Ansgar -59cobalt- Wiechers wrote:
Nothing new here. I'm quite aware of tunneling to dump files, any clown with netcat can do that quite easily. In fact i've used it myself. Very handy Your reply also ignores the fact that a properly set up system uses firewalls, policies and lockdowns, not just content filters.
As the admin, *I* will decide what DNS queries (and all other traffic) will leave the network, and also occur between network segments. Lets look at tour example of DNS, and what rules would be put in place.
- Only server's would be allowed to send DNS requests out.
- Only certain DNS server's would be allowed to query. Would these rules allow *your* wkstn's DNS queries out? No. Would they be blocked and logged? Yes Would the admin be asking you some questions about you intentionally violating AUP? Would you enjoy being fired? Goto 1, and repeat for most, if not all traffic. The obvious exception here is SSL tunnelling, but there are such things as SSL whitelists.
This assumes you got the tool to send the packet on the PC in the first place, which is another matter and another violation of AUP.
While everything you and others have stated is *possible*, you are looking at each technique in isolation of a total setup, and ignoring a properly layered approach. I'm yet to see a properly set up enterprise that allows the end user to initiate a direct connection with the outside world. With internal servers/units that allow/disallow certain traffic types, yes; letting Joe User have a direct SMTP, HTTP, DNS(or whatever) connection with anywhere external, NO.
In theory you could bring in tools, then clink away trying to find a weakness in the setup, but the chances of doing it undetected are very,very slim. If you would like to take the risk and think you can get away with it, please keep your cubicle tidy so your replacement doesn't trip over the junk you leave behind when you get terminated and escorted off the premises. Cheers, E.