OOB DNS Exfiltration
Theory
Why Use OOB DNS?
Time-based SQLi
OOB DNS
MSSQL DNS Exfiltration Techniques
Function
Query
DNS Limitations
Character Restrictions
Solution: Encode and Split
Complete Payload
Tool 1: Interactsh
Web Interface
Payload Example
CLI Version
Tool 2: Burp Collaborator
Setup
Payload (Two Requests)
Tool 3: Custom DNS Server
Using Technitium DNS
Check Logs
Practical Example
Step 1: Test Payload
Step 2: Extract Password Hash
Step 3: Decode Result
URL Encoded Payload
Decoding Exfiltrated Data
CyberChef Recipe
OOB DNS Beyond SQLi
Quick Reference
MSSQL Functions
Function
Permissions Needed
Encoding Template
Splitting Template
Tools
Tool
Platform
Type
Stealth Tips
Last updated