ื”ืืคืฉืจื™ ืœ 251-ืืช ืขืฆืžื™ ืœ

21-ืช, ืื ื ืฉืืจ ืœืื•ืจืš ื”ื“ื•ืžื™ื™ืŸ ืคื—ื•ืช ืžืชื•ื•ื™ื. ืื—ืจ 21ืžืกืคื™ืง ืžืงื•ื ื‘ื›ืœ ื”ื“ื•ืžื™ื™ืŸ, ืื– ื ื™ืชืŸ ืœื”ื›ื ื™ืก ืขื“

ืชื•ื•ื™ื. 251ืชื•ื•ื™ื, ื ืžืœื ืืช ื›ืžื•ืช ื”ืžืงื•ื ืฉืœื ื™ื’ืจื•ื ืœื›ืชื•ื‘ืช ื”ื“ื•ืžื™ื™ืŸ ืœื—ืจื•ื’ ืžื”ืื•ืจืš ืฉืœ

)ื‘ื™ืช ืจืืฉื•ืŸ, ืฉื ื™ ื‘ืชื™ื ืจืืฉื•ื ื™ื, ืฉืœื•ืฉื” messageืœืื—ืจ ืžื›ืŸ, ื ื‘ื“ื•ืง ื›ืœ ืคืขื ืจืฆืฃ ื‘ืื•ืจืš ืฉื•ื ื” ืžืชื•ืš

ืื•ืชื™ื•ืช ืจืืฉื•ื ื•ืช ืžื”ื”ื•ื“ืขื” ื™ื’ื™ืข nื™ืœ ื‘ืชื™ื ืจืืฉื•ื ื™ื ื•ื›ืŸ ื”ืœืื”( ื•ื ืงื•ื“ื“ ืืช ื”ืจืฆืฃ. ืื ืื•ืจืš ื”ืจืฆืฃ ืฉืžื›

(. ืœืื—ืจ ืžื›ืŸ, ื ื•ืกื™ืฃ ืื•ืชื• ืœื“ื•ืžื™ื™ืŸ )ืœื ืžื•ืคื™ืข breakืชื•ื•ื™ื ื›ืฉื”ื•ื ืžืงื•ื“ื“, ื ืคืกื™ืง ืืช ื”ืœื•ืœืื” ) 21ืœืื•ืจืš

ื‘ืงื˜ืข ื”ืงื•ื“( ื•ื ืงืฆืจ ืืช ื”ื”ื•ื“ืขื” ืžื”ื”ืชื—ืœื” )ื ื•ืจื™ื“ ืืช ื”ืื•ืชื™ื•ืช ืฉื›ื‘ืจ ืงื•ื“ื“ื ื• ื•ื”ื•ืกืคื ื• ืœื“ื•ืžื™ื™ืŸ(.

. ื–ื” ื”ื™ื” ื ื™ื›ืจ ื›ืฉื”ืชื ืกื™ืชื™ ืขื ืงื™ื“ื•ื“ ืฉืœ ื”ื•ื“ืขื•ืช ื•ื“ืจืขื™ื•ืŸ ืจืข ืžืื”ืจืขื™ื•ืŸ ื”ื–ื” ืืžื ื ื ืจืื” ืœื’ื™ื˜ื™ืžื™, ืืš ื”ื•ื

21-ื“ื•ืจ ืฉืžื™ื ื™( ื™ื•ืชืจ ืž i7ื™ืฆื™ืจืช ื›ืชื•ื‘ื•ืช ื”ื“ื•ืžื™ื™ืŸ ืœืงื—ื” )ืขืœ ืžื—ืฉื‘ ืขื -ืื•ืชื™ื•ืช ื•ืžืขืœื” 3111ื‘ืื•ืจืš

ืฉื ื™ื•ืช! ื–ืืช ืœื ื›ืžื•ืช ื–ืžืŸ ืœื’ื™ื˜ื™ืžื™ืช ืœื”ืœื™ืš ืงื™ื“ื•ื“ ื›ื–ื” ืคืฉื•ื˜. ื›ืžื•ืช ื”ืื™ื˜ืจืฆื™ื•ืช ืฉื ืขืฉื• ื”ื™ื ืžื’ื•ื—ื›ืช ื•ื™ืฉ

ืฆื•ืจืš ื“ื—ื•ืฃ ืœืžืฆื•ื ืฉื™ื˜ื” ืื—ืจืช.

Page 44: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

44 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ืžื” ืœื•ืงื— ืคื” ืืช ื”ื–ืžืŸ? ื”ื”ืœื™ืš ืœืงื•ื“ื“ ื›ืœ ืคืขื ื›ืžื•ืช ื›ืœืฉื”ื™ ืฉืœ ืื•ืชื™ื•ืช ื‘ืฉื‘ื™ืœ ืœืžืฆื•ื ืืช ื”ืื•ืจืš ืื•ืงื™ื™,

)ืื•ืจืš ืœืื—ืจ ืงื™ื“ื•ื“: Base36-ืื•ืชื™ื•ืช ื™ื›ื•ืœื•ืช ืœื”ื™ื›ื ืก ื›ืฉื”ืŸ ืžืงื•ื“ื“ื•ืช ื‘ 11ื”ืžืงื•ื“ื“ ื”ืžืชืื™ื. ืื ืœื“ื•ื’ืžื”

11-ืœืื•ืชื™ื•ืช( ืื– ื”ืงื•ื“ ื™ื‘ื“ื•ืง ืืช ื”ืื•ืช ื”ืจืืฉื•ื ื”, ืฉืชื™ ืื•ืชื™ื•ืช ืจืืฉื•ื ื•ืช, ืฉืœื•ืฉ ืื•ืชื™ื•ืช ืจืืฉื•ื ื•ืช ืขื“ 22

ืคืขืžื™ื ื™ืชื‘ืฆืข ืงื™ื“ื•ื“ ืขื“ ืœื”ื’ืขื” ืœืžืงืจื” ื”ืงืฆื”(, ืœื‘ืกื•ืฃ ื”ื•ื ื™ืขืฉื” ืืช 11ืื•ืชื™ื•ืช ืจืืฉื•ื ื•ืช )ื›ืœื•ืžืจ

ื”ืื•ืชื™ื•ืช ื”ืจืืฉื•ื ื•ืช ืฉื•ื‘ ื•ื™ื•ืกื™ืฃ ืื•ืชื ืœื“ื•ืžื™ื™ืŸ. 11-ื”ืงื™ื“ื•ื“ ืœ

ื“ื™ ื”ืจื‘ื”. ื›ืžื•ืช ื”ืคืขืžื™ื ืฉื‘ื•ืฆืข - Base36-ืคืขืžื™ื ืงืจื™ืื” ืœืงื•ื“ ื”ืงื™ื“ื•ื“ ืœ 3111ืื•ืชื™ื•ืช ื™ืฉ ืคื” 3111ืขื‘ื•ืจ

ืง ืขืœ ื”ืžื—ืฉื‘. ื‘ืฉืœื‘ ื”ื–ื” ื”ื‘ื ืชื™ ืฉืžื” ืฉืื ื™ ืฆืจื™ืš ื–ื” ืœื“ืขืช ืืช ื”ื™ื—ืก ื‘ื™ืŸ ื”ืœื™ืš ื”ืงื™ื“ื•ื“ ื”ื•ื ืžื” ืฉืžืขื™

ืฉืœ ื”ื‘ืกื™ืกื™ื ืขื–ืจื” ืœื ื• ืœื”ื‘ื™ืŸ ln-ืื•ืจืš ื”ื•ื“ืขื” ืžืงื•ื“ื“ืช ืœืื•ืจืš ื”ื•ื“ืขื” ืจื’ื™ืœื”. ื”ืฉื™ื˜ื” ืฉืœ ื”ื—ืœื•ืงื” ื‘ื™ืŸ ื”

ื›ืžื” ืžื™ื“ืข ืžืชื•ื•ืกืฃ, ืื– ื ื•ื›ืœ ืœื”ืฉืชืžืฉ ื‘ื” ื›ื“ื™ ืœืฉืขืจ ืืช ืื•ืจืš ื”ื”ื•ื“ืขื” ื”ืจื’ื™ืœื” ื‘ื”ื™ื ืชืŸ ืื•ืจืš ื”ื•ื“ืขื”

ืžืงื•ื“ื“ืช:

๐‘™๐‘’๐‘›๐‘”๐‘กโ„Ž๐‘๐‘ฆ๐‘ก๐‘’๐‘  = โŒŠ๐‘™๐‘’๐‘›๐‘”๐‘กโ„Ž๐‘’๐‘›๐‘ โ‹…ln(36)

ln(256)โŒ‹

ืžื”ื•ื“ืขื” ืžืงื•ื“ื“ืช. ื ืขื’ืœ ื›ืœืคื™ ืžื˜ื” ื›ื“ื™ ืœื ืœื”ืกืชื›ืŸ 21%ื›ืขืช, ืื ื—ื ื• ื™ื•ื“ืขื™ื ืฉืื•ืจืš ื”ื”ื•ื“ืขื” ื”ืจื’ื™ืœื” ื”ื™ื

ื‘ื‘ื“ื™ืงื•ืช ืœืขื•ืžืช ื”ืงื•ื“ ื”ื™ืฉืŸ )ื•ื”ื•ื ื™ืขื™ืœ x500ื‘ื—ืจื™ื’ื”. ื”ืงื•ื“ ื”ื—ื“ืฉ ืฉืžืฉืชืžืฉ ื‘ืžืชืžื˜ื™ืงื” ื™ื•ืฆื ื™ืขื™ืœ ืคื™

ืžืฉืžืขื•ืชื™ืช ื‘ื›ืœ ื‘ื—ื™ื ื”(:

( ืฉืžื—ืฉื‘ืช ืืช ืื•ืจืš ื”ืžื™ื“ืข ืฉื ื™ืชืŸ ืœืงื•ื“ื“ O(1)ื‘ืงื•ื“ ื”ืงื•ื“ื ื”ืชื—ืœืคื” ื‘ืฉื•ืจืช ืงื•ื“ ื™ื—ื™ื“ื” ) for-ื”ืœื•ืœืืช

ื‘ื•ื“ื“. ื›ืขืช, ื ื™ืชืŸ ืœืงื•ื“ื“ ืืช ื”ืžื™ื“ืข ืžืฉืžืขื•ืชื™ืช ืžื”ืจ ื™ื•ืชืจ. label-ืœ

ื”ื‘ืขื™ื”: ื”ื’ื‘ืœื” ืขืœ ืื•ืจืš ื“ื•ืžื™ื™ืŸ ืžืงืกื™ืžืœื™ | ื”ืคืชืจื•ืŸ: ื—ื™ืœื•ืง ืœืžืกืคืจ ื›ืชื•ื‘ื•ืช ื“ื•ืžื™ื™ืŸ

ืื•ืชื™ื•ืช, ืื™ืš ื ื•ื›ืœ ืœืฉืœื•ื— 251-ืœ, ื•ืงื™ื™ืžืช ื”ื’ื‘ืœื” ืœื‘ื’ืœืœ ืฉืœื ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืื•ืจืš ื“ื•ืžื™ื™ืŸ ื‘ืœืชื™ ืžื•ื’ื‘

ื”ืจื‘ื” ืžื™ื“ืข? ื”ืคืชืจื•ืŸ ื”ืžืชื‘ืงืฉ ื”ื•ื ืœื—ืœืง ืืช ื”ืžื™ื“ืข ืœื“ื•ืžื™ื™ื ื™ื ืฉื•ื ื™ื. ืชื”ืœื™ืš ืฉืœ ืคื™ืฆื•ืœ

(Fragmentation ื”ื•ื ืœื ื“ื‘ืจ ื–ืจ ื‘ืจืฉืชื•ืช. ื’ื ืคืจื•ื˜ื•ืงื•ืœ )IP ื•ื’ื ืคืจื•ื˜ื•ืงื•ืœTCP ืžื‘ืฆืขื™ื ืชื”ืœื™ื›ื™ ืคื™ืฆื•ืœ

MSS-ื• MTUื—ืช ืœื’ื‘ื•ืœ ืžืกื•ื™ื )ื”ืžื•ื’ื“ืจื™ื ื‘ืชื•ืจ ( ืชื”ื™ื” ืžืชPDUืžืฉืœื”ื ืขืœ ืžื ืช ืฉื’ื•ื“ืœ ื›ืœ ื—ื‘ื™ืœืช ืžื™ื“ืข )

Page 45: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

45 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

-)ืฉืžื•ื’ื“ืจ ื› MTU-ื‘ืชื™ื. ื‘ื’ืœืœ ืฉื–ื” ื™ื•ืชืจ ืžื” 1511ื‘ื”ืชืืžื”(. ื ืชื‘ื•ื ืŸ ืขืœ ื”ืœื™ืš ืฉืœื™ื—ืช ืžื™ื“ืข ื‘ื’ื•ื“ืœ

ืชื™ืืœืฅ ืœืคืจืง ืืช ืขืฆืžื” ืœื—ื‘ื™ืœื•ืช ื”ื‘ืื•ืช: IP(, ื—ื‘ื™ืœืช 3511

ืœื ืžื™ื“ืข, ื”ื•ื ืฉื›ื•-ื”ื“ื‘ืจ ื”ืžืฉื•ืชืฃ ืœื›ืœ ื”ืคืจื•ื˜ื•ืงื•ืœื™ื ืฉืขื•ืฉื™ื ื—ืœื•ืงื” ืœืชืชื™ - ืžืกืคื•ืจ ื•ืžื™ืงื•ื ื”ื—ืœืงื™ื

ื”ื•ื ืžืกืคืจ ืฉืžืชืืจ ืืช IPื‘ืคืจื•ื˜ื•ืงื•ืœ Fragment offsetื—ื‘ื™ืœืช ืžื™ื“ืข. ืฉื“ื” -ืฉื•ืžืจื™ื ืขืœ ืžืกืคื•ืจ ืฉืœ ื›ืœ ืชืช

ื”ืจืืฉื•ืŸ ืžืชื—ื™ืœ fragment-ื‘ื”ืงืฉืจ ืฉืœ ื”ื”ื•ื“ืขื” ื”ื›ื•ืœืœืช. ืœื“ื•ื’ืžื”, ื” fragmentืžื™ืงื•ื ื”ืžื™ื“ืข ืฉืœ ื›ืœ

( ืขื“ ืžืงื•ื x 8 = 1480 395) 3191ื”ืฉื ื™ ืžืชื—ื™ืœ ืžืžืงื•ื fragment-, ื”3118( ืขื“ ืžืงื•ื x 8 = 0 1) 1ืžืžืงื•ื

ื’ื ื ื•ืชื ืช ืœื ื• ืžืกืคื•ืจ ื•ื’ื -ื”ื™ื ืฉื™ื˜ืช ืžืกืคื•ืจ ืฉืžืฉื™ื’ื” ืฉื ื™ ืฆื™ืคื•ืจื™ื ื‘ืžื›ื” ืื—ืช offset-. ืฉื™ื˜ืช ื”2118

ืžืชืืจ ื‘ืฆื•ืจื” ืคืฉื•ื˜ื” ืืช ืืœื’ื•ืจื™ืชื RFC815ื ื•ืชื ืช ืœื ื• ืืช ื”ืžื™ืงื•ื ืฉืœ ื”ื—ืœืง ื‘ื”ืงืฉืจ ืฉืœ ื›ืœืœ ื”ืžื™ื“ืข.

ื›ืฉื—ืœืง ื—ื“ืฉ ืžื’ื™ืข, ื”ื•ื ื‘ื ืœืžืœื ื—ื•ืจ. ื ื‘ื“ื•ืง ืื ื”ื•ื ืžื›ืกื” ืœื—ืœื•ื˜ื™ืŸ ืืช ื”ื—ื•ืจ, ื•ืื ื›ืŸ, ื”ื”ืจื›ื‘ื” ืžื—ื“ืฉ:

ื ืžื—ืง ืืช ื”ื—ื•ืจ ืžืจืฉื™ืžืช ื”ื—ื•ืจื™ื ืฉื™ืฉ ืœืžืœื. ื‘ืกื•ืคื• ืฉืœ ื“ื‘ืจ, ื™ื’ื™ืข ื”ื ืชื•ืŸ ื”ืื—ืจื•ืŸ ื•ื”ื•ื ื™ืžืœื ืืช ื”ื—ื•ืจ

ื”ื ื•ืชืจ. ื›ืชื•ืฆืื” ืžื›ืš ื”ื—ื•ืจ ื”ืื—ืจื•ืŸ ื™ื™ืžื—ืง ืžืจืฉื™ืžืช ื”ื—ื•ืจื™ื ื•ื›ืฉื”ืจืฉื™ืžื” ื”ื–ื• ืชื”ื™ื” ืจื™ืงื” )ื›ืฉืื™ืŸ ื—ื•ืจื™ื

ื”ืžื™ื“ืข ื”ื•ืจื›ื‘ ื‘ื”ืฆืœื—ื”. -ืœืžืœื(

ื”ื“ื‘ืจ ื”ื ื•ืกืฃ ืฉื ื™ืชืŸ ืœืฉื™ื ืœื‘ ืืœื™ื• ื‘ื˜ื‘ืœื” ืœืžืขืœื” ื”ื•ื ืฉื”ื—ืœืง ื”ืื—ืจื•ืŸ ืžื›ื™ืœ ืืช - ื–ื™ื”ื•ื™ ืฉืœ ื—ืœืง ืื—ืจื•ืŸ

". ื“ืจืš ืœื”ื‘ื“ื™ืœ ืืช ื”ื—ืœืง ื”ืื—ืจื•ืŸ ืžืฉืืจ ื”ื—ืœืงื™ื ื”ื•ื ื—ืฉื•ื‘ ื‘ื™ื•ืชืจ, ื•ื’ื More Fragments"-ื‘ 1ื”ืขืจืš

ืฉืื™ื ื• ืžื•ื‘ื˜ื— ื‘ื›ืœืœ, ื•ื ืฆื˜ืจืš ืœื˜ืคืœ ื—ืœืง ืœื ืคืฉื•ื˜. ื”ื—ืœืง ื”ื‘ืขื™ื™ืชื™ ื”ื•ื ื–ื™ื”ื•ื™ ื”ื’ืขืชื ืฉืœ ื›ืœ ื”ื—ืœืงื™ื, ื“ื‘ืจ

ื‘ื•. ืื™ืŸ ืขืจื•ื‘ื” ืฉื”ื—ืœืง ื”ืื—ืจื•ืŸ ื‘ืืžืช ื™ื’ื™ืข ืื—ืจื•ืŸ, ื›ืš ืฉื™ืฉ ืฆื•ืจืš ื‘ืžืกืคืจ ืžืขืจื›ื•ืช ื‘ืฉื‘ื™ืœ ืœื‘ื“ื•ืง ืžืชื™ ื”ื›ืœ

ื”ื’ื™ืข.

ื‘ืžืขืจื›ืช ืฉื‘ื ื™ืชื™, ืื™ืŸ ื“ืจืš ืœื“ืขืช ืžืจืืฉ ืืช ื›ืžื•ืช ื”ืžื™ื“ืข ืฉื™ื™ื›ื ืก ื‘ื“ื•ืžื™ื™ืŸ ื‘ื•ื“ื“. ืœื›ืŸ, ื”ืœื™ืš ื”ืžืกืคื•ืจ ืฉืœ

ืœื—ืœืง ื”ืžื™ื“ืข 3 -ื›ืชื™ ืื™ืชื” ื”ื™ื ืžืกืคื•ืจ ืคืฉื•ื˜ ื”ืžื™ื“ืข ืงื•ืจื” ื‘ืžืงื‘ื™ืœ ืœืชื”ืœื™ืš ื”ืงื™ื“ื•ื“. ื”ืฉื™ื˜ื” ืฉื”ืœ

" ืœื—ืœืง ื”ืžื™ื“ืข ื”ืื—ืจื•ืŸ ืืš 1-" ืœื—ืœืง ื”ืžื™ื“ืข ื”ืื—ืจื•ืŸ. ื‘ืžืงื•ืจ, ืจืฆื™ืชื™ "t-1"-ืœื—ืœืง ื”ืžื™ื“ืข ื”ืฉื ื™ ื• 2ื”ืจืืฉื•ืŸ,

label ืœื ื™ื›ื•ืœ ืœื”ืชื—ื™ืœ ืขื ืžืงืฃ, ื›ืš ืฉื”ืฉื™ืžื•ืฉ ื‘ืื•ืช ื ื•ืกืคืช ื”ื•ื ื”ื›ืจื—ื™ ืคื”. ื‘ืื•ืคืŸ ื“ื•ืžื”, ื ื™ืชืŸ ื”ื™ื”

, ืืš ืœืžืจื‘ื™ืช ื”ื”ื•ื“ืขื•ืช ืžืฆืืชื™ IPืช ื‘ืคืจื•ื˜ื•ืงื•ืœ ืฉืžืชื•ืืจ offset-ืœื”ืฉืชืžืฉ ื‘ืฉื™ื˜ื” ื“ื•ืžื” ืœืฉื™ื˜ืช ื”

ืคืจืง "ืงื™ื“ื•ื“ -ืกืคืจืชื™ื™ื ื•ืืจื‘ืข ืกืคืจืชื™ื™ื ืœืœื ืงื™ื“ื•ื“ ื ื•ืกืฃ )ื›ืžื• ืฉืชื™ืืจืชื™ ื‘ืชืช-ืฉืฉื™ืžื•ืฉ ื‘ืžืกืคืจื™ื ืชืœืช

.3-ืžื™ื“ืข" ื‘ืคืจืง ื”ืงื•ื“ื( ืœื•ืงื— ื‘ืžืžื•ืฆืข ื™ื•ืชืจ ืชื•ื•ื™ื ืžืืฉืจ ืžืกืคื•ืจ ืคืฉื•ื˜ ืฉืžืชื—ื™ืœ ืž

Page 46: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

46 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ืžื‘ื ื” ื›ืชื•ื‘ืช ื“ื•ืžื™ื™ืŸ

Main Subdomain - ืจืช ื”ื–ื” ื”ื“ื•ืžื™ื™ืŸ ืฉื‘ืชื•ื›ื• ื ืžืฆื ืฉ-NS .ืฉืืœื™ื• ืชื•ืคื ื” ื”ื‘ืงืฉื”

-)ื‘ืงื•ื“ ื”ืฉืชืžืฉืชื™ ื‘ ื’ื™ื‘ื•ื‘ ืฉืœ ื”ื”ื•ื“ืขื” ื”ืžืงื•ืจื™ืชืคื•ื ืงืฆื™ื™ืช ื”ืื•ืชื™ื•ืช ื”ืจืืฉื•ื ื•ืช ืฉืœ 1 - ืžื–ื”ื” ื”ื•ื“ืขื”

SHA256)ืžืฉื ื™ื ื‘ื• ื•ืœื›ืŸ ื”ื•ื ื™ื›ื•ืœ ืœื”ื™ื•ืช / . ื”ื’ื™ื‘ื•ื‘ ื”ื–ื” ืžืฉืชื ื” ื‘ืื•ืคืŸ ื“ืจืกื˜ื™ ืขื ื›ืœ ืื•ืช ืฉืžื•ืกื™ืคื™ื

ืช ืœืืจื‘ืขืช ื”ืื•ืชื™ื•ืช ื”ืจืืฉื•ื ื•ืช )ื”ืจื‘ื” ืืคืฉืจื•ื™ื• 25,515. ื™ืฉื ื ื’ื (volatileื•ืœื ืฆืคื•ื™ )ื™ื—ืกื™ืช ืจื ื“ื•ืžืœื™

ืคื—ื•ืช ืืคืฉืจื•ื™ื•ืช ื‘ื”ืฉื•ื•ืื” ืœื’ื™ื‘ื•ื‘ ื”ืžืœื ืืš ืžืกืคื™ืง ืœืฆืจื›ื™ื ืฉืœื ื•(.

ื‘ื ื•ืกืฃ, ื”ืฉืจืช ืฉืžืงื‘ืœ ืืช ื”ืžื™ื“ืข ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ืืจื‘ืขืช ื”ืื•ืชื™ื•ืช ื”ืจืืฉื•ื ื•ืช ืฉืœ ื”ื’ื™ื‘ื•ื‘ ื›ื“ื™ ืœืงื‘ื•ืข

ื›ื•ืŸ. ื”ื•ื ื‘ืื•ืคืŸ ื—ื“ ืžืฉืžืขื™ ื™ื—ืกื™ืช ืื ื”ื•ื ืคืขื ื— ืืช ื”ื”ื•ื“ืขื” ื ื›ื•ืŸ ืื• ืื ื—ืœืง ืžื”ืžื™ื“ืข ืœื ื”ื’ื™ืข/ืœื ืคื•ืขื ื— ื 

ืืจื‘ืขืช ื”ืื•ืชื™ื•ืช ืœืžื–ื”ื” ื•ื”ืฉื•ื•ืื” ืฉืœ , ืฉื”ืชืงื‘ืœื” ืืฆืœื•ืฉืœ ื”ื”ื•ื“ืขื” ืžื—ื“ืฉ ืขื•ืฉื” ื–ืืช ืขืœ ื™ื“ื™ ื’ื™ื‘ื•ื‘

ื”ื”ื•ื“ืขื”.

ืœืขื™ืชื™ื , ืฉื›ืŸ ืื™ืŸ ื™ื›ื•ืœืช ืœื“ืขืช ืžื” ืกื“ืจ ื”ื“ื•ืžื™ื™ื ื™ื ื”ืžื’ื™ืขื™ื ืœืฉืจืช, ืื• ื›ืžื” ืคืขืžื™ื ื”ื ื™ื’ื™ืขื• - ืžืกืคื•ืจ

ืจ ื“ื•ืžื™ื™ื ื™ื ื•ื›ืœ ื“ื•ืžื™ื™ืŸ , ืžืคืจืงื™ื ืืช ื”ืžื™ื“ืข ืœืžืกืคืœื›ืŸ. ืžืกืคืจ ืคืขืžื™ื DNS ื™ื›ื•ืœ ืœืฉืœื•ื— ื‘ืงืฉืช ืžื—ืฉื‘ ืืจื’ื•ื ื™

ืžืงื‘ืœ ืžืกืคืจ ืžืฉืœื•.

ืื•ืจืš ื”ื”ื•ื“ืขื” ื”ืžืงื•ืจื™ืช ื”ื›ื•ืœืœืช. ื”ืฉืจืช ืžืฉืชืžืฉ ื‘ื ืชื•ืŸ ื–ื” ื‘ืฉื‘ื™ืœ ืœื–ื”ื•ืช ืฉื›ืœ ื”ืžื™ื“ืข - ืื•ืจืš ื”ื”ื•ื“ืขื”

ื”ื’ื™ืข ื•ื ืืกืฃ ื‘ื”ืฆืœื—ื”. ืื•ืจืš ื”ื”ื•ื“ืขื” ื”ื•ื ื’ื ืืžืฆืขื™ ื‘ื˜ื™ื—ื•ืช ืžืฉื ื™ ืœืžื–ื”ื” ื”ื”ื•ื“ืขื”, ืฉืžื•ื•ื“ื ืฉื”ื”ื•ื“ืขื”

ื”ื’ื™ืขื” ื‘ืฉืœืžื•ืชื”, ื•ื‘ืื•ืจื›ื” ื”ืžืœื.

Page 47: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

47 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

115ืื•ืจื›ื• ืฉืœ ื”ื˜ืงืกื˜ ื”ื–ื” ื”ื•ื ืœืคื™ ื”ืฉื™ื˜ื” ื”ืžืชื•ืืจืช. Lorem Ipsumืฉืœ ื”ื˜ืงืกื˜ ืœื”ืœืŸ ื“ื•ื’ืžื ืœืงื™ื“ื•ื“

ื ื™ืฆื•ืจ ืืช ,". ืœืคื™ ื”ืชื‘ื ื™ืช ืœืžืขืœื”2d8cืฉืœื• ื”ืŸ " SHA256ืชื•ื•ื™ื, ื•ืืจื‘ืขืช ื”ืื•ืชื™ื•ืช ื”ืจืืฉื•ื ื•ืช ืฉืœ ื’ื™ื‘ื•ื‘

:ื›ืชื•ื‘ื•ืช ื”ื“ื•ืžื™ื™ืŸ ื”ื‘ืื•ืช ืืฉืจ ืžืชื›ืชื‘ื•ืช ืขื ื”ื˜ืงืกื˜ ื”ืžืงื•ืจื™ ืœืื—ืจ ืงื™ื“ื•ื“ ื‘ืื•ืคืŸ ื”ื‘ื

ื”ื’ื“ืจืช ื”ืขืจื•ืฅ ื”ืกืžื•ื™

. ื‘ื’ืœืœ ืฉื”ื•ื ืคืจื•ื˜ื•ืงื•ืœ ื›ืœ ื›ืš ื‘ืกื™ืกื™, ื›ืœ ื›ืœื™ ืฉืžืืคืฉืจ DNSืกืžื•ื™ ืฉื‘ื• ื ืฉืชืžืฉ ื”ื•ื ืคืจื•ื˜ื•ืงื•ืœ ื”ืขืจื•ืฅ ื”

ืœืชืงืฉืจ ืื™ืชื”. ื–ื” ื›ื•ืœืœ, ืืš ืœื IP-ื›ื“ื™ ืœืžืฆื•ื ืงื•ื“ื ืืช ื›ืชื•ื‘ืช ื” DNS-ืชืงืฉื•ืจืช ืื™ื ื˜ืจื ื˜, ื™ืฉืชืžืฉ ื‘

ืžื•ื’ื‘ืœ ืœ:

ืชืงืฉื•ืจืชICMP - Ping

ื›ืœื™DNS Lookup - nslookup / dig

ืชืงืฉื•ืจืชHTTP - 'ื“ืคื“ืคื ื™ื, ื•ื›ื•

ืช ืชืงืฉื•ืจTCP - Telnet ,SSH

ืื•ืคื˜ื™ืžื™ื–ืฆื™ื” ืœื“ืคื™ ืื™ื ื˜ืจื ื˜ ื‘ื“ืคื“ืคื ื™ื- prefetch-dns

ืฉืชื•ืžื›ื•ืช ื‘ื’ื™ืฉื” ืœืœื™ื ืงื™ื ืขื( ืจืฉืชื•ืช ื—ื‘ืจืชื™ื•ืชProtocol Graph Open)

Page 48: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

48 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

)ื“ื•ืžื™ื™ืŸ ืœื ืงื™ื™ื(, ื‘ืœื™ ืชืœื•ืช ื‘ืžื” ืฉื”ื•ื ืžืงื‘ืœ. NXDOMAINืฉืœื ื• ื™ื—ื–ื™ืจ ื‘ื›ืœ ืžืงืจื” ืชืฉื•ื‘ืช NS-ืฉืจืช ื”

ื”ื•ื ื™ืฉืžื•ืจ ืืช ื”ืžื™ื“ืข ืฉื”ืชืงื‘ืœ, ื•ื›ืืฉืจ ื›ืœ ื—ืœืงื™ ื”ืžื™ื“ืข ื™ื’ื™ืขื•, ื”ื•ื ื™ื“ืคื™ืก ืื•ืชื ื”ื—ื•ืฆื” )ืื• ื™ืฉืžื•ืจ ืื•ืชื•

'(.o-ืœืชื™ืงื™ื™ื”, ืื ืžืฉืชืžืฉื™ื ื‘ืืคืฉืจื•ืช '

dns-prefetch

ื›ืืฉืจ ื“ืคื“ืคืŸ ืžื‘ืงืฉ ืžืฉืื‘ ืžืฉืจืช )ืฆื“ ืฉืœื™ืฉื™(, . HTML-ื‘ metaื“, ื”ื™ื ื“ื•ื•ืงื ืชื’ื™ืช ืขืจื•ืฅ ืกืžื•ื™ ืžืกืงืจืŸ ืžืื•

ืœืคื ื™ ืฉื”ื“ืคื“ืคืŸ ื™ื›ื•ืœ ืœื”ื’ื™ืฉ ืืช ื”ื‘ืงืฉื”. ืขื‘ื•ืจ ืืชืจื™ื IP ื™ืฉ ืœืคืชื•ืจ ืืช ืฉื ื”ื“ื•ืžื™ื™ืŸ ืฉืœ ืžืงื•ืจ ื–ื” ืœื›ืชื•ื‘ืช

ื‘ื•ืช ืชืงืฉื•ืจืชื™ืช ื›ื™ื›ื•ืœื” ืœื”ื•ื‘ื™ืœ ืœื”ืชืข DNS-ื”ืคื•ืชื—ื™ื ื—ื™ื‘ื•ืจื™ื ืœืฆื“ื“ื™ื ืฉืœื™ืฉื™ื™ื ืจื‘ื™ื, ื–ืžืŸ ืจื–ื•ืœื•ืฆื™ื™ืช ื”

DNS-ื‘ืžื™ื“ื” ื•ื”ืชืฉื•ื‘ื” ืœืฉืื™ืœืชืช ื”ื‘ื•ื“ื“ื•ืช ) ืžื™ืœื™ ืฉื ื™ื•ืช ืœืงื—ืชื‘ื•ืช ื–ื• ื™ื›ื•ืœื” ื›ืงื•ื—. ื”ืชืขืจื‘ื” ืžืฆื“ ื”ืœ

-dnsืžืฉืชืžืฉื™ื ื‘ืชื’ื™ืช ืขืœ ืžื ืช ืœืคืชื•ืจ ื‘ืขื™ื” ื–ื•, .ืžืกืคืจ ืฉื ื™ื•ืชื•ืŸ( ื•ื‘ืžืงืจื™ื ืงื™ืฆื•ื ื™ื™ื ืืฃ ื ืžืฆืืช ื‘ืžื˜ืž

prefetch - ืืช ื›ืชื•ื‘ืช ื”ืžื ืกื” ืœืžืฆื•ื ืชื’ื™ืช ื–ื•-IP ืขื•ื“ ืฉื”ืžืฉืชืžืฉ ืขืชื™ื“ ืœื’ืฉืช ืืœื™ื”ื ืฉืžื•ืช ื“ื•ืžื™ื™ื ื™ื ืœืฉ

.DNS Lookupืชื’ื™ืช ืฉืขื•ืฉื” -ืœื’ืฉืช ืœืงื™ืฉื•ืจ ื”ืžืฉืชืžืฉ ืžื ืกื” ืœืคื ื™ื™ ืฉ

:ื™ื›ื•ืœื™ื ืœื”ืฉืชืžืฉ ื‘ืฉื•ืจื” ื”ื‘ืื” ื‘ืขืช ืฆื™ื•ืŸ ื”ืงื™ืฉื•ืจืžืคืชื—ื™ื ืขืœ ืžื ืช ืœื–ืจื– ืืช ื–ืžืŸ ื”ืžืขื‘ืจ ื‘ื™ืŸ ืงื™ืฉื•ืจื™ื,

ืืœ ื”ืงื™ืฉื•ืจ, ื•ืขื•ืงืคืช ื’ื DNSืœื“ืคื“ืคืŸ ืœื‘ืฆืข ื‘ื“ื™ืงืช ื”ืชื’ื™ืช ืื™ื ื” ืžืฉื ื” ืืช ื ืจืื•ืช ื”ืืชืจ ืืš ื’ื•ืจืžืช

:CSP-ื• CORSืžืขืจื›ื•ืช

ืื™ื ื” ืคื•ืขืœืช, ื•ืขืœ ืžื ืช ืœื”ืคืขื™ืœ ืื•ืชื” ื™ืฉ ืœื”ื•ืกื™ืฃ ืชื’ื™ืช dns-prefetchืืคืฉืจื•ืช ืœื‘ืฆืข ื‘ื‘ืจื™ืจืช ืžื—ื“ืœ, ื”

" ืžืคืขื™ืœื” x-dns-prefetch-controlืชื’ื™ืช " -ืฉืœ ื”ื“ืคื“ืคืŸ( flags-)ืžื–ืœ ืฉื–ื” ืœื ืฉื™ื ื•ื™ ื‘ HTMLื ื•ืกืคืช ืืœ ืงื•ื“

ืœืงื™ืฉื•ืจื™ื ืžื‘ืœื™ ืฉื”ืžืฉืชืžืฉ ืœื•ื—ืฅ ืขืœื™ื”ื. ืื—ืช ื”ืฉื™ื˜ื•ืช ืฉื”ืชื ืกื™ืชื™ ืื™ืชืŸ DNSืืช ื”ื™ื›ื•ืœืช ืœื‘ืฆืข ื‘ื“ื™ืงื•ืช

ื˜ื”ื•ืจ, ื›ืš ืฉื™ื”ื™ื” ื ื™ืชืŸ ืœื”ื˜ืžื™ืข ืื•ืชื• ื‘ืชื•ืกืฃ JS-ืชื™ ืขืœ ื”ืคืจื•ื™ืงื˜, ื”ื™ื” ื™ื™ืฉื•ื ืฉืœ ืืœื’ื•ืจื™ืชื ื”ืงื™ื“ื•ื“ ื‘ื›ืฉืขื‘ื“

ืœื ืžืฆื•ืจืฃ ืœืคืจื•ื™ืงื˜(. ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืชื•ืกืฃ ื“ืคื“ืคืŸ ืฉื‘ืขืช ื˜ืขื™ื ืช ืืชืจ ื™ืขื‘ื™ืจ ืžื™ื“ืข ืืœ JSื›ืจื•ื )ืงื•ื“

. ื‘ื”ื ื—ื” ืฉื”ืชื•ืงืฃ DOMืฉื”ื•ื ืžื—ื“ื™ืจ ืœืืชืจ ืขื dns-prefetchืฉืœ ื”ืชื•ืงืฃ ื‘ืืžืฆืขื•ืช ืชื’ื™ื•ืช NSื”ืฉืจืช

ื‘ื“ืคื“ืคืŸ )ื›ื™ ืœื ืคืฉื•ื˜ ืœื”ืชืงื™ืŸ ืชื•ืกืฃ ืฉืœื ื‘ื ืžื”ื—ื ื•ืช(, developer mode-ื ื“ืจืš ืœื”ืคืขื™ืœ ืืช ื”ื™ืžืฆ

ื•ื™ื›ืชื•ื‘ ืงื•ื“ ืฉื™ื‘ืฆืข ืืช ื”ืงื™ื“ื•ื“ ื”ืžืชืื™ื, ื”ื•ื ื™ื›ื•ืœ ืœื’ืจื•ื ืœื–ืœื™ื’ืช ืžื™ื“ืข ืžื”ื“ืคื“ืคืŸ ืฉืœ ืžื—ืฉื‘ ืืจื’ื•ื ื™, ื›ื•ืœืœ

ืฉืขืœื•ืœื™ื ืœื”ื™ื•ืช ื‘ืชื•ืš GETื”ืงืฉื•ืช ืžืงืœื“ืช, ืฆื™ืœื•ืžื™ ืžืกืš, ืงื™ืฉื•ืจื™ื ืฉื‘ื”ื ื”ืžืฉืชืžืฉ ื”ื™ื” )ื›ื•ืœืœ ืคืจืžื˜ืจื™ื

ื”ืงื™ืฉื•ืจื™ื(, ื’ื™ืฉื” ืœืงื•ืงื™ื•ืช ื•ื›ื•'.

Page 49: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

49 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

DNSExfil

ืœื‘ื™ืฆื•ืข ื›ืœ framework, ื’ืจืกื” ืจืืฉื•ื ื™ืช ืœืžื” ืฉืืžื•ืจ ืœื”ื™ื•ืช DNSExfilื”ื›ืœื™ ืฉืขื‘ื“ืชื™ ืขืœื™ื• ื›ื‘ืจ ื–ืžืŸ ืžื” ื”ื•ื

ืžืฉืชืžืฉ ืฉืœื™ื˜ื” ืžืœืื” ืขืœ . ื‘ื ื™ื’ื•ื“ ืœื›ืœื™ื ืงื™ื™ืžื™ื ื”ื™ื•ื, ื”ื›ืœื™ ื”ื–ื” ืืžื•ืจ ืœืชืช ืœDNS Exfiltrationืกื•ื’ ืฉืœ

. ื”ื•ื ื ื•ืขื“ ืœืงื”ื™ืœื” DNSืกื˜ ื›ืœื™ื ืœื‘ื ื™ื™ืช ืฉื™ื˜ื•ืช ืœื–ืœื™ื’ืช ืžื™ื“ืข ื“ืจืš -ื”ืงื™ื“ื•ื“, ื”ืžืกืคื•ืจ ื•ื•ื™ื“ื•ื ื”ื ืชื•ื ื™ื

ืฉื™ืืคืฉืจื• ืœื›ืœ fragmentation-ืฉื™ื˜ื•ืช ื“ื—ื™ืกื”, ืฉื™ื˜ื•ืช ื”ืฆืคื ื”, ืฉื™ื˜ื•ืช ืœืงื™ื“ื•ื“ ืžื™ื“ืข ื• -ืฉืชืชืจื•ื ืœื• ืงื•ื“

ืžืฉืชืžืฉ ืœื™ืฆื•ืจ ื›ืœ ืงื™ื“ื•ื“ ืœื“ื•ืžื™ื™ืŸ ืฉื‘ืจืฉื•ืชื•.

ืžื™ื•ืช ืžืงืกื™ืžืœื™ืช ื‘ืจืืฉื”, ื•ืœืงื—ื• ืžืกืคืจ ืฉื‘ื•ืขื•ืช ืœื‘ื ื™ื™ืชื”. ืœืžืจื‘ื” ื”ืฆืขืจ, ืขื“ ื”ืžืขืจื›ืช ื ื‘ื ืชื” ืขื ื“ื™ื ื

ืœื–ืžืŸ ื›ืชื™ื‘ืช ื”ืžืืžืจ ื”ื–ื” ืœื ื”ืกืคืงืชื™ ืœืกื™ื™ื ืื•ืชื” )ื•ื‘ื”ื—ืœื˜ ื“ืจื•ืฉื™ื ืœื™ ืขื•ื“ ื›ืžื” ืฉื‘ื•ืขื•ืช ืขื‘ื•ื“ื”(. ืขืœ

ื‘ื–ืจื™ื–ื•ืช, ื›ืš ืฉืชื•ื›ืœื• ืœื”ืฉืชืžืฉ ื‘ื” ื‘ื ื•ื—ื•ืช )ื‘ืžืงื•ืจ ื”ื™ื CLIืžื ืช ืฉื™ื”ื™ื” ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื”, ื‘ื ื™ืชื™ ื›ืœื™

(. ืžื” ืฉืžื•ื’ืฉ ืœืคื ื™ื›ื ื”ื™ื ื’ืจืกื” ืจืืฉื•ื ื” )ืื ื™ ืงื•ืจื ืœื” Rustื‘ื” ื‘ืฉืคืช ืชื›ื ื•ืช ืืžื•ืจื” ืœื”ื™ื•ืช ื‘ื›ืœืœ ื›ืชื•

MVP - ืžื•ืฆืจ ืจืืฉื•ื ื™ ื‘ืกื™ืกื™( ืฉื ื•ืชื ืช ืฉืœื™ื˜ื” ื‘ืกื™ืกื™ืช ืขืœ ื“ื—ื™ืกื” ื•ื“ื‘ืจื™ื ื ื•ืกืคื™ื. ืขื ื”ื–ืžืŸ, ื‘ืœื™ ื ื“ืจ, ืื ื™

ืืกื™ื™ื ืœื‘ื ื•ืช ืืช ื”ื›ืœื™ ื”ื–ื”, ืื•ืœื™ ืื›ืชื•ื‘ ื›ืชื‘ืช ื”ืžืฉืš ืขืœ ื”ืชื”ืœื™ืš...

Page 50: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

51 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ื”ื›ื ื”: ืฉื™ื ื•ื™ ื”ื’ื“ืจื•ืช ื“ื•ืžื™ื™ืŸ

NSืฉ ื‘ื›ืœื™, ื™ืฉ ืœื”ื›ื™ืŸ ืจืืฉื™ืช ืืช ื”ื“ื•ืžื™ื™ืŸ ืฉืชื‘ื—ืจื• ื›ืš ืฉื™ื•ื›ืœ ืœื”ืขื‘ื™ืจ ืืช ื”ืžื™ื“ืข ืœืฉืจืช ืขืœ ืžื ืช ืœื”ืฉืชืž

ื”ืžืชืื™ื. ืœืฉื ื›ืš, ื ื•ืกื™ืฃ ืฉืชื™ ืฉื•ืจื•ืช ืœื”ื’ื“ืจื•ืช ื”ื“ื•ืžื™ื™ืŸ:

Content Name Type

t1ns.the-gordons.site t1 NS

39552215318521 t1ns A

. ืžื“ื•ื‘ืจ ื‘ื“ื•ืžื™ื™ืŸ the-gordons.siteืฉืœื™ื˜ืชื™, ืืฉืจ ื ืงืจื ืฉื ืžืฆื ื‘ื”ื•ื ื“ื•ืžื™ื™ืŸ ืžืœื ืชื™ื”ื“ื•ืžื™ื™ืŸ ืฉื‘ื• ื”ืฉืชืžืฉ

ืฉืœื•. ืขืœ ืžื ืช ืฉื”ื‘ืงืฉื•ืช DNS-ื•ื™ืฉ ืœื™ ื™ื›ื•ืœืช ืœืฉื ื•ืช ื•ืœื ื”ืœ ืืช ืจืฉื•ืžื•ืช ื” Hostingerืฉื’ืจืชื™ ืฉื ืงื ื” ื‘ืืชืจ

. NameServerื”ืžื™ื“ืข ืฉืœ ื”ืชื•ืงืฃ( ื™ืฉ ืœื”ื’ื“ื™ืจ ืฉืจืช -ืฉื•ืžืจ DNS-ื™ืขื‘ืจื• ืœืฉืจืช ื“ื•ืžื™ื™ืŸ ืคื ื™ืžื™ )ืงืจื™ ืฉืจืช ื”

ื™ื™ื‘ ืœื”ื™ื•ืช ื›ืชื•ื‘ืช ื“ื•ืžื™ื™ืŸ )ืœื ื™ื›ื•ืœ ืœื”ื™ื•ืช ื”ืฉืจืช ืืœื™ื• ืžืคื ื™ื ื— -ื‘ืจืฉื•ืžื•ืช ืžืขืœื” ื‘ืขื™ื” NS-ืฉื•ืจืช ื”ื”ื’ื“ืจืช

ืคืฉื•ื˜ื”(. IPื›ืชื•ื‘ืช

ืฉืœ ื”ืฉืจืช ืฉืœื ื•. IP-ื ื•ืกืคืช, ืืฉืจ ื ื•ืชื ืช ืฉื ื—ื“ืฉ ืœื›ืชื•ื‘ืช ื” Aืขืœ ืžื ืช ืœืขืงื•ืฃ ืืช ื”ื‘ืขื™ื”, ื ื•ืกื™ืฃ ืจืฉื•ืžืช

ื”ื“ื•ืจืฉ ื–ืืช. ื›ืš, ื”ืฉืจืช NS-ื›ืขืช, ื™ืฉ ืœืฉืจืช ืฉืœื ื• ื›ืชื•ื‘ืช ื“ื•ืžื™ื™ืŸ ืžืฉื•ื™ื›ืช ืืœื™ื•, ื•ื ื™ืชืŸ ืœื”ื–ื™ืŸ ื–ืืช ืืœ ืฉื“ื” ื”

ื‘ืื•ืชื• .t1nsื“ื•ืžื™ื™ืŸ ื•ืœื”ืขื‘ื™ืจ ืื•ืชื” ืœืฉืจืช -ื•ื›ืŸ ืœื–ื”ื•ืช ืชืงืฉื•ืจืช ืฉืชื’ื™ืข ืœื—ืคืฉ ืชืชื™ื•ืžืคืชื— "ืฆื™ื ื•ืจ ืงืœื™ื˜ื”",

ื“ื•ืžื™ื™ืŸ ื ื™ืชืŸ ืœื”ื’ื“ื™ืจ ืžืกืคืจ ืฆื™ื ื•ืจื•ืช, ืœืงืœื™ื˜ืช ื ืชื•ื ื™ื ืžืžืงื•ืžื•ืช ืฉื•ื ื™ื.

ื”ืขืจื” ื—ืฉื•ื‘ื” ื‘ื ื•ื’ืข ืœืชื™ืื•ื ื”ืฉืจืช ื•ื”ืœืงื•ื—

ื•ื›ื ืช )ืœื”ืœืŸ, ืช DNSEXfil-Server.py - 1, ื ื™ืชืŸ ืœืžืฆื•ื ืฉืชื™ ืชื•ื›ื ื•ืช ืฉื›ืชื•ื‘ื•ืช ื‘ืคื™ื™ืชื•ืŸ repository-ื‘ืชื•ืš ื”

)ืœื”ืœืŸ, ืชื•ื›ื ืช ืœืงื•ื—(. ื›ืฉืžื’ื“ื™ืจื™ื ืืช ื”ืœืงื•ื— ื ื™ืชืŸ ืœื”ื’ื“ื™ืจ ืืช ื”ืงื™ื“ื•ื“ DNSExfil-Client.py-ืฉืจืช( ื•

ื•ื”ื“ื—ื™ืกื”, ืืš ื–ื” ืงืจื™ื˜ื™ ืœื”ื’ื“ื™ืจ ืืช ืื•ืชืŸ ื”ื’ื“ืจื•ืช ื’ื ื‘ืฉืจืช )ืขืœ ืžื ืช ืฉื™ื™ื“ืข ืื™ืš ืœื”ืชืžื•ื“ื“ ืขื ื”ื ืชื•ื ื™ื(.

ืง ืื•ืชื ื›ืžื• ืฉื”ื ืžืชื•ื›ื ืช ื”ืœืงื•ื— ืฉืื—ืจืื™ื™ื ืขืœ ื“ื—ื™ืกื” ื•ืงื™ื“ื•ื“ ื•ืœื”ืขืชื™ flagsื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื“ื™ื•ืง ื‘ืื•ืชื

ืืœ ื”ืฉืจืช )ืื•ืชื• ืงื•ื“ ื‘ื“ื™ื•ืง(. ื‘ืขืชื™ื“, ืื•ืกื™ืฃ ื‘ืงื•ื“ ืืช ื”ื™ื›ื•ืœืช ืœืฉืžื•ืจ, ืœื”ืขื‘ื™ืจ ื•ืœืงืœื•ื˜ ื‘ืงืœื•ืช ื”ื’ื“ืจื•ืช

. ื›ืœ ืขื•ื“ ื”ืฉืจืช ื•ื”ืœืงื•ื— ื™ื˜ืขื ื• ืืช ืื•ืชื• ืงื•ื‘ืฅ, ื”ื ื™ื”ื™ื• protobuf-ื“ื—ื™ืกื” ื•ืงื™ื“ื•ื“ ื‘ืคื•ืจืžื˜ ื“ื—ื•ืก ื“ืžื•ื™

ืžืชื•ืืžื™ื ืขื ื”ื”ื’ื“ืจื•ืช ืฉืœื”ื.

Page 51: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

51 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ื•ื?ื’ืจื•ืข? ื›ืžื” ื–ื” ื‘ืืžืช ื™ืขื‘ื•ื“ ื›ื™ DNSExfilื”ืื

ื”ื™ื ืœื ืกื•ื“ DNSืฉืืœื” ื˜ื•ื‘ื”, ืฉืžืฆื“ื™ืงื” ืคืจืง ืฉืœื ืฉื™ืขื ื” ืขืœื™ื”. ื ืชื—ื™ืœ ื‘ื›ืš ืฉื”ืขื‘ืจืช ืžื™ื“ืข ื‘ืืžืฆืขื•ืช

ื›ืชื‘ ืขืœ ื›ืš ื‘ืจืฉื™ืžืช Oskar Pearson -ืขื•ื“ ืžืื– ืฉ DNS Tunnelingืฉืžื•ืจ. ื›ืชื‘ื• ื›ืชื‘ื•ืช ื•ืžืืžืจื™ื ืขืœ

ื‘ืชื•ืจ ื˜ื›ื ื™ืงื” Blackhatื”ืฉื™ื˜ื” ื”ื•ืฆื’ื” ื‘ื›ื ืก 2111. ื‘ืฉื ืช 3889ื‘ืืคืจื™ืœ 31-ื‘ Bugtraq ื”ืชืคื•ืฆื”

ื”ืืงืจื™ื ืื™ืจืื ื™ื™ื ืžืกืชืžื›ื™ื ืขืœ . ื ืฉืžืข ื™ืฉืŸ? ื•ื‘ื›ืŸ, ื™ืฉื ืŸ ืจืื™ื•ืช ืฉื’ื ื›ื™ื•ื, Kaminsky Danื‘ื”ืจืฆืื” ืฉืœ

ืฉืœืขื™ืชื™ื 0day, ืขื ืฉื“ืจื•ื’ื™ื ื›ืืœื” ื•ืื—ืจื™ื ื‘ื ื•ื–ืงื•ืช ืฉืœื”ื. ื‘ื ื™ื’ื•ื“ ืœืคื’ื™ืขื•ืช ืฉื™ืžื•ืฉ ื‘ื˜ื›ื ื™ืงื•ืช ื“ื•ืžื•ืช

ื™ื›ื•ืœื•ืช ืœื”ื™ื•ืช ืžืชื•ืงื ื•ืช ืœืื—ืจ ื–ืžืŸ ืžื” ื‘ื’ืœืœ ืชืงืœื” ื ืงื•ื“ืชื™ืช, ืฉื™ื˜ื•ืช ื•ืขืงืจื•ื ื•ืช ื—ื“ืฉื™ื ืฉื ื—ืฉืคื™ื ื‘ื›ื ืกื™ื

ื–ืžืŸ. ืœื ืคืฉื•ื˜ ื ืขืœืžื™ื, ืืœื ืขื•ื‘ืจื™ื ืฉื“ืจื•ื’ ื•ืฉื™ืคื•ืจ ืœืื•ืจืš

ืฉื”ืฆื˜ืจืฃ ื‘ื—ื•ื“ืฉ dnscat2ืœืคื ื™ ืฉื”ืชื—ืœืชื™ ืืช ื”ืคืจื•ื™ืงื˜ ื”ื–ื”, ืขืฉื™ืชื™ ืžื—ืงืจ ืขืœ ืคืจื•ื™ืงื˜ื™ื ื“ื•ืžื™ื, ื›ื•ืœืœ ืขืœ

. ืœื›ืœ ืื—ื“ ืžื”ื ื™ืฉ ืืช ื”ื—ื•ื–ืงื•ืช Kali Linux( ืœืกื˜ ื”ื›ืœื™ื ืฉืžื’ื™ืขื™ื ืžื•ืชืงื ื™ื ืขื 2123ื”ืื—ืจื•ืŸ )ื™ื•ืœื™

ืžื”ื ืœื ืžืกืคืง ืืช ื”ืขืจื›ื” ื”ืžืœืื” ืฉืžื ืฆืœืช ืœื—ืœื•ื˜ื™ืŸ ืืช ื”ืคืจื•ื˜ื•ืงื•ืœ ื•ื”ื—ื•ืœืฉื•ืช ืฉืœื•, ืื‘ืœ ืืฃ ืื—ื“

ื•ื ื•ืชื ืช ืœืžืฉืชืžืฉ ืืช ื”ื™ื›ื•ืœืช ื”ืื•ืœื˜ื™ืžื˜ื™ื‘ื™ืช ืœืฉืœื•ื˜ ื•ืœื”ืจื›ื™ื‘ ื‘ืขืฆืžื• ืขื ืคื™ื ืฆื˜ื” ืืช ื”ืงื™ื“ื•ื“ ืฉืœื•. ืœืื•ืชื”

ื›ืœ ื›ืœื™ ืžืฆืœื™ื— ืื—ืจืช ืขื ื›ืœ ื—ืกื™ืžื”, ืื™ืŸ ื›ืœื™ -ืžืกืงื ื” ื”ื’ื™ืขื• ื’ื ื›ืœ ื”ืžื—ืงืจื™ื ืฉืงืจืืชื™ ืฉืขืกืงื• ื‘ื ื•ืฉื

ืื—ื“ ืฉืฉื•ืœื˜ ื‘ื›ืœ.

ืžืจ ืœืคืชื— ืืช ื”ื™ื™ืฉื•ื ื”ื›ื™ ื˜ื•ื‘ ืื• ื”ืฉื™ื˜ื” ื”ืžื•ืฉืœืžืช, ืืš ืื ื™ ื‘ื”ื—ืœื˜ ืฉื•ืืฃ ืœื™ืฆื•ืจ ืืช ื”ื›ืœื™ ืื ื™ ืœื ืžืชื™ื™

ื”ื›ื™ ื˜ื•ื‘ ืฉื™ืขืฉื” ืืช ื”ืขื‘ื•ื“ื”. ืคื™ืจืงืชื™ ืืช ื”ืคื™ืฆ'ืจื™ื ืฉืชื›ื ื ืชื™ ืœืคืจื•ื™ืงื˜ ืœื—ืžื™ืฉื” ืฉืœื‘ื™ ื”ื ืคืงื”, ื•ืื ื™

ืžืชื›ื ืŸ ืœืขื‘ื•ื“ ืขื ืื ืฉื™ื ื ื•ืกืคื™ื ื‘ืงื”ื™ืœื” ืขืœ ืžื ืช ืœื”ืคื•ืš ืืช ื”ื›ืœื™ ื”ื–ื” ืœืžืฆื™ืื•ืช )ืžื•ื–ืžื ื™ื ืœื™ืฆื•ืจ ืื™ืชื™

ื ื•ืฉื ื”ื–ื” ืžืขื ื™ื™ืŸ ืืชื›ื(.ืงืฉืจ ืื ื”

, IP Reputation ,WHOIS"ืžื›ื•ื‘ื“" ) ืžืกืคื™ืงืฉืœืš ืฉื”ื“ื•ืžื™ื™ืŸืกื™ื›ื•ื™ ืื™ืŸ, 4# ื“ื™ื‘ืจ ืœืคื™ื˜ืขื ื”:

Alexa )ื™ืขื‘ื•ื“ ืœื ื–ื” ื•ืœื›ืŸ

ื‘ื“ื•ื’ืžื” ืฉืชื™ืืจืชื™ ื›ืืŸ, ืœื ืกื‘ื™ืจ ืฉืื ืชืงื ื• ื“ื•ืžื™ื™ืŸ ืžืฉืœื›ื ืฉื”ื•ื ืžื™ื“ ื™ืขื‘ื•ื“ ืขื ื›ืœ -ื–ื” ืงืฆืช ื ื›ื•ืŸ

ื›ื™ ื”ื ืชื•ื ื™ื ืฉืœื• "ื˜ืจื™ื™ื ืžื“ื™"(. ืื‘ืœ, ืžื” ืื ื”ื™ื™ืชื™ ื”ืจืฉืชื•ืช ื”ืืจื’ื•ื ื™ื•ืช ื”ื ื•ืงืฉื•ืช ื‘ื™ื•ืชืจ )ืขืœื•ืœ ืœื”ื™ื—ืกื

ืฉืœ ืืชืจ ื™ื“ื•ืข ืฉืงื™ื™ื ื›ื‘ืจ ื–ืžืŸ ืžื” ื•ื™ืฉ ืœื• ื ื•ื›ื—ื•ืช ื‘ืจืฉืช? ื”ืื ื”ื˜ืขื ื” DNS-ืžืงื‘ืœ ืฉืœื™ื˜ื” ืขืœ ื”ื’ื“ืจื•ืช ื”

ื”ื–ืืช ืขื“ื™ื™ืŸ ื”ื™ื™ืชื” ืขื•ืžื“ืช? ืœื ื‘ื“ื™ื•ืง.

( ื‘ืขืœ ืžืฉืื‘ื™ื ื‘ืœืชื™ ืžื•ื’ื‘ืœื™ื ื”ื™ื” ืจื•ืฆื”APT Groupืœืคื™ ืื™ืš ืฉืื ื™ ืจื•ืื” ืืช ื–ื”, ืื ืชื•ืงืฃ ื‘ืจืžื” ืžื“ื™ื ื™ืช )

ืœื”ื•ืฆื™ื ืžืชืงืคื” ื›ื–ืืช ืœืคื•ืขืœ )ื•ื”ื•ื ื™ื›ื•ืœ(, ื”ื•ื ื™ืฆื˜ืจืš ืื• ืœื”ืฉืชืœื˜ ืขืœ ืืชืจ ืžื•ื›ืจ )ื‘ืืžืฆืขื•ืช ืคื’ื™ืขื•ื™ื•ืช

, ืื• ืœื—ืœื•ืคื™ืŸ, ืœื™ืฆื•ืจ ืืชืจ ื—ื“ืฉ, ืœืชืช ืœื• ืœืฆื‘ื•ืจ ืชืื•ืฆื”, DNS-ืงื™ื™ืžื•ืช ื‘ืฉืจืช(, ื•ืœืฉื ื•ืช ืœื• ืืช ื”ื’ื“ืจื•ืช ื”

ืœืžื›ื•ืจ ืžื•ืฆืจื™ื, ืœืคืจืกื ืžื™ื“ืข ื‘ืจืฉืชื•ืช ื”ื—ื‘ืจืชื™ื•ืช, ื•ืื– ืœืื—ืจ ื›ืžื” ืฉื ื™ื ืœื”ืฉืชืžืฉ ื‘ื• ื‘ืชื•ืจ ื‘ืกื™ืก

ืœื ืžืชื”, ื–ื” ืขื ื™ื™ืŸ ืฉืœ ื”ื–ื“ืžื ื•ืช DNS Tunnelingืœื”ืขื‘ืจืช ื”ืžื™ื“ืข. ื‘ื™ืŸ ื›ื” ื•ื›ื”, ื”ืฉื™ื˜ื” ืขืฆืžื” ืฉืœ

ื•ืืคืฉืจื•ืช.

Page 52: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

52 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ื™ืฆื™ื’ื• ืืช ื”ื“ื•ืžื™ื™ื ื™ื ืฉื ืจืื™ื ืžื•ื–ืจ, ื•ื–ื” DNS-, ื ื™ืชื•ื— ืคืฉื•ื˜ ืฉืœ ื ืชื•ื ื™ ื”3#ื˜ืขื ื”: ืœืคื™ ื“ื™ื‘ืจ

ื™ื—ืฉื•ืฃ ืืช ื”ืขืจื•ืฅ ื”ืกืžื•ื™

ื™ื ืฉื”ื ืืจื•ื›ื™ื ืžืฉืžืขื•ืชื™ืช ื™ื—ืฉื•ืฃ ืืช ื”ื“ื•ืžื™ื™ื  DNS-ื ื™ืชื•ื— ืฉืœ ืชืขื‘ื•ืจืช ื” -ื–ืืช ื ืงื•ื“ื” ืœื ืจืขื” ื‘ื›ืœืœ

ืžืžืจื‘ื™ืช ื”ื“ื•ืžื™ื™ื ื™ื ืฉืžื—ืฉื‘ ืœื’ื™ื˜ื™ืžื™ ื™ื™ื’ืฉ ืืœื™ื”ื. ื”ื˜ืขื ื” ืื™ื ื” ืžืฉื•ืœืœืช ื›ืœ ื™ืกื•ื“. ืขื ื–ืืช, ืชื›ื ื•ืŸ ื ื›ื•ืŸ ืฉืœ

ื”ืงื™ื“ื•ื“ ื›ืŸ ื™ื›ื•ืœ ืœืคืชื•ืจ ืืช ื”ื‘ืขื™ื” )ืืคื™ืœื• ืื ื—ืœืงื™ืช(.

, ื›ืžื• CDNื“ื•ืžื™ื™ืŸ ื“ื™ื ืืžื™ื™ื ื”ื•ื ืœื ื“ื‘ืจ ื™ื•ืฆื ื“ื•ืคืŸ ื‘ื ื•ืฃ. ืืชืจื™ื ืฉืžืกืคืงื™ื ืฉื™ืจื•ืชื™ -ืจืืฉื™ืช, ืฉื™ืžื•ืฉ ื‘ืชืชื™

Cloudflare ืžืฉืชืžืฉื™ื ื‘ื›ืชื•ื‘ื•ืช ื“ื•ืžื™ื™ืŸ ืฉื“ื•ืžื•ืช ื‘ืฆื•ืจืชืŸ ื”ื›ืœืœื™ืช ืœื“ื•ืžื™ื™ื ื™ื ืฉืื ื• ืžืฉืชืžืฉื™ื ื‘ื”ื ื‘ืฉื™ื˜ื” ,

ืฉืœื ื•:

ืืžื ื, ืงื™ื™ื ื”ื‘ื“ืœ ืžืฉืžืขื•ืชื™ ื‘ืื•ืจืš ื”ื“ื•ืžื™ื™ื ื™ื ื”ื›ื•ืœืœ. ื ื™ืชืŸ ืœืจืื•ืช ื‘ื‘ื™ืจื•ืจ ืฉืื•ืจืš ื”ื“ื•ืžื™ื™ืŸ ื‘ื“ื•ื’ืžื” ืœืžืขืœื”

ืœื”ื•ืจื™ื“ ืืช ื›ืžื•ืช ื™ื” ื”ืชื•ื•ื™ื ืฉื™ืฉ ื‘ืฉื™ื˜ื” ืฉืœื ื•. ืคืชืจื•ืŸ ืืคืฉืจื™ ืœื›ืš ื™ื” 251-ื”ื•ื ืžืฉืžืขื•ืชื™ืช ืงืฆืจ ื™ื•ืชืจ ืž

ื”ืชื•ื•ื™ื ื‘ืžื›ื•ื•ืŸ ืขืœ ืžื ืช ืœื”ืชื—ืžืง ืžื’ื™ืœื•ื™(. ื ื™ืชืŸ ืœืขืฉื•ืช ื–ืืช 251)ื›ืœื•ืžืจ ืœื ืœื ืฆืœ ืืช ื›ืœ ื”ืชื•ื•ื™ื ื‘ื›ืœ ื“ื•ืžื™ื™ืŸ

ืขืœ ื™ื“ื™ ืฉื™ื ื•ื™ ืฉืชื™ ืฉื•ืจื•ืช ืงื•ื“ )ื”ืงื•ื“ ืฉื›ืชื‘ืชื™ ื”ื•ื ื‘ืืžืช ื“ื™ ื“ื™ื ืืžื™(, ื•ืื ื™ ืžืชื›ื•ื•ืŸ ื‘ืขืชื™ื“ ืœื”ื›ื ื™ืก ืืช ื–ื”

ืœ ื“ื‘ืจ ื‘ื“ื—ื™ืกื” ื•ื‘ืงื™ื“ื•ื“. ื‘ืชื•ืจ ืคืจืžื˜ืจ ืฉืžืฉืชืžืฉ ื™ื•ื›ืœ ืœืฉืœื•ื˜ ื‘ื• ื•ืœืฉื ื•ืช ืื•ืชื•, ื›ืžื• ื‘ื›

ื ื™ืชืŸ ื’ื ืœื”ืคื—ื™ืช ื‘ื›ืžื•ืช ื”ื‘ืงืฉื•ืช ืฉื ืขืฉื•ืช ื‘ื›ืœ ื™ื—ื™ื“ืช ื–ืžืŸ )ื•ื–ื” ืžื—ื–ื™ืจ ืื•ืชื ื• ื—ื–ืจื” ืœืื™ื–ื•ืŸ ื”ืžื•ืฉืœื ื‘ื™ืŸ

ืกื•ื“ื™ื•ืช ืœืžื”ื™ืจื•ืช ื”ืขื‘ืจืช ืžื™ื“ืข(.

, ื—ื•ืงืจื™ื ื‘ืื•ื ื™ื‘ืจืกื™ื˜ืช ื‘ืŸ ื’ื•ืจื™ื•ืŸ ื•ื‘ื—ื‘ืจืช 2139ืฉื ื™ืช, ื ื™ืชืŸ ืœื›ื•ื•ืŸ ืขื•ื“ ื™ื•ืชืจ ืืช ื”ื ืชื•ื ื™ื ื›ืš ืฉืœื ื™ืชื’ืœื•. ื‘ื™ื•ื ื™

. ืœื”ืœืŸ ืชืžืฆื™ืช ืฉืœ ืžื” ืฉื”ื DNS-ืฉืขื•ืกืง ื‘ื–ื™ื”ื•ื™ ืžื™ื“ืข ืฉืขื•ื‘ืจ ื‘ ื”ื•ืฆื™ืื• ืžืืžืจ" "ืืงืืžื™ ื˜ื›ื ื•ืœื•ื’ื™ื•ืช

ืžื—ืคืฉื™ื:

ืชื•ื•ื™ื(, ืœื“ื•ื’' 251ื‘ืฉื‘ื™ืœ ืžืงืกื™ืžื•ื ืžืงื•ื )ืชื—ืช ื”ืžื’ื‘ืœื” ืฉืœ ื™ืฉืชืžืฉื• ื‘ืฉืžื•ืช ื“ื•ืžื™ื™ืŸ ืงืฆืจื™ืืชื•ืงืคื™ื .1

"28a.de ืฉื ืขืฉื” ื‘ื• ืฉื™ืžื•ืฉ ืขืœ ื™ื“ื™ ื•ื•ื™ืจื•ืก "BernhardPOS ื ื•ื›ืœ ืœื”ืฉืชืžืฉ ื‘ืขืฆืžื ื• 2135ื‘ืฉื ืช .

ื‘ืฉืžื•ืช ื“ื•ืžื™ื™ืŸ ืืจื•ื›ื™ื ื™ื•ืชืจ, ื‘ื›ื•ื•ื ื”.

ืขื ืฉื’ื™ืื•ืช ืงืœื•ืช, ืœื“ื•ื’' ื™ืฉืชืžืฉื• ื‘ืฉืžื•ืช ื“ื•ืžื™ื™ืŸ ืฉื“ื•ืžื™ื ืœืืชืจื™ื ืงื™ื™ืžื™ืืชื•ืงืคื™ื .2

"d4fg732a.deploy-cloudflare.net ืฉืื™ื ื• ืฉื™ื™ืš ืœื—ื‘ืจืช ,"Cloudflare .ืขืฆืžื”

-ืฉื™ื—ืกืžื• ืื•ืชื• ื•ืืช ื›ืœ ืชืชื™, ืกื‘ื™ืจ Data Exfiltrationืžื”ืจื’ืข ืฉืžื•ืฆืื™ื ืฉื“ื•ืžื™ื™ืŸ ืžืฉืžืฉ ืœื‘ื™ืฆื•ืข .3

.ื”ื“ื•ืžื™ื™ืŸ ืฉืœื•

, DNS-ื›ืžื•ืช ืื•ืชื™ื•ืช ืฉื ืฉืœื—ื•, ืกื•ื’ื™ ื‘ืงืฉื•ืช ื” -( per-domain approach) ืื•ืกืคื™ื ืžื™ื“ืข ืขืœ ื›ืœ ื“ื•ืžื™ื™ืŸ .4

ื”ื‘ื“ืœื™ ื–ืžืŸ )ืงื‘ื•ืขื™ื?( ื‘ื™ืŸ ื”ื‘ืงืฉื•ืช. ืื ื”ืขืจืš ืฉืœ ืื—ื“ ืžื”ื ื’ื“ื•ืœ ืžืขืจืš ืกืฃ ืžืกื•ื™ื, ื”ื“ื•ืžื™ื™ืŸ ื™ืกื•ืžืŸ

ื ื™ื ืฉื•ื ื™ื )ืชืžื™ื›ื” ื‘ื–ื” ื‘ื”ืžืฉืš(.ื‘ืชื•ืจ ื‘ืขื™ื™ืชื™. ืื ื›ืš, ื ืฉืชืžืฉ ื‘ืžืกืคืจ ื“ื•ืžื™ื™

Page 53: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

53 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

, ืื• ืชื•ืืžืช TCPืืžื•ืจื” ืœื‘ื•ื ืชืงืฉื•ืจืช DNSืฉืœืื—ืจ ืชืงืฉื•ืจืช ื™ืฉ ืžืขืจื›ื•ืช ืฉืžืกืชืžื›ื•ืช ืขืœ ื›ืš .5

ICMP ื•ื”ืŸ ื™ืฆืคื• ืœื›ืš. ื ื™ืฆื•ืจ ื’ื ืชืงืฉื•ืจืช ,TCP ืชื•ืืžืช ืœืื—ืจ ื‘ืงืฉืช ื”-DNS.

ื”ื•ื•ื“ืื•ืช ืฉืœ -ืœื‘ื“ื•ืง ืืช ืจืžืช ืื™( ื ืขืฉื•ืช ืœื“ื•ืžื™ื™ื ื™ื ืขืœ ืžื ืช Shannon Entropyื‘ื“ื™ืงื•ืช ืื ื˜ืจื•ืคื™ื” ) .6

. ื‘ื“ื™ืงื•ืช ืื ื˜ืจื•ืคื™ื” ืžื•ืฆื™ืื•ืช ื‘ืกื•ืคืŸ ืžืกืคืจ, ื ื™ืงื•ื“ ืกื˜ื˜ื™ืกื˜ื™, ืฉืื•ืžืจ "ืขื“ ื›ืžื” ืช ืฉืœ ื”ื“ื•ืžื™ื™ืŸื”ืื•ืชื™ื•

ืฆืคื•ื™ ื”ื˜ืงืกื˜ ื•ื”ืื•ืชื™ื•ืช ืฉืœื•". ื˜ืงืกื˜ ื‘ืื ื’ืœื™ืช, ืœื“ื•ื’ืžื”, ื‘ืขืœ ืื ื˜ืจื•ืคื™ื” ื ืžื•ื›ื”, ื›ื™ ื”ื•ื ื™ื—ืกื™ืช ืฆืคื•ื™. ืื

' eืื ื—ื ื• ืœื ื™ื•ื“ืขื™ื ืื™ื–ื” ืื•ืช ืชื’ื™ืข ื”ืœืื”, ืื ื—ื ื• ื™ื›ื•ืœื™ื ืœื ื—ืฉ ืฉื™ื•ืชืจ ืกื‘ื™ืจ ืฉื”ืื•ืช ื”ื‘ืื” ืชื”ื™ื” '

'. ืื ื—ื ื• ื™ื›ื•ืœื™ื ืžืื•ืชื™ื•ืช ืจืืฉื•ื ื•ืช ืœื ื—ืฉ ืืช qu' ื”ื•ื ื™ื•ืชืจ ืฆืคื•ื™ ื•ื ืคื•ืฅ ืžื”ืจืฆืฃ 'th', ื•ืฉื”ืจืฆืฃ 'zืฉืจ 'ืžื

ื›ืžื• ืืฆืœื ื•. ืื™ ืืคืฉืจ ืœื“ืขืช ืžื” base36ืฉืืจ ื”ืžื™ืœื”. ื”ื”ืชื ื”ื’ื•ื™ื•ืช ื”ืžืชื•ืืจื•ืช ื›ืืŸ ืœื ื—ืœื•ืช ืขืœ ืงื™ื“ื•ื“

ืชื”ื™ื” ื”ืื•ืช ื”ื‘ืื”, ื›ื™ ื”ืงื™ื“ื•ื“ ืฉืœื ื• ื”ื•ื ืœื ืฉืคื”.

[https://arxiv.org/pdf/1709.08395.pdf]ืžืงื•ืจ:

ื ื•ื›ืœ ืœืขืงื•ืฃ ืืช ื–ื” ื‘ืืžืฆืขื•ืช ืฉื™ืžื•ืฉ ื‘ืงื™ื“ื•ื“ ืžืชืงื“ื ื™ื•ืชืจ, ืฉื‘ื ื•ื™ ืžืžืกืคืจ ืื•ืชื™ื•ืช, ืื• ื™ืงื•ื“ื“ ื›ืœ ื‘ื™ืช ืœืžื™ืœื”

ืœื’ื™ื˜ื™ืžื™ืช ื‘ืื ื’ืœื™ืช )ื›ืžื• ื‘ื“ื•ื’ืžื ื‘ื—ื™ื“ืช ื”ืืกื™ืจื™ื ืœืžืขืœื”(.

ื”ืขื‘ืจืช ื›ืœ ื”ืžื™ื“ืข.ืœ ืจืง ื‘ื“ื•ืžื™ื™ืŸ ืื—ื“ื•ืขื“ ื”ื™ื•ื ื”ืฉืชืžืฉื• 2118ื›ืœ ื•ื•ื™ืจื•ืก ืžืื– .7

Aื”ืŸ ืžืกื•ื’ DNS-ืžื‘ืงืฉื•ืช ื” 88.1% -ืงืœืืกื™ื•ืช. ืœืคื™ ืžืงื•ืจ ืฉื”ื ืžืฆื˜ื˜ื™ื DNSืžืฆืคื™ื ืœืกื•ื’ื™ ื‘ืงืฉื•ืช .8

(. ืœื›ืŸ, ื™ืฉ ืœืฆืคื•ืช ื‘ืขื™ืงืจ Reverse lookup pointers) PTR-( ื•IPv6-)ืžื™ื•ืขื“ ืœ AAAA(, IPv4-)ืžื™ื•ืขื“ ืœ

ืœื”ืŸ.

ื”ื“ื•ืžื™ื™ืŸ ืฉืœื• )ื›ื™ -ื•ืจ ืขืœ ืชืชื™ื“ื•ืžื™ื™ืŸ ืฉืžืฉืชืžืฉื™ื ื‘ื• ืœื”ืขื‘ืจืช ืžื™ื“ืข ืœืจื•ื‘ ืœื ื™ื—ื– - ื“ื•ืžื™ื™ืŸ-ื™ื™ื—ื•ื“ื™ื•ืช ืชืชื™ .9

ื“ื•ืžื™ื™ืŸ ืชื—ืช ื“ื•ืžื™ื™ืŸ ืžืกื•ื™ื.-ื”ื•ื ืจื•ืฆื” ืœื”ืขื‘ื™ืจ ื”ื•ื“ืขื•ืช ืฉื•ื ื•ืช(. ืœื›ืŸ, ืžื—ืคืฉื™ื ืืช ื”ื™ื™ื—ื•ื“ื™ื•ืช ืฉืœ ืชืชื™

ื›ื“ื™ Cache-ื™ื ืกื• ืœื”ืชื—ืžืง ืœืจื•ื‘ ืžืฉื™ืžื•ืฉ ื‘ DNS-ืชื•ืงืคื™ื ืฉืžืฉืชืžืฉื™ื ื‘ - DNSื ืคื— ืชืงืฉื•ืจืช .10

ื”ืชื—ืžืงื•ื™ื•ืช ืื—ืจื•ืช ืงืฆืจื™ื ืื• TTLืฉื”ืžื™ื“ืข ื™ื’ื™ืข ืœืฉืจืช ืฉืœ ื”ืชื•ืงืฃ. ื”ื ืžื ืกื™ื ืœืจื•ื‘ ืœื”ืฉืชืžืฉ ื‘ืขืจื›ื™

ืžืฉื™ืžื•ืฉ ื‘ืžื˜ืžื•ืŸ. ื›ืชื•ืฆืื” ืžื›ืš, ื ืคื— ื”ืžื™ื“ืข ืฉื ืฉืœื— ืœื“ื•ืžื™ื™ืŸ ืžืกื•ื™ื ื”ื•ื ื’ื‘ื•ื” ืžืฉืžืขื•ืชื™ืช ืœืื•ืจืš ื–ืžืŸ.

ื™ื—ืคืฉื• ืืช ืื•ืจืš ื”ื“ื•ืžื™ื™ืŸ ื”ืžืžื•ืฆืข ืฉืžื•ืขื‘ืจ, ื•ืฆืจื™ืš ืœื•ื•ื“ื ืฉื”ื•ื ื™ื”ื™ื” ืงืฆืจ ื™ื—ืกื™ืช. -ื”ืื•ืจืš ืงื•ื‘ืข! .11

Page 54: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

54 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

, ืฉื‘ื•ื“ืง ืืช ื”ื”ื’ื“ืจื•ืช ื›ืชื‘ื• ืžืืžืจ ื“ื•ืžื”ื‘ืกื™ื“ื ื™ UNSW, ื—ื•ืงืจื™ื ืžืื•ื ื™ื‘ืจืกื™ื˜ืช 2138ื‘ื ื•ื‘ืžื‘ืจ

Machine Learningื‘ืืžืฆืขื•ืช DNS Tunnelingื”ืžืชืื™ืžื•ืช ืœืžืขืจื›ืช ืฉืชื•ื›ืœ ืœื–ื”ื•ืช ื•ืœื”ื’ืŸ ื‘ื–ืžืŸ ืืžืช ืžืคื ื™

ืจืืฉื™ืช ื”ื•ื ืงืฆืจ ืžื“ื™ -ื‘ื–ื™ื”ื•ื™ ืžื•ืฆืœื—(. ื”ื™ื™ืชื™ ืœื•ืงื— ืืช ื”ืžื—ืงืจ ื”ื–ื” ื‘ืขื™ืจื‘ื•ืŸ ืžื•ื’ื‘ืœ 85%)ืขื ื“ื™ื•ืง ืฉืœ

)ื ื•ืจื” ืื“ื•ืžื” ื’ื“ื•ืœื”(, ื•ืฉื ื™ืช ืื ื™ ืžื•ืฆื ืฉื”ื‘ื“ื™ืงื•ืช ืฉื”ื ืขืฉื• ื”ื™ื• ืžื™ื•ืฉื ื•ืช, ืœื ืžื“ื•ื™ืงื•ืช ื‘ืžื™ื•ื—ื“ ื•ืœื

ืžืงื™ืคื•ืช. ืขื ื–ืืช, ืžื’ื™ืข ืœื”ื ื—"ื— ืขืœ ื”ื’ื“ืจืช ื”ืžืืคื™ื™ื ื™ื ืฉื”ืžื›ื•ื ื” ื”ืœื•ืžื“ืช ืฆืจื™ื›ื” ืœื—ืคืฉ:

[Time_Detection_of_DNS_Exfiltration_and_Tunneling_from_Enterprise_Networks-Real]ืžืงื•ืจ:

ื™ื ื›ื™ ื“ื•ืžื™ื™ื ื™ื ืืจื•ื›ื™ื ื™ื•ืชืจ ืขืœื•ืœื™ื ืœื”ื›ื™ืœ ืžื™ื“ืข ื”ื—ื•ืงืจื™ื ืกื‘ื•ืจ - (FQDNื›ืžื•ืช ืื•ืชื™ื•ืช ื‘ื“ื•ืžื™ื™ืŸ ) .1

ื›ืชื•ื‘ื•ืช ื”ื“ื•ืžื™ื™ืŸ ืชื•ื•ื™ื, ืืš 239 - 11ืจื’ื™ืฉ. ื‘ืžืขืจื›ืช ืฉืœื”ื ื ืงืœื˜ื• ื•ื ืชืคืกื• ื“ื•ืžื™ื™ื ื™ื ืฉื•ื ื™ื ื‘ืื•ืจืš

ืชื•ื•ื™ื. 93-ืœ 11ื‘ื™ืŸ - ืฉืœื ื ืงืœื˜ื• ื”ื™ื• ืงืฆืจื•ืช ืžืฉืžืขื•ืชื™ืช

ื›ื™ื ื‘ืื•ืจื›ื™ื ื“ื•ืžื™ื™ืŸ ืืจื•-ืชืชื™ - ื›ืžื•ืช ืื•ืชื™ื•ืช ื‘ืชืชื™ ื”ื“ื•ืžื™ื™ืŸ )ื›ืœ ื”ืื•ืชื™ื•ืช ืฉืžืฉืžืืœ ืœื“ื•ืžื™ื™ืŸ ื”ืจืืฉื™( .2

- 31ื ืชืคืกื• ื‘ืžืขืจื›ืช, ื‘ืขื•ื“ ืฉื“ื•ืžื™ื™ื ื™ื ืฉืœื ื ืชืคืกื• ื”ื™ื• ืงืฆืจื™ื ืžืฉืžืขื•ืชื™ืช )ื‘ื™ืŸ 215 - 21ืžืฉืชื ื™ื ื‘ื™ืŸ

ืชื•ื•ื™ื(. 29

ื”ื—ื•ืงืจื™ื ืžืกืชืžื›ื™ื ืขืœ ื›ืš ืฉืžืจื‘ื™ืช ื”ืฉื™ื˜ื•ืช ืฉืขื•ืกืงื•ืช -ื›ืžื•ืช ืื•ืชื™ื•ืช ื’ื“ื•ืœื•ืช ื•ื›ืžื•ืช ืกืคืจื•ืช .3

ืชื™ ืฆืคื•ื™ ืฉืœ "ื˜ืงืกื˜ ืจื ื“ื•ืžืœื™" ืฉืžืื•ืคื™ื™ืŸ ื‘ืงื™ื•ืžืŸ ื”ื‘ืœ-ืžืฉืชืžืฉื™ื ื‘ DNSื‘ื”ื•ืฆืืช ืžื™ื“ืข ื‘ืืžืฆืขื•ืช

ืื•ืชื™ื•ืช ื’ื“ื•ืœื•ืช ื•ืกืคืจื•ืช. ืœื“ื‘ืจื™ื”ื, ืื•ืชื™ื•ืช ื’ื“ื•ืœื•ืช ื•ืžืกืคืจื™ื ื”ื ืกื™ืžื ื™ื ื‘ืจื•ืจื™ื ืœืžื™ื“ืข

ืฉืžืงื•ื“ื“/ืžื•ืฆืคืŸ. ืขื ื–ืืช, ื”ื ืžื•ื“ื™ื ืฉืœื ื›ืœ ื”ืžื™ื“ืข "ื”ื‘ืœืชื™ ืงืจื™ื" ื”ื•ื ื‘ื”ื›ืจื— ื ื•ื–ืงื” ืฉืžื ืกื”

ืœื”ื•ืฆื™ื ืžื™ื“ืข ืžืžื—ืฉื‘ ืืจื’ื•ื ื™, ื•ืœื›ืŸ ืžืกืชืžื›ื™ื ืขืœ ืฉืงืœื•ืœ ืขื ื ืชื•ื ื™ื ื ื•ืกืคื™ื.

ืœืžืขืœื”.ืื•ืชื• ื“ื‘ืจ ื›ืžื• -ืื ื˜ืจื•ืคื™ื” .4

, ื–ืืช ื›ื™ ื”ื labels-ื”ื—ื•ืงืจื™ื ื”ืฉืชืžืฉื• ื‘ืกืคื™ืจืช ื›ืžื•ืช ื” - )ื›ืžื•ืช ื”ื ืงื•ื“ื•ืช( labels-ืกืคื™ืจืช ื›ืžื•ืช ื” .5

-ืžืืžื™ื ื™ื ืฉื™ืฉื ืŸ ืชื‘ื ื™ื•ืช ื‘ืจื•ืจื•ืช ืฉื—ื•ื–ืจื•ืช ืขืœ ืขืฆืžืŸ )ื›ืžื• ืฉื™ืฉ ืชื‘ื ื™ืช ื‘ืจื•ืจื” ืฉื—ื•ื–ืจืช ืขืœ ืขืฆืžื” ื‘

DNSExfil ื–ืืช ื‘ื”ื—ืœื˜ ื ืงื•ื“ื” ื˜ื•ื‘ื”, ืœืžืจื•ืช ืฉื™ืฉื ืŸ ื“ืจื›ื™ื ืœืขืจืคืœ ืืช ื”ืžื™ื“ืข ืขื•ื“ ื™ื•ืชืจ, ื›ืš ืฉืœื .)

ื™ื”ื™ื” ื ื™ืชืŸ ืœื–ื”ื•ืช ืื•ืชื•.

ื”ืžืงืกื™ืžืœื™ ื•ื”ืžืžื•ืฆืข ืฉืœ label-ืœื‘ืกื•ืฃ, ื”ื—ื•ืงืจื™ื ื‘ื•ื“ืงื™ื ืืช ืื•ืจืš ื” -ืžืงืกื™ืžืœื™/ืžืžื•ืฆืข labelืื•ืจืš .6

ืงืฆืจื™ื. labelsืืจื•ื›ื™ื ื™ื•ืชืจ ืกื‘ื•ืจื™ื ืœื”ืชื’ืœื•ืช ืžืืฉืจ labels-ื›ืœ ื“ื•ืžื™ื™ืŸ. ื–ื” ื ืจืื” ืฉ

Page 55: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

55 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ืจืขื™ื•ื ื•ืช ืœืฉื™ืคื•ืจ

ื™ ื—ื•ืฉื‘ ืฉืขืœื• ืœื—ืœืงื›ื )ืื ื™ืฉ ืœื›ื ืื—ืจื™ ืฉื™ืจื“ื ื• ืขืœ ื”ืคืจื•ื™ืงื˜ ืฉืœื™, ื ืžืฉื™ืš ืขื ืžืกืคืจ ืจืขื™ื•ื ื•ืช ืœืฉื™ืคื•ืจ ืฉืื 

ื›ืคื™ ืฉืืžืจืชื™, ื”ืคืจื•ื™ืงื˜ ื”ื–ื” ื”ื•ื ืจืขื™ื•ื ื•ืช ืฉืœื ื›ืชื‘ืชื™ ืคื”, ืžื•ื–ืžื ื™ื ืœื›ืชื•ื‘ ืœื™, ื”ืžื™ื™ืœ ืฉืœื™ ื›ืชื•ื‘ ืœืžื˜ื”(.

ืจืง ื”ื”ืชื—ืœื” ืฉืœ ื›ืœื™ ืžืงื™ืฃ ืฉืืžื•ืจ ืœื“ืขืช ืœื”ืชืžื•ื“ื“ ืขื ื‘ืขื™ื•ืช ืฉื•ื ื•ืช ื•ืžืขืจื›ื•ืช ื”ื’ื ื” ืฉื•ื ื•ืช. ืชืžื™ื“ ื™ืฉ

ืžืงื•ื ืœื”ืฉืชืคืจ, ื•ื”ืคืจืง ื”ื–ื” ืžื•ืงื“ืฉ ืœื›ืš.

?ืชื•ืกื™ืฃ ืฉื™ืžื•ืฉ ื‘ื”ืฆืคื ื”

, RC4-ื™ื”ื™ื” ื ื™ืชืŸ ืœืžืฆื•ื ื‘ืขื“ื›ื•ืŸ ื”ืงืจื•ื‘ ืฉืœ ื”ืงื•ื“ ื”ื•ืกืคื” ืฉืœ ืžืกืคืจ ืกืคืจื™ื•ืช ืœื”ืฆืคื ื” )ื ืชื—ื™ืœ ืž -ื‘ื”ื—ืœื˜!

AES ื•-Blowfish ,ื”ืืจื›ื™ื˜ืงื˜ื•ืจื” ืฉืœื”ื ืชื”ื™ื” ื“ื•ืžื” ืœืื—ืช ืฉื”ืฉืชืžืฉืชื™ ื‘ื” ื‘ืฉื‘ื™ืœ ืกืคืจื™ื•ืช ื”ื“ื—ื™ืกื” .)

ืœื™ื ืžื”ื› 91%-ื•ืื ื™ ืฆืคื•ื™ ืœื™ื™ืฉื ืื•ืชื” ืจืืฉื™ืช ื‘ืคื™ื™ืชื•ืŸ )ื›ื™ ืื™ืŸ ืžื” ืœืขืฉื•ืช ื–ืืช ืฉืคื” ื™ื•ืชืจ ืžื“ื™ ื ืคื•ืฆื” ื•

ื›ืชื•ื‘ื™ื ื‘ื”( ื•ืœืื—ืจ ืžื›ืŸ ื’ื ื‘ืฉืคื•ืช ื ื•ืกืคื•ืช.

ืžื” ืขื ืชืžื™ื›ื” ื‘ืžืกืคืจ ื›ืชื•ื‘ื•ืช ื“ื•ืžื™ื™ืŸ ื‘ื• ื–ืžื ื™ืช?

ื‘ืื•ืชื• ื“ื•ืžื™ื™ืŸ t2-ื• t1ื“ื•ืžื™ื™ื ื™ื ืฉื•ื ื™ื )-ื‘ื’ืจืกื” ื™ืฉื ื” ื™ื•ืชืจ ืฉืœ ื”ืงื•ื“ ื”ื•ืกืคืชื™ ืืช ื”ืชืžื™ื›ื” ื‘ืžืกืคืจ ืชืชื™

ื–ืืช, ( ื•ื–ื” ืขื‘ื“ ื ื”ื“ืจ )ื”ื•ืจื“ืชื™ ืืช ื–ื” ืžื”ื’ืจืกื” ืฉื”ืขืœื™ืชื™ ื›ื™ ืœื ื”ืกืคืงืชื™ ืœื‘ื—ื•ืŸ ืืช ื–ื” ื›ืจืื•ื™(. ืขื ืจืืฉื™

ืชืžื™ื›ื” ื‘ืžืกืคืจ ื“ื•ืžื™ื™ื ื™ื ืฉื•ื ื™ื ืœื—ืœื•ื˜ื™ืŸ ื–ื” ืœื ื“ื‘ืจ ืฉื ื™ืกื™ืชื™, ืื‘ืœ ื‘ื”ื—ืœื˜ ืžืชื›ื ืŸ ืœื ืกื•ืช ื‘ืงืจื•ื‘. ืจืื™ื ื•

ืœืžืขืœื” ืฉืžืจื‘ื™ืช ื”ื•ื•ื™ืจื•ืกื™ื ืžืกืชืžื›ื™ื ืจืง ืขืœ ื“ื•ืžื™ื™ืŸ ืื—ื“ ืฉื“ืจื›ื• ืขื•ื‘ืจื•ืช ื›ืœ ื”ื”ื•ื“ืขื•ืช, ื•ืฉื™ืžื•ืฉ ื‘ื›ืžื” ื™ื›ื•ืœ

ืœื”ื™ื•ืช ืฉื“ืจื•ื’ ืžืื•ื“ ืžืขื ื™ื™ืŸ.

(DNSBinืฉืœื™ืฉื™ )-ืฆื“ DNSืœื”ืฉืชืžืฉ ื‘ืฉื™ืจื•ืช

ื‘ื”ื—ืœื˜ ืจืื™ืชื™ ืืช ื”ืคื•ื˜ื ืฆื™ืืœ ืฉืœ ืœืขื‘ื•ื“ ื‘ืฉื™ืชื•ืฃ ืขื RequestBinืฉืœ DNSBinืื– ืฉืจืื™ืชื™ ืืช ื•ื•ืื•. ื›ืŸ. ืž

ื•ื”ืชื•ืงืฃ RequestBinืฉืœ DNS-ืฉื™ืจื•ืชื™ื ื›ืืœื”. ื‘ืื•ืคืŸ ืชื™ืื•ืจื˜ื™, ื”ืžื—ืฉื‘ ื”ืืจื’ื•ื ื™ ื™ื™ืฆื•ืจ ืงืฉืจ ืขื ืฉืจืช ื”

ื” ื™ืขื ื” ืขืœ ื”ื“ืจื™ืฉื” ืœื ืœื”ื™ื•ืช ื‘ืชืงืฉื•ืจืช ื™ืฉื™ืจื” ืคืฉื•ื˜ื•ืช. ื– HTTPื™ื›ื•ืœ ืœืงืœื•ื˜ ืืช ื”ืžื™ื“ืข ื”ื–ื” ื“ืจืš ื‘ืงืฉื•ืช

ืขื ื”ืžื—ืฉื‘ ื”ืืจื’ื•ื ื™. ืขื ื–ืืช, ื–ื” ืœื ืฆืคื•ื™ ืœื”ื™ื•ืช ืคื™ืฆ'ืจ ืฉืื ื™ ืื›ื ื™ืก ื‘ืงืจื•ื‘, ืื‘ืœ ืื•ืœื™ ื‘ืฉืœื‘ื™ื ืžืื•ื—ืจื™ื

ื™ื•ืชืจ.

ืœื’ืจื•ื ืœื›ืชื•ื‘ื•ืช ื“ื•ืžื™ื™ืŸ ืœื”ื™ืจืื•ืช ื ื•ืจืžืœื™ื•ืช )ื‘ืื•ืจืš ื•ื‘ืชื•ื›ืŸ(

ื™ื“ืข ื”ืžืงื•ื“ื“ ื‘ื›ืชื•ื‘ื•ืช ื›ืคื™ ืฉื›ืชื‘ืชื™, ืื ื™ ื‘ื”ื—ืœื˜ ืžืชื›ื ืŸ ืœืชืช ืœืžืฉืชืžืฉ ืฉืœื™ื˜ื” ืžืœืื” ืขืœ ืื•ืจืš ื•ืชื•ื›ืŸ ื”ืž

ื”ื“ื•ืžื™ื™ืŸ. ื”ืžืขืจื›ืช ื ื‘ื ืชื” ื‘ืžื—ืฉื‘ื” ืขืœ ื“ื™ื ืืžื™ื•ืช ืžืงืกื™ืžืœื™ืช, ื›ืš ืฉื–ืืช ืœื ืืžื•ืจื” ืœื”ื™ื•ืช ื‘ืขื™ื”.

(DNS Upstreamื‘ืงืฉื•ืช ืฉืขื•ื‘ืจื•ืช ืฉืื™ื ืŸ ืงืฉื•ืจื•ืช ื™ื›ื•ืœื•ืช ืœื”ื™ืขื ื•ืช ื›ืจื’ื™ืœ )

DNS-ืขืœ ื›ืœ ื‘ืงืฉื” ืฉื”ื’ื™ืขื” ืœืฉืจืช ืฉืœื ื ืจืื™ืช ื›ืžื• ื‘ืงืฉื•ืช ื” -ื–ื” ื’ื ืจืขื™ื•ืŸ ืฉื™ืฆื ืœื™ ืœืฉื—ืง ืื™ืชื•

ื•ืœื”ื—ื–ื™ืจ ื—ื–ืจื” ืืช 9.9.9.9ืžื•ื›ืจ ื›ืžื• DNSื’ื ื›ืืœื”(, ืคืฉื•ื˜ ืœื”ืขื‘ื™ืจ ืืช ื”ืžื™ื“ืข ืœืฉืจืช ื”ืžืงื•ื“ื“ื•ืช )ื™ืฉ

Page 56: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

56 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ื”ืžื™ื“ืข. ืžื ื™ืกื™ื•ื ื™, ืจืื™ืชื™ ืฉืœืขืฉื•ืช ื–ืืช ืขื•ืœื” ืœื ืžืขื˜ ืžืฉืื‘ื™ื ื•ื–ืžืŸ ืœืฉืจืช, ื•ื’ื•ืจื ืœืžืขื ื” ืื™ื˜ื™ ื™ื•ืชืจ

, ื™ื’ื™ืขื• ืืœื™ื• ืจืง ื‘ืงืฉื•ืช ืฉืงืฉื•ืจื•ืช ืืœื™ื• )ืืœื ืื ื›ืŸ ืžื™ืฉื”ื• ื™ื™ื’ืฉ ืืœื™ื• NS-ื‘ืžืžื•ืฆืข. ื‘ื ื•ืกืฃ, ื›ืฉืฉืจืช ืžื•ื’ื“ืจ ื›

ืกื˜ื ื“ืจื˜ื™ ืื‘ืœ ืœืžื” ืฉืžื™ืฉื”ื• ื™ืขืฉื” ืืช ื–ื”(. ื‘ืžืฆื‘ ื›ื–ื”, ื”ื•ื ืขืœื•ืœ ืœื’ืจื•ื ืœืœื•ืœืื” )ืฉืจืช DNSืฉืจืช ื‘ืชื•ืจ

ื•ื›ืŸ ื”ืœืื”(. ืื ื™ ืœื ื‘ื˜ื•ื— ืฉืœื”ื•ืกื™ืฃ ืืช ื–ื” ื›ืคื™ืฆ'ืจ NS-ืฉืœ ื’ื•ื’ืœ, ืฉืžื‘ืงืฉ ื—ื–ืจื” ืžื” DNS-ืžื‘ืงืฉ ืžื” NS-ื”

ื–ื” ืจืขื™ื•ืŸ ื˜ื•ื‘.

ืœื”ื—ื–ื™ืจ )ื›ื•ืœืœ ื”ื›ืœื™ ืฉืœื™( DNS-ืžื” ืฉืื ื™ ื›ืŸ ืžืืžื™ืŸ ืฉื™ืฉ ืœืฉื ื•ืช, ื–ื” ืืช ื”ื”ืจื’ืœ ืฉืœ ื—ืœืง ืžื›ืœื™ ื”

NXDOMAIN ื“ื•ืžื™ื™ืŸ ืœื ืงื™ื™ื( ื‘ืชื•ืจ ืชื’ื•ื‘ื” ืœื›ืœ ืฉืื™ืœืชืช(DNS ืื ื™ ืžืืžื™ืŸ ืฉืชื’ื•ื‘ื•ืช ื›ืืœื• ืขืœื•ืœื•ืช ืœื”ืชืจื™ืข .

ืงื™ื™ื ื‘ื–ืžืŸ ื›ื” ืงืฆืจ. ื”ื“ื•ืžื™ื™ืŸ ืฆืจื™ืš -ืœื-ืฉื•ื ื•ืช, ื›ื™ ืื™ืŸ ืกื™ื‘ื” ืฉื™ื’ื™ืขื• ื›ืœ ื›ืš ื”ืจื‘ื” ืชื’ื•ื‘ื•ืช ื“ื•ืžื™ื™ืŸ DNSืžืขืจื›ื•ืช

ื” ืœืงื•ื“.ืœื”ื—ื–ื™ืจ ืชืฉื•ื‘ื” ืขื ื™ื™ื ื™ืช, ืขื“ื›ื ื™ืช ื•ืœื’ื™ื˜ื™ืžื™ืช. ื‘ื”ื—ืœื˜ ืืฉืืฃ ืœื”ื•ืกื™ืฃ ืืช ื–

ื›ื™ื•ื•ื ื™ืช-ืืคืฉืจื•ืช ืœืชืงืฉื•ืจืช ื“ื•

ื›ื™ื•ื•ื ื™ืช ืžื›ืจื™ื—ื” ืื•ืชื ื• ืœื”ืฉืชืžืฉ ื‘ืชืงืฉื•ืจืช ืžื”ื™ืจื” ื™ื—ืกื™ืช, -ื™ืฉ ื›ืœื™ื ืื—ืจื™ื ืฉืขื•ืฉื™ื ืืช ื–ื”. ืชืงืฉื•ืจืช ื“ื•

ื•ื–ื” ืขืœื•ืœ ืœื—ืฉื•ืฃ ืืช ื”ืขืจื•ืฅ ื”ืกืžื•ื™. ืื ื™ ื›ืŸ ืจื•ืฆื” ืœื”ื•ืกื™ืฃ ืคื™ืฆ'ืจ ื›ื–ื”, ืื‘ืœ ืคื—ื•ืช ื“ื—ื•ืฃ ืœื™ ื›ืจื’ืข ื›ื™ ืื ื™

ืื•ืœื™ ื‘ืขืชื™ื“, .DNSืžื‘ื•ืกืก reverse shellื‘ื ื™ื™ืช ืžืชืจื›ื– ื‘ื”ื•ืฆืืช ืžื™ื“ืข ื‘ืฆื•ืจื” ื ื›ื•ื ื” ื•ืื™ื˜ื™ืช, ื•ืคื—ื•ืช ื‘

ื‘ื”ื—ืœื˜.

Rust-ืœื›ืชื•ื‘ ืืช ื–ื” ืžื—ื“ืฉ ื‘

ื›ื™ ืื ื™ ืžืืžื™ืŸ ืฉื–ื” ืื—ื“ ืžื”ืฉืคื•ืช ืฉื”ื›ืœื™ ื”ื–ื” ืืžื•ืจ ืœื”ื™ื•ืช Python3-ื›ืŸ. ื›ืŸ. ื›ืŸ. ื›ืชื‘ืชื™ ืืช ื–ื” ื‘ื”ืชื—ืœื” ื‘

, ืฉืขืฉื” ืขื‘ื•ื“ื” ื ื”ื“ืจืช ื›ืฉื‘ื ื™ืชื™ ืกื‘ื™ื‘ื• ืชื•ืกืฃ JS-ื›ืชื•ื‘ ื‘ื”ืŸ. ื’ื ื›ืชื‘ืชื™ ื’ืจืกื” ื‘ืกื™ืกื™ืช ืฉืœ ื”ื›ืœื™ ื”ื–ื” ื‘

ืื—ืช -ืชืงื ืชื™ ืื•ืชื• ืขืœ ืžื—ืฉื‘. ืื ื™ ืžืืžื™ืŸ, ืฉื”ืคืจื•ื™ืงื˜ ื”ื–ื” ืฆืจื™ืš ืœื”ื™ื•ืช ื›ืชื•ื‘ ื‘ืžืกืคืจ ืฉืคื•ืช ื›ืจื•ื ื•ื”

( ื•ืื—ืช ืฉืคื•ืขืœืช JS(, ืื—ืช ืฉืคื•ืขืœืช ื‘ื“ืคื“ืคื ื™ื )ื‘ืžืงืจื” ืฉืœื ื•, Rust)ื‘ืžืงืจื” ืฉืœื ื•, native-ืฉืžืชืงืžืคืœืช ืœ

ืžืกืคืงืช ืœื™ Python-(. ื›ืชื™ื‘ืช ื”ื›ืœื™ ื‘Python 3ืขืœ ืฉืจืชื™ื, ืžื—ืฉื‘ื™ ืœื™ื ื•ืงืก ื•ืงืœ ืœืชื›ื ืช ื‘ื” )ื‘ืžืงืจื” ื”ื–ื”,

ื•ืช ื‘ื ื•ื’ืข ืœืื™ืš ืœื™ื™ืฉื ืื•ืชื” ื‘ื™ืขื™ืœื•ืช ื‘ืฉืคื•ืช ืื—ืจื•ืช.ืฆืœื™ืœ

Page 57: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

57 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ืกื™ื›ื•ื

, ื–ืœื™ื’ืช DNSื•ืžืฉื”ื• ืขืžื•ื“ื™ื ื”ืœืœื• ื›ื™ืกื™ื ื• ื”ืจื‘ื” ืžืื•ื“ ื ื•ืฉืื™ื )ื“ื—ื™ืกื”, ื”ืฆืคื ื”, ืงื™ื“ื•ื“ ืžื™ื“ืข, -51-ืœืื•ืจืš ื”

(. ื”ื’ื“ืจื ื• ืžื” ื–ืืช ื–ืœื™ื’ืช ืžื™ื“ืข, ื•ืขื•ื“ ICMPืื ื˜ืจื•ืคื™ื”, ืงื™ื“ื•ื“ื™ื ื‘ื‘ืกื™ืกื™ื ืฉื•ื ื™ื, ืžื™ื“ืข, ืขืจื•ืฆื™ื ืกืžื•ื™ื™ื,

ื•ื™ื™ื, ื•ืกื™ืคืงืชื™ ื“ื•ื’ืžืื•ืช ืฉื•ื ื•ืช ืฉื”ืฉืชืžืฉื• ื‘ื”ื ื‘ืขื‘ืจ. ื“ื™ื‘ืจื ื• ื’ื ืขืœ ืขืฉืจืช ื“ื™ื‘ืจื ื• ืขืœ ืขืจื•ืฆื™ื ืกืž

ื”ื“ื™ื‘ืจื•ืช ืฉืฆืจื™ื›ื•ืช ืœื”ืชืงื™ื™ื ื‘ืฉื™ื˜ื” ื˜ื•ื‘ื” ืœื–ืœื™ื’ืช ืžื™ื“ืข. ืœืื—ืจ ืžื›ืŸ ื ื›ื ืกื• ืœื ืขืœื™ื™ื ืฉืœ ืชื•ืงืฃ ืคื•ื˜ื ืฆื™ืืœื™

ื•ืขืœ ื”ืชื ืื™ื ื•ื”ืžื’ื‘ืœื•ืช ืฉืฆืจื™ื›ื™ื ืœื”ืชืงื™ื™ื ื‘ื“ื•ืžื™ื™ืŸ ืœื’ื™ื˜ื™ืžื™. DNSื•ื“ื™ื‘ืจื ื• ืขืœ

ืœื• ืœืฉื™ื˜ื” ืœืงื™ื“ื•ื“ ื›ืœ ืกื•ื’ ืฉืœ ืžื™ื“ืข. ื”ืฆื’ืชื™ ืืช ื”ืคืจื•ื™ืงื˜ ืฉืœื™, ืขื‘ืจื ื• ืขืœ ื”ื”ืœื™ืš ืœื”ืžื™ืจ ืืช ื”ืžื’ื‘ืœื•ืช ื”ืœ

12-ืฉืขืœื™ื• ืืขื‘ื•ื“ ื‘ืชืงื•ืคื” ื”ืงืจื•ื‘ื”, ื•ืืช ื”ืชื•ื›ื ื™ื•ืช ืฉืœื™ ืืœื™ื• ืœื–ืžืŸ ื”ืงืจื•ื‘. ื ื—ืฉืคืชื ืœืžื™ื“ืข ืžืœื ืคื—ื•ืช ืž

ื”ื™ื” ืจืง ืงืฆื” ื”ืžื–ืœื’ ืœื›ืœ ื”ืชื—ื•ื ื”ืขืฆื•ื ืฉืœ -ืžื—ืงืจื™ื ืฉื•ื ื™ื, ื›ื•ืœืœ ืžื—ืงืจื™ื ืื™ืฉื™ื™ื ืฉืื ื™ ืขืฉื™ืชื™. ื•ื›ืœ ื–ื”

Data Exfiltration .

ืชื•ื“ื” ืจื‘ื” ืฉืคื™ื ื™ืชื ืžื–ืžื ื›ื, ื•ืื ื™ -ืขืžื•ื“ื™ื ืฉืœ ืงืจื™ืื” 21ืืœื• ืฉื”ื’ื™ืขื• ืœืคืจืง ื”ื–ื”, ืœืื—ืจ ื›ืžืขื˜ ืื– ืœ

ืžื ื™ื— ืฉื ืชืจืื” ื‘ื—ืœืง ื”ื‘ื )ืžืชื™ ืฉื–ื” ื™ื”ื™ื”(.

ื”ืจืฆืื•ืช ื ื•ืกืคื•ืช ืขืœ ื”ื ื•ืฉื )ืžืžืœื™ืฅ ื‘ื—ื•ื(

Misuse of DNS, the Second Most Used Protocol | Black Hat Asia 2020 - YouTube

AWS GuardDuty: Post-DNS Era Covert Channel For C&C - Sze Siong Teo | HITB SecConf

Amsterdam 2021 - YouTube

PacketWhisper Stealthily Exfiltrating Data | DEFCON 26 - 2018 - YouTube

Low & Slow - Techniques for DNS Data Exfiltration - Dimitri Fousekis | BSidesLV 2019 - YouTube

Page 58: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

58 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ืขืœ ื”ืžื—ื‘ืจ

ื™ื—"ืœ ื‘ืจืฉืช ืื•ืจื˜. ื™ืฉ 5(. ืžืชื›ื ืช, ื—ื•ืงืจ ืื‘ื˜ื—ืช ืžื™ื“ืข ืขืฆืžืื™ ื•ืขื“ ืœืื—ืจื•ื ื” ืžื•ืจื” ืœืกื™ื™ื‘ืจ 38ืžืื•ืจ ื’ื•ืจื“ื•ืŸ )

ืœืชื•ืš ื”ืœื™ืœื” ื•ืœืกืคืจ CTFืชื’ืจื™ ืœืœืžื•ื“ ื“ื‘ืจื™ื ื—ื“ืฉื™ื, ืœืคืชื•ืจ ื -ืฉืœื•ืฉื” ื“ื‘ืจื™ื ื‘ืขื•ืœื ืฉืื ื™ ืื•ื”ื‘ ืœืขืฉื•ืช

ืกื™ืคื•ืจื™ื ืžื’ื ื™ื‘ื™ื )ื›ืžื• ื”ืกื™ืคื•ืจ ืฉืงืจืืชื ืขื›ืฉื™ื•(. ื‘ืžืงื•ืจ ืžืจื—ื•ื‘ื•ืช, ื”ื™ื›ืŸ ืฉืื ื™ ืžื—ื›ื” ืœื’ื™ื•ืก ื”ืงืจื•ื‘ ืฉืœื™.

(. ืชื•ื›ืœื• ืœืžืฆื•ื ืื•ืชื™ ื‘ื“ื™ืกืงื•ืจื“ UI/UXืžื‘ื™ืŸ ื”ื›ื•ื‘ืขื™ื ื”ืจื‘ื™ื ืฉืœื™ ืื ื™ ื’ื ืžื•ืกื™ืงืื™ ื•ืžืขืฆื‘ ื’ืจืคื™ )

(mmgordon82#8278 ื•ื‘ืžื™ื™ืœ. ืžื•ื–ืžื ื™ื ืœืจืื•ืช ื’ื ืืช )ืฉืขืฉื™ืชื™ ืขืœ ื”ื•ื“ืขืช ืกืคืื ื”ื”ืจืฆืื” ื”ืื—ืจื•ื ื”

(.ื‘ื™ื™ื˜-ืงืœื™ืงืžืื•ื“ ืžืขื ื™ื™ื ืช ืฉืงื™ื‘ืœืชื™ ื‘ืคื™ื™ืกื‘ื•ืง )ืžืชื ืฆืœ ืžืจืืฉ ืขืœ ื”ืื™ื›ื•ืช ื”ื™ืจื•ื“ื” ื•ื”ืฉื ื”ืžืื•ื“

ื™ืฉ ืœื›ื ืจืขื™ื•ื ื•ืช ื—ื“ืฉื™ื? ืจื•ืฆื™ื ืœื“ื‘ืจ? ื™ื•ืชืจ ืžืžื•ื–ืžื ื™ื ืœื™ืฆื•ืจ ืื™ืชื™ ืงืฉืจ ื‘ืžื™ื™ืœ:

[email protected]

Page 59: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

59 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

ื‘ื™ื‘ืœื™ื•ื’ืจืคื™ื”

Ahmed, J., Habibi Gharakheili, H., Raza, Q., Russell, C., & Sivaraman, V. (2019). Real-Time Detection of DNS

Exfiltration and Tunneling from Enterprise Networks. IFIP/IEEE International Symposium on

Integrated Network Management (pp. 649-653). Washington D.C.: ResearchGate. Retrieved from

https://www.researchgate.net/publication/337228301_Real-

Time_Detection_of_DNS_Exfiltration_and_Tunneling_from_Enterprise_Networks

Amit Klein, I. K. (2016). The Perfect Exfiltration. SafeBreach. Retrieved from

https://go.safebreach.com/rs/535-IXZ-934/images/Whitepaper_Perfect_Exfiltration.pdf

Annarita Giani, V. H. (2006). Data exfiltration and covert channels. Sensors, and Command, Control,

Communications, and Intelligence (C3I) Technologies for Homeland Security and Homeland

Defense V. 6201. Kissimmee: SPIE.

Antwerp, R. C. (2011). Exfiltration Techniques: An Examination and Emulation. Thesis. Newark, Delaware,

USA: University of Delaware. Retrieved from

https://udspace.udel.edu/bitstream/handle/19716/10145/Ryan_VanAntwerp_thesis.pdf?sequen

ce=1&isAllowed=y

Areej Al-Bataineh, G. W. (2012). Analysis and detection of malicious data exfiltration in web traffic. 2012

7th International Conference on Malicious and Unwanted Software (pp. 26-31). Fajardo: IEEE.

doi:10.1109/malware.2012.6461004

Asaf Nadler, A. A. (2019, January). Detection of malicious and low throughput data exfiltration over the

DNS protocol. Computers & Security, 80, 36-53. doi:10.1016/j.cose.2018.09.006

Carrara, B. (2016). Air-Gap Covert Channels. Thesis. Ottawa, Canada: University of Ottawa. Retrieved from

https://ruor.uottawa.ca/bitstream/10393/35103/1/Carrara_Brent_2016_thesis.pdf

Chapter 5: Data Exfiltration Mechanisms. (2014). In R. E. Aditya K Sood, Targeted Cyber Attacks - Multi-

staged Attacks Driven by Exploits and Malware (pp. 77-93). Waltham: Elsevier.

Clark, D. D. (1982, July). RFC 815: IP DATAGRAM REASSEMBLY ALGORITHMS. Retrieved from IETF:

https://datatracker.ietf.org/doc/html/rfc815

Cloudflare. (2021). What is DNS? | How DNS works. Retrieved from Cloudflare:

https://www.cloudflare.com/en-gb/learning/dns/what-is-dns/

Faheem Ullah, M. E. (2018, January 1). Data exfiltration: A review of external attack vectors and

countermeasures. Journal of Network and Computer Applications, 101, 18-54.

doi:10.1016/j.jnca.2017.10.016

Gardiner, J., Cova, M., & Nagaraja, S. (2014). Command & Control: Understanding, Denying and Detecting.

Birmingham: University of Birmingham. Retrieved from

https://arxiv.org/ftp/arxiv/papers/1408/1408.1136.pdf

Guri, M. (2019, June). Optical air-gap exfiltration attack via invisible images. Journal of Information Security

and Applications, 46, 222-230. doi:https://doi.org/10.1016/j.jisa.2019.02.004

Page 60: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

61 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

IBM. (2010). Networking on z/OS - Internet Control Message Protocol (ICMP) and other layer 3 protocols.

Retrieved from z/OS Basic Skills: https://www.ibm.com/docs/en/zos-basic-skills?topic=nll-

internet-control-message-protocol-icmp-other-layer-protocols

Infoblox. (2020). Data Exfiltration and DNS. Retrieved from Infoblox - Next Level Networking:

https://www.infoblox.com/wp-content/uploads/infoblox-whitepaper-data-exfiltration-and-dns-

closing-the-back-door.pdf

Infoblox. (2020). Data Exfiltration through Service Provider DNS Infrastructure. Retrieved from Infoblox -

Next Level Networking: https://www.infoblox.com/wp-content/uploads/infoblox-whitepaper-

data-exfiltration-through-service-provider-dns-infrastructure.pdf

Iveson, S. (2019, November). IP Fragmentation in Detail. Retrieved from Packet Pushers:

https://packetpushers.net/ip-fragmentation-in-detail/

Jacob Steadman, S. S.-H. (2019). DNSxD: Detecting Data Exfiltration over DNS. Belfast: Queen's University.

Retrieved from

https://pureadmin.qub.ac.uk/ws/portalfiles/portal/161785678/1570493592_CameraReady.pdf

Kaspersky Lab. (2015). The Duqu 2.0. Retrieved from https://media.kasperskycontenthub.com/wp-

content/uploads/sites/43/2018/03/07205202/The_Mystery_of_Duqu_2_0_a_sophisticated_cybe

respionage_actor_returns.pdf

Kolegov, D. N. (2014). Covert timing channel over HTTP cache-control headers. Mathematical Foundations

of Computer Security, 89-91. Retrieved from http://mi.mathnet.ru/eng/pdma153

Lord, N. (2018, September 11). What is Data Exfiltration? DataInsider - Digital Guardian's Blog. Retrieved

from https://digitalguardian.com/blog/what-data-exfiltration

Mark. (2014, 12). Does encrypting a file make it larger? Retrieved from Stackoverflow:

https://security.stackexchange.com/a/76572

Matrosov, A., & Harley, D. (n.d.). Stuxnet Under the Microscope. ESET. Retrieved from

https://www.esetnod32.ru/company/viruslab/analytics/doc/Stuxnet_Under_the_Microscope.pdf

McAfee. (2017). Grand Theft Data - Data exfiltration study: Actors, tactics, and detection. McAfee.

Retrieved from https://www.mcafee.com/enterprise/en-us/assets/reports/rp-data-

exfiltration.pdf

McAfee. (2019). Grand Theft Data II: The Drivers and Shifting State of Data Breaches. McAfee. Retrieved

from https://www.mcafee.com/enterprise/en-us/assets/reports/restricted/rp-data-exfiltration-

2.pdf

Michael Dymshits, D. T. (2017). USA Patent No. US10915629B2. Retrieved from

https://patents.google.com/patent/US10915629B2/en

Nadler, A., Aminov, A., & Shabtai, A. (2019). Detection of Malicious and Low Throughput Data Exfiltration

Over the DNS Protocol. Computers & Security, 36-53. Retrieved from

https://www.sciencedirect.com/science/article/pii/S0167404818304000

Page 61: Data Exfiltration 101 - Basics & DNS Tunnelling

Data Exfiltration 101 - Basics & DNS Tunnelling www.DigitalWhisper.co.il

61 2021 ืื•ื’ื•ืกื˜ ,132ื’ืœื™ื•ืŸ

Naotake Ishikura, D. K. (2021, June). DNS Tunneling Detection by Cache-Property-Aware Features. IEEE

Transactions on Network and Service Management, 18, 1203-1217.

doi:10.1109/TNSM.2021.3078428

Polley, K. (2019, April 16). Detecting and Verifying ICMP Exfiltration with AI. Retrieved from PatternEx:

https://www.patternex.com/threatex/detecting-and-verifying-icmp-exfiltration-with-ai-enabled-

platform

Rowland, C. H. (1997). Covert Channels in the TCP/IP Protocol Suite. Retrieved from First Monday:

https://firstmonday.org/ojs/index.php/fm/article/view/528/449

Stamp, M., Alazab, M., & Shalaginov, A. (2021). Malware Analysis Using Artificial Intelligence and Deep

Learning. Springer.

Trend Micro. (2014, Septamber 9). ANDROMEDA. Retrieved from Threat Encyclopedia:

https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/andromeda

Trend Micro Threat Research Team. (2012). The Taidoor Campaign: An In-Depth Analysis. Cupertino: Trend

Micro. Retrieved from https://www.trendmicro.co.kr/cloud-content/us/pdfs/security-

intelligence/white-papers/wp_the_taidoor_campaign.pdf

Wikipedia. (n.d.). Covert channel. Retrieved from Wikipedia, the free encyclopedia:

https://en.wikipedia.org/wiki/Covert_channel

Wikipedia. (n.d.). Data exfiltration. Retrieved from Wikipedia, the free encyclopedia:

https://en.wikipedia.org/wiki/Data_exfiltration

Wyke, J. (2011). What is Zeus? Oxford: Sophos. Retrieved from https://www.sophos.com/fr-

fr/medialibrary/PDFs/technical-papers/Sophos-what-is-zeus-tp.pdf

Zanki, K. (2020, September). Taidoor - a truly persistent threat. Retrieved from Reversing Labs:

https://blog.reversinglabs.com/blog/taidoor-a-truly-persistent-threat