Tweet Disematkan
Databouncing
53 posts

Databouncing
@databouncing
databouncing is the art of indirect exfiltration using hostname lookups as a transport medium - click the link, snoop around.
United Kingdom Bergabung Nisan 2024
20 Mengikuti40 Pengikut

LOLEXFIL
Living off the land Data Exfiltration method
lolexfil.github.io
English

Some good insight from @DidierStevens youtu.be/eh3BD7v8cZQ?si… could be useful to make life harder where it fails (as a benifit) in databouncing

YouTube
English

Approved 🫡
vs1m@Vsimpro
Been building on this idea databouncing.io/bouncing-with-… Using signup forms for databounce/data exfil Got the POC working: Playwright automation to register emails, triggers DNS lookups -> my listener catches + send the file to a Discord webhook. data-exfil using facebook reg :D!
English

If you want to databounce via email gist.github.com/yosignals/dce9…
This is crude but functional
It will use the hostname space as you’d expect, 500 recipients per send

English

@SwiftOnSecurity Ubi looks great but, looks locked in, synology has a good balance of flexibility and integration (just doesnt have that slick ubi UX)
English

I’d be happy putting a reward out for whoever authors something stable first, you’d get support from myself @DeathsPirate and @N1ckDunn where we have time 3/4
English

checkcybersecurity.service.ncsc.gov.uk/ip-check/form great for businesses, and databouncing aficionados ?
GIF
English

@DeathsPirate @PamKeithFL Narrowcasting is the term, and it’s made things very ugly 🫠
English

@PamKeithFL Target the demographic you need with a quick form to gather their interest and give them something back in return (free coffee or something) for their time. Then you have a list of contacts for direct comms.
English

I've been working on a secret project over the past few months.
Not going to say anything more about it other than dropping this screenshot.
#TrustedSec

English
Databouncing me-retweet

I'll be speaking at Defcon Gloucester this evening on all things @databouncing. Hopefully see some of you later!
English

Ayo #bugbounty hunters, you want to squeeze some money out of those lame host header poisonings ? Check out CWE-441 - then check out #databouncing - all you have to do is argue with triage until you are a millionaire 😁🫡
English

There are some very real implications to this technique and the reason we put time and money into building databouncing.io was to force the conversation not being had. - we'll start chipping away visually demonstrating how to move files via trusted domains...
English

@Microsoft asked us to refer to @Akamai when we demo'd Databouncing through their domains, Akamai's guy said essentially 'that's how the internet works', what's interesting is that when we spoke to NSA it was suggested that @Cloudflare had a response
English



