Tweet ghim
Databouncing
53 posts

Databouncing
@databouncing
databouncing is the art of indirect exfiltration using hostname lookups as a transport medium - click the link, snoop around.
United Kingdom Tham gia Nisan 2024
20 Đang theo dõi40 Người theo dõi

LOLEXFIL
Living off the land Data Exfiltration method
lolexfil.github.io
English

Some good insight from @DidierStevens youtu.be/eh3BD7v8cZQ?si… could be useful to make life harder where it fails (as a benifit) in databouncing

YouTube
English

Approved 🫡
vs1m@Vsimpro
Been building on this idea databouncing.io/bouncing-with-… Using signup forms for databounce/data exfil Got the POC working: Playwright automation to register emails, triggers DNS lookups -> my listener catches + send the file to a Discord webhook. data-exfil using facebook reg :D!
English

If you want to databounce via email gist.github.com/yosignals/dce9…
This is crude but functional
It will use the hostname space as you’d expect, 500 recipients per send

English

@SwiftOnSecurity Ubi looks great but, looks locked in, synology has a good balance of flexibility and integration (just doesnt have that slick ubi UX)
English

I’d be happy putting a reward out for whoever authors something stable first, you’d get support from myself @DeathsPirate and @N1ckDunn where we have time 3/4
English

checkcybersecurity.service.ncsc.gov.uk/ip-check/form great for businesses, and databouncing aficionados ?
GIF
English

@DeathsPirate @PamKeithFL Narrowcasting is the term, and it’s made things very ugly 🫠
English

@PamKeithFL Target the demographic you need with a quick form to gather their interest and give them something back in return (free coffee or something) for their time. Then you have a list of contacts for direct comms.
English

I've been working on a secret project over the past few months.
Not going to say anything more about it other than dropping this screenshot.
#TrustedSec

English
Databouncing đã retweet

I'll be speaking at Defcon Gloucester this evening on all things @databouncing. Hopefully see some of you later!
English

Ayo #bugbounty hunters, you want to squeeze some money out of those lame host header poisonings ? Check out CWE-441 - then check out #databouncing - all you have to do is argue with triage until you are a millionaire 😁🫡
English

There are some very real implications to this technique and the reason we put time and money into building databouncing.io was to force the conversation not being had. - we'll start chipping away visually demonstrating how to move files via trusted domains...
English

@Microsoft asked us to refer to @Akamai when we demo'd Databouncing through their domains, Akamai's guy said essentially 'that's how the internet works', what's interesting is that when we spoke to NSA it was suggested that @Cloudflare had a response
English



