InfoSec Write-ups

A collection of write-ups from the best hackers in the world on topics ranging from bug bounties…

Follow publication

Member-only story

A Simple DNS OOB exfil solution, or pingb.in (life)hack

--

There are times when you want something more out of life, and I can’t help you with that, but then there are times when you want something more out of bug hunting like P1 bugs where RCE-s and SSRF-s tend to fall under. I can’t help you with finding those P1 bugs, but hopefully this article will help you exploit them when you are facing certain limitations.

DNS OOB exfil is an essential part of a serious bug hunter’s arsenal. But this type of outgoing connection bypass requires from you to set up a way to receive DNS queries to the server that you own where you can log the incoming traffic for later viewing (referring to the only downside of burp collaborator which can crap out at random times, or your computer may crash, ISP issues etc.). While there is a free domain provider, all the tutorials out there that I found sadly require you to use a paid one (as far as I had managed to find, and I looked hard, and even alternative solutions have caused me headaches), and you are already paying for your vps server, and whatever other “regular” bills you have, so what to do if you don’t want to pay for yet another thing? Well, I actually found this solution after restraining myself from breaking my keyboard over frustration that I couldn’t make free domain provider’s DNS configuration to work as per my understanding of the said tutorials where the paid DNS…

--

--

Published in InfoSec Write-ups

A collection of write-ups from the best hackers in the world on topics ranging from bug bounties and CTFs to vulnhub machines, hardware challenges and real life encounters. Subscribe to our weekly newsletter for the coolest infosec updates: https://weekly.infosecwriteups.com/

Written by Vuk Ivanovic

IT Security and bug bounty hunting, knowledge collector especially anything with word quantum, and sometimes writer of fiction.

No responses yet

Write a response