Databouncing (@databouncing) 's Twitter Profile
Databouncing

@databouncing

databouncing is the art of indirect exfiltration using hostname lookups as a transport medium - click the link, snoop around.

ID: 1776034477556301824

linkhttps://databouncing.io calendar_today04-04-2024 23:50:01

50 Tweet

29 Takipçi

17 Takip Edilen

🏴‍☠️ ÐΞΛТHS PłЯΛТΞ (@deathspirate) 's Twitter Profile Photo

Great day at SnoopCon. Honoured to have been accepted to talk about all things #DataBouncing and to showcase some of the behind the scenes work that some are up to. I am Jakoby @N1ckDunn and the guys at tuoni.io

Databouncing (@databouncing) 's Twitter Profile Photo

Databouncing will go under the radar of traditional #CTI as we know it, I’d be interested in hearing strategies to try and bring covert comms back into the fold

Databouncing (@databouncing) 's Twitter Profile Photo

Ayo #bugbounty hunters, you want to squeeze some money out of those lame host header poisonings ? Check out CWE-441 - then check out #databouncing - all you have to do is argue with triage until you are a millionaire 😁🫡

Databouncing (@databouncing) 's Twitter Profile Photo

While databouncing is pretty unstoppable in most cases it’s always nice if you’re gifted even more: PAN-234015 The X-Forwarded-For (XFF) value is not displayed in traffic logs.

Databouncing (@databouncing) 's Twitter Profile Photo

If you want to databounce via email gist.github.com/yosignals/dce9… This is crude but functional It will use the hostname space as you’d expect, 500 recipients per send

If you want to databounce via email gist.github.com/yosignals/dce9… 

This is crude but functional 

It will use the hostname space as you’d expect, 500 recipients per send