Databouncing

53 posts

Databouncing banner
Databouncing

Databouncing

@databouncing

databouncing is the art of indirect exfiltration using hostname lookups as a transport medium - click the link, snoop around.

United Kingdom Sumali Nisan 2024
20 Sinusundan40 Mga Tagasunod
Naka-pin na Tweet
Databouncing
Databouncing@databouncing·
A little thread on the concern set of data-bouncing, The most important component here is that the exfil is second order, also known as indirect, this means you can’t control it within your network, while many refer to it as a DNS exfil, that’s only the second leg, 1/*
English
1
1
0
488
Databouncing
Databouncing@databouncing·
Hmmm Databouncing + Fastflux, hmmmm
English
0
0
3
80
Databouncing
Databouncing@databouncing·
@SwiftOnSecurity Ubi looks great but, looks locked in, synology has a good balance of flexibility and integration (just doesnt have that slick ubi UX)
English
0
0
0
36
SwiftOnSecurity
SwiftOnSecurity@SwiftOnSecurity·
What are you using for home NAS/SAN these days? Whats your setup?
English
250
13
476
175.7K
Databouncing
Databouncing@databouncing·
we feel that the only reason Databouncing hasn’t gotten the attention it deserves is because the PoCs have mostly been fun demonstrations of its capability - if you could share for reach 🙌❤️ 4/4
English
0
0
0
53
Databouncing
Databouncing@databouncing·
I’d be happy putting a reward out for whoever authors something stable first, you’d get support from myself @DeathsPirate and @N1ckDunn where we have time 3/4
English
1
1
2
273
Databouncing
Databouncing@databouncing·
A little bit of positive downtime, and we’re back at it We’re looking for some assistance in building databouncing integration into C2 frameworks (Sliver, Tuoni, Merlin, others ?) 1/4
English
1
1
2
325
Databouncing
Databouncing@databouncing·
While databouncing is pretty unstoppable in most cases it’s always nice if you’re gifted even more: PAN-234015 The X-Forwarded-For (XFF) value is not displayed in traffic logs.
English
0
0
1
95
🏴‍☠️ ÐΞΛТHS PłЯΛТΞ
@PamKeithFL Target the demographic you need with a quick form to gather their interest and give them something back in return (free coffee or something) for their time. Then you have a list of contacts for direct comms.
English
1
0
1
36
Pam Keith, Esq.
Pam Keith, Esq.@PamKeithFL·
One of the BIG data problems we have in campaigning is that while we have a list of registered voters, we DO NOT have a list of eligible not registered Americans. That means that we can’t target people for calls or texts or whatever to encourage them to register. If we fixed
English
4
18
64
1.9K
Dave Kennedy
Dave Kennedy@HackingDave·
I've been working on a secret project over the past few months. Not going to say anything more about it other than dropping this screenshot. #TrustedSec
Dave Kennedy tweet media
English
86
95
1.1K
84K
Databouncing
Databouncing@databouncing·
Seeing lots of databouncing candidates on Chinese infrastructure 🥸
English
0
0
1
89
Databouncing
Databouncing@databouncing·
Ayo #bugbounty hunters, you want to squeeze some money out of those lame host header poisonings ? Check out CWE-441 - then check out #databouncing - all you have to do is argue with triage until you are a millionaire 😁🫡
English
0
0
1
146
Databouncing
Databouncing@databouncing·
without actually putting any data on any services of those domains, this is industrialized exfiltration and no one seems to have an answer.
English
0
0
0
53
Databouncing
Databouncing@databouncing·
There are some very real implications to this technique and the reason we put time and money into building databouncing.io was to force the conversation not being had. - we'll start chipping away visually demonstrating how to move files via trusted domains...
English
1
0
0
59
Databouncing
Databouncing@databouncing·
@Microsoft asked us to refer to @Akamai when we demo'd Databouncing through their domains, Akamai's guy said essentially 'that's how the internet works', what's interesting is that when we spoke to NSA it was suggested that @Cloudflare had a response
English
1
0
0
94