← Back to collection

Tunnelling

HTTP over DNS

A proof of concept that carries HTTP requests in DNS labels and reconstructs them at a server.

HTTPtunnelproof of concept

Screenshot used in the talk for HTTP over DNS
Screenshot used in the original talk.

HTTP is verbose, yet it can be encoded into a series of small DNS exchanges. The slide demonstrates the architecture and its limits.

This entry is intentionally descriptive. A future abuse section can add defensive indicators and response advice with the FIRST DNS Abuse SIG context.