skip to content

How does an internal DNS resolver carry commands for a host with no outbound path?

level: middleimportance: should knowfreq 44%

answer

  1. the host only talks to an internal address
  2. somebody else does the recursing
  3. the question itself is the payload
  4. the operator owns the authoritative side
  5. cache is the enemy of a repeat

basics

~20 s

The host never talks outside. It asks the internal resolver, which recurses on its behalf; the name asked for is attacker-chosen data, and the operator's own authoritative server answers it. Bytes cross both ways through a permitted intermediary.

solid answer

~50 s

When the proxy refuses a destination, name resolution is usually the one outward path left, because everything in the estate needs it. The implant builds a name whose labels encode its message, under a domain the operator's own name servers are authoritative for. The internal resolver does exactly its job: it walks the delegation from the root down and asks that authoritative server. The reply - a TXT, CNAME or address record - comes back through the resolver to the implant. The infected host's own socket only ever reaches an internal address; the packet that crosses the boundary is the resolver's. The costs are real: cached answers mean each message needs a unique name, a label holds at most 63 characters inside a name of about 253, and the operator must own a domain and run its name servers. It suits short commands, not volume.

go deeper

for a junior

Know that internal machines usually cannot reach the internet themselves and ask an internal resolver instead, and that the resolver is the thing that speaks to the outside world.

for a middle

Walk recursion end to end and show how an attacker-chosen name plus an operator-owned authoritative server turns ordinary resolution into a two-way carrier.

for a senior

Judge the ceiling and the costs: name-length limits, unique names to defeat caching, and the fact that the operator sees a resolver rather than a host.

for a principal

Weigh what constraining name resolution would cost the business against the residual you accept by leaving general recursion available to every machine in the estate.

### Why the resolver is the last door An estate can refuse every direct outbound connection and still cannot refuse name resolution, because nothing works without it. The usual shape is that internal hosts may speak only to the internal recursive resolver, and the resolver alone is permitted to talk to the outside world. That is a sound design, and it leaves exactly one permitted intermediary that will reach an arbitrary destination on request. ### The mechanics, end to end 1. The implant constructs a name such as `k2f9a1c0mq.cmd.op-domain.example`, where the leading labels are its message, encoded into characters legal in a name. 2. It asks the internal resolver to resolve that name. This is an ordinary local query to an internal address - the only kind of traffic the host is allowed to originate. 3. The resolver, having nothing cached, performs recursion: root, then the delegation for the top-level domain, then the name servers delegated for `op-domain.example`. Those name servers are the operator's. 4. The operator's server therefore receives the message, in the query name, and answers. A TXT record can carry a few hundred octets back (each string at most 255); a CNAME or address record carries less but is less unusual. 5. The answer returns through the resolver to the implant. Two-way channel, no outbound socket from the host. ### The design constraints that follow **Caching.** A recursive resolver answers from cache while a record's TTL lasts. If the implant asked the same name twice, the second query might never leave the estate. Every message therefore has to be a distinct name, and the operator serves very short TTLs. Uniqueness is not a stylistic choice; it is what makes the carrier function. **Size.** A label is at most 63 characters and the whole name about 253, and the encoding needed to make binary data legal inflates it. Each message is therefore small and costs a full recursive lookup. This is a carrier for a sleep instruction, a task identifier or a short result - reaching for it to move volume is slow and expensive, which is why operators treat it as the path taken when the web path is refused rather than the preferred one. **Addressing.** The operator's authoritative server sees the *resolver's* address as the source, not the host's. In a large estate that is one address standing in for thousands of machines. If the operator wants to know which host is calling, they have to build an identifier into the labels themselves. This is a genuine cost of the carrier and a detail that separates people who have thought about it from people who have only heard of it. ### The claim to get right A query arriving at the operator's name server proves that *some* client behind that resolver asked for the name, and nothing more. It does not identify the host, and it does not prove which process asked. Equally, from the estate's side, the fact that the host never sends a packet outward is exactly why blocking outbound port 53 for clients changes nothing: those clients were never talking outward in the first place. The resolver was. ### What removes it The technique depends on ordinary recursion being available for arbitrary names. The control class that bites is constraining resolution itself - forcing all resolution through one resolver and restricting which names may be resolved at all - and the reason that is rare is the same reason the carrier works: general recursion is what makes the internet usable, and taking it away is a business decision, not a configuration preference.

  • What does the operator's authoritative name server actually see as the source of these queries?
    The recursive resolver, not the implanted host. Unless the implant encodes an identifier into the labels, the operator learns only which resolver forwarded the query - and in a large estate that is one address standing in for thousands of machines. Addressing has to be built into the name, which is a real cost of choosing this carrier.
  • Why is this a poor carrier for anything but short commands?
    Bandwidth. A label holds at most 63 characters within a name of about 253, encoding binary data inflates it further, and every message costs a full recursive lookup with a fresh unique name to defeat caching. That is fine for a sleep instruction or a task identifier and painfully slow for anything larger, which is why it is the path taken when the web path is refused.
  • Why does blocking outbound port 53 for client machines not remove this carrier?
    Because the clients were never speaking outward. They query the internal resolver on an internal address, and the resolver performs the recursion under its own permission to reach the outside. The block removes a path nobody was using; the carrier runs through the intermediary the estate deliberately maintains.

A guest with no outside line asks the concierge to look something up. The call that leaves the building is the concierge's, and the request itself is the message.

saying these in an interview costs you the question

  • Thinks the infected host contacts the operator's name server directly
  • Assumes blocking outbound port 53 for clients removes the carrier
  • Believes the same name can be reused for every message
  • Treats name resolution as a high-bandwidth channel
  • Says the operator learns which host is calling from the query source

context