DNS exfiltration is not blocked #125
Labels
bug
Something isn't working
enhancement
New feature or request
MVP
Things that need to be considered for the MVP release
Describe the bug
Data can be exfiltrated by DNS tunneling.
There's a full discussion on the MS repo, issue 4036. The resolution is to attach a private DNS resolver to the firewall, and have all spokes route their DNS through that (they probably already do?). The firewall DNS resolver then white/black-lists hosts that are allowed.
Note that the firewall is still necessary to prevent traffic flow, this only addresses name lookup and exfiltration via the DNS protocol.
Steps to reproduce
Attacker-side:
On the Workspace VM (only tested Linux at the moment)
The text was updated successfully, but these errors were encountered: