A program on a device can hide data in the names it asks — a DNS tunnel
(iodine, dnscat2, dns2tcp, malware) — to send a file out or take its
orders, through names such as 4a6f686e20446f65.x.example.com.
Protection → Protections, card Data leaks through DNS
(administrators; free, beta, on by default) finds them from the names
alone, on the box: nothing is decrypted, nothing is sent out, and the
names themselves are never kept (only a hash of each while they are
counted) (internal/tunnel).
- A name is encoded when the part under its domain (the last two labels,
three under
co.uk,gouv.frand the like) is 100 characters or more, or when its longest label, of 20 characters or more and not an international name (xn--), looks random: high entropy with digits among the letters (hexadecimal, base32, base64) or hardly any vowel. - A device (its address: a device that changes address, IPv6 privacy
addresses for example, starts again from zero; a router in front of
several devices counts as one) that asks 40 different encoded names
under the same domain within 10 minutes is leaking: that domain is
then blocked for that address only, the domain itself and every name
under it, for 24 hours (answer as for a blocked name; reason and
origin
tunnel, shown "Data leak through DNS"), and an alert of the kindexfiltrationis recorded (one a day by device and domain, kept as the other notices, see Alerts), with a line in the log (the domain and the address, never the names). - A tunnel needs its author to run the name servers of its domain, so the
domains that encode on purpose or that their customers cannot serve are
left out: the blocklists of mail servers (Spamhaus, SORBS, SpamCop,
Abusix…), the reputation lookups of antivirus software (Sophos, McAfee,
ESET, Team Cymru…) and the shared platforms of the clouds and content
networks (
amazonaws.com,windows.net,googleusercontent.com,akamaiedge.net,cloudflare.net…; the listKnownofinternal/tunnel). The reverse names (.arpa) are never counted. - Allow this domain puts a domain in the list of the domains never taken for a leak (at most 200): its blocks are lifted at once, and nothing else changes for it (the lists and categories still apply, unlike a personal allow rule, which also wins over the detection). Remove watches it again. The unblock of a device from the query log does not lift a leak block: allow the domain.
- At most 4096 device and domain pairs are followed at once, 256 by device, and 4096 blocks are in force at most.
GET /api/v1/exfiltration gives enabled, threshold, window_minutes,
block_hours, allowed and the detections of the last 30 days;
PUT /api/v1/exfiltration takes {"enabled": false} (off: the blocks in
force are dropped; audit exfiltration.on / exfiltration.off) and/or
{"allowed": ["example.com"]}, the whole list (a registrable domain each,
400 otherwise; audit exfiltration.allowed).