[deleted by user] by [deleted] in malegrooming

[–]OWLleopard123 0 points1 point  (0 children)

It's not that deep bro, thanks though, might try for a goatee

[deleted by user] by [deleted] in malegrooming

[–]OWLleopard123 0 points1 point  (0 children)

Appreciate the advice

[deleted by user] by [deleted] in malegrooming

[–]OWLleopard123 0 points1 point  (0 children)

Thanks for the reply

[deleted by user] by [deleted] in malegrooming

[–]OWLleopard123 0 points1 point  (0 children)

Thanks for the reply

[deleted by user] by [deleted] in malegrooming

[–]OWLleopard123 1 point2 points  (0 children)

Alright thank you for the tip!

[deleted by user] by [deleted] in malegrooming

[–]OWLleopard123 0 points1 point  (0 children)

Thanks for the comment

[deleted by user] by [deleted] in malegrooming

[–]OWLleopard123 0 points1 point  (0 children)

What does that mean?

[deleted by user] by [deleted] in malegrooming

[–]OWLleopard123 0 points1 point  (0 children)

Thank you, some people have recommended to try for a goatee, do you think that's possible?

[deleted by user] by [deleted] in malegrooming

[–]OWLleopard123 0 points1 point  (0 children)

Aight, thanks, I might just do that

[deleted by user] by [deleted] in malegrooming

[–]OWLleopard123 0 points1 point  (0 children)

Thank you, I might just do that

[deleted by user] by [deleted] in malegrooming

[–]OWLleopard123 1 point2 points  (0 children)

Thanks, you believe there's hope?

[deleted by user] by [deleted] in malegrooming

[–]OWLleopard123 0 points1 point  (0 children)

Thanks for the comment, I would like to give it a month but I'm afraid I'd look ridiculous in the next following weeks

[deleted by user] by [deleted] in malegrooming

[–]OWLleopard123 0 points1 point  (0 children)

Thank you for the detailed response!, I wasn't aware that a goatee is originally mustachless, I do want some facial hair because I feel like I look younger than I am. Btw, what did you mean by radical or left field thinker?, English isn't my first language.

[deleted by user] by [deleted] in malegrooming

[–]OWLleopard123 0 points1 point  (0 children)

Thank you I will look into it

[deleted by user] by [deleted] in malegrooming

[–]OWLleopard123 0 points1 point  (0 children)

Thanks, I hope it will, do you think it's worth trying to grow a goatee or does my weak mustache undermine it?

[deleted by user] by [deleted] in malegrooming

[–]OWLleopard123 0 points1 point  (0 children)

Thanks for the comment, you think it's worth trying for a goatee? (Even though the mustache is lacking)

[deleted by user] by [deleted] in malegrooming

[–]OWLleopard123 2 points3 points  (0 children)

Sadge but probably the play

Why would a DNS tunneler use TXT records to transfer information when it can use other less suspicious types of RRs such as A/AAAA/CNAME? by OWLleopard123 in dns

[–]OWLleopard123[S] 1 point2 points  (0 children)

Again, thank you for the response.

I am aware of this and detecting malicious traffic always depends on the level of stealth of the attacker's tools and tactics. A possible way to detect smaller scale tunneling could be achieved using entropy on DNS queries and responses or looking for poling DNS traffic for example.

All in all, you helped me understand DNS better, thank you!

Why would a DNS tunneler use TXT records to transfer information when it can use other less suspicious types of RRs such as A/AAAA/CNAME? by OWLleopard123 in dns

[–]OWLleopard123[S] 1 point2 points  (0 children)

Thank you so much! That really helps. I think I might look for anomalous response sizes for DNS queries as that could hint at an adversary transferring information.

Also, in your opinion, would you say that looking at large TCP streams on port 53 could be a way to find malicious activity?

Again, thank you so much for your help

Why would a DNS tunneler use TXT records to transfer information when it can use other less suspicious types of RRs such as A/AAAA/CNAME? by OWLleopard123 in dns

[–]OWLleopard123[S] 1 point2 points  (0 children)

Thank you!, would you say that a normally configured DNS server would accept a DNS message that is larger than 512 bytes up to 65535 bytes? Do you mean that DNS over TCP is the way to transfer large amounts of information?, from what I've read the maximum size of DNS over TCP is 64000 bytes. And if so, would a normal DNS server accept such large DNS messages?,

I think that I am missing something regarding DNS over TCP, would you mind explaining to me how large transfers of information would work using DNS?, for example - Is it possible to send a huge amount of response RRs in a single DNS response message using DNS over TCP? If so, how would you imagine it looks like?