Warda-DNSDocs

Data leaks through DNS

A program on a device can hide data in the names it asks — a DNS tunnel (iodine, dnscat2, dns2tcp, malware) — to send a file out or take its orders, through names such as 4a6f686e20446f65.x.example.com. Protection → Protections, card Data leaks through DNS (administrators; free, beta, on by default) finds them from the names alone, on the box: nothing is decrypted, nothing is sent out, and the names themselves are never kept (only a hash of each while they are counted) (internal/tunnel).

  • A name is encoded when the part under its domain (the last two labels, three under co.uk, gouv.fr and the like) is 100 characters or more, or when its longest label, of 20 characters or more and not an international name (xn--), looks random: high entropy with digits among the letters (hexadecimal, base32, base64) or hardly any vowel.
  • A device (its address: a device that changes address, IPv6 privacy addresses for example, starts again from zero; a router in front of several devices counts as one) that asks 40 different encoded names under the same domain within 10 minutes is leaking: that domain is then blocked for that address only, the domain itself and every name under it, for 24 hours (answer as for a blocked name; reason and origin tunnel, shown "Data leak through DNS"), and an alert of the kind exfiltration is recorded (one a day by device and domain, kept as the other notices, see Alerts), with a line in the log (the domain and the address, never the names).
  • A tunnel needs its author to run the name servers of its domain, so the domains that encode on purpose or that their customers cannot serve are left out: the blocklists of mail servers (Spamhaus, SORBS, SpamCop, Abusix…), the reputation lookups of antivirus software (Sophos, McAfee, ESET, Team Cymru…) and the shared platforms of the clouds and content networks (amazonaws.com, windows.net, googleusercontent.com, akamaiedge.net, cloudflare.net…; the list Known of internal/tunnel). The reverse names (.arpa) are never counted.
  • Allow this domain puts a domain in the list of the domains never taken for a leak (at most 200): its blocks are lifted at once, and nothing else changes for it (the lists and categories still apply, unlike a personal allow rule, which also wins over the detection). Remove watches it again. The unblock of a device from the query log does not lift a leak block: allow the domain.
  • At most 4096 device and domain pairs are followed at once, 256 by device, and 4096 blocks are in force at most.

GET /api/v1/exfiltration gives enabled, threshold, window_minutes, block_hours, allowed and the detections of the last 30 days; PUT /api/v1/exfiltration takes {"enabled": false} (off: the blocks in force are dropped; audit exfiltration.on / exfiltration.off) and/or {"allowed": ["example.com"]}, the whole list (a registrable domain each, 400 otherwise; audit exfiltration.allowed).