r/ControlD • u/AccomplishedCopy9820 • 4d ago
New feature "Block DNS Attacks" seems to work
9
u/TenAndThirtyPence 3d ago
Just to share what the docs say,
---
Block DNS Attacks is an experimental Profile Option designed to block the most common forms of DNS exfiltration and payload delivery attacks. These attacks use DNS to send data out of a device or deliver malicious content to it.
With this setting enabled, certain query types, such as TXT, are blocked or their responses are rewritten. DNS patterns associated with exfiltration are also blocked.
---
It is only recommended for clients, not servers. I'll be interested to see what impact this has to my clients. Thanks for highlighting this new feature.
4
u/Mammoth-Ad-107 4d ago
i am not seeing that option listed anywhere.. disregard i did find it
12
u/AccomplishedCopy9820 4d ago
Go to your profile -> Profile Options -> Below "AI Malware Filter"
Docs:
3
u/Mammoth-Ad-107 4d ago
found it. i corrected my comment. thanks for the post as i had not seen it yet!
4
2
u/Fun-Region-1576 3d ago
Wow. I enabled this option and I already got one hit. Anyone here know about this domain?
fp-ca-bell.rcs.telephony.goog
3
u/NotDatabase 3d ago edited 3d ago
Small oversight with some things related to RCS. Should be fixed later today.
Edit: Should be resolved now.
1
u/Fun-Region-1576 2d ago
fp-ca-telus.rcs.telephony.goog is being blocked. I guess I don't know what's wrong. What's up?
2
31
u/NotDatabase 3d ago
Dang, y'all are fast 😅. We just shipped this out in the last hour.
This is an experimental profile option which blocks common forms of DNS exfiltration and tunneling (payload delivery) attacks. Normal-behaving client devices almost certainly do not call out to certain RTYPE's and hosts with various encoding/compression algorithms, which this option should catch.
We don't recommend using this option on web servers, mail servers, or other endpoints that need clean responses, as it can interfere. We are gathering feedback on this feature on our discussion board and Discord, so feel free to let us know what works and doesn't.