
Join us for an evening of fun at this month’s hack::soho taking place 24 September, 6pm – 9pm, set up to be a loose networking environment where cyber security professionals can chat, get some complimentary food & drink, and discuss rising global trends.
This month’s hack::soho features a talk from Nick Dunn, IOActive Senior Security Consultant. The abstract of the talk, ‘A Stealth and Safety Issue – Exfiltration using ‘data bouncing,’ is below!
hack::soho is a monthly event hosted at our London, UK office for the cybersecurity and hacking community to discuss all things security over food and refreshments. We welcome you to invite others in your circle to extend our collective network.
Spots are limited, so please use real contact details to confirm your registration. We will not sell, distribute, or use your contact information outside of sending you details about upcoming hack::soho meetups.
We hope you can join us!
Not able to make it to this hack::soho in person? No worries, we will livestream the presentation portion kicking off around 7pm on 24 September. Join the livestream and bookmark the page here.
ABSTRACT
The concept of “data bouncing” via a third-party web server provides an extremely stealthy method of bypassing traditional network safeguards. By directing web requests to certain domains that process hostnames in headers, you can relay small pieces of data to your DNS listener, allowing you to collect and reconstruct data, be it strings, files, or any other type of data.
The recent discovery of this technique has received minimal publicity, which seems to be partly attributable to the unfamiliar use of familiar services, and partly to a lack of easy to use tooling. This talk aims to rectify both of these by providing a clear explanation of the concept and presenting a new tool to allow the exfiltration to be carried out easily.
