Wikipedia over DNS
dgl.cx
dgl.cx
For example, you could encode harvested data (eg: keystrokes) as a DNS query for h28sdhnz890j1hadsl.sj12h89shbapqp8n15kl258.example.com. The TXT record you get back would be the server's response signed with the C&C server's private key. This is so that you can use multiple domains and rotate them in case one gets seized and the signed response prevents spoofing.
Such a system would be quite passive and likely to fly under the radar on most systems.
Here's a very quick presentation on DNS channels and DNS tunnels from a few years back:
http://www.loria.fr/~lnussbau/files/tuns-sec09-slides.pdf
A key question with controlling any of these sorts of channels is not necessarily blocking them, but limiting the bandwidth of the channels.
Interesting presentation, thanks for the link!
To implement your own custom DNS server, use Net::DNS::Nameserver; # (and see ozymandns for implementation example)
It doesn't support splitting, I just wrote it quickly as a proof of concept.
For real use there is the earlier mentioned by jedsmith Iodine.
The code is pretty much a hack which I haven't got around to tidying up (but mail me if you really want it).
It's really just glue anyway -- the interesting bits are done by:
* http://search.cpan.org/perldoc?Parse::MediaWikiDump
* http://search.cpan.org/perldoc?Text::Summary::MediaWiki
The script then saves the produced summaries in SQLite, then some code based on Stanford::DNSserver (http://www.stanford.edu/~riepel/lbnamed/Stanford-DNSserver/) does a lookup in SQLite, follows #redirects and returns a TXT record.
These days I'd probably use PowerDNS's pipe backend to implement it rather than a full DNS server in Perl (there's helper modules like ruby-pdns that make writing a DNS server with specialised purposes incredibly easy).
For example there's IXFR which is helpful when doing dynamic updates.
Alternatively don't use DNS for transfers -- there's nothing forcing its use, except for talking to clients -- SQL replication works (e.g. with PowerDNS), or the approach most spam blocklists take and rsync zones around for serving by a special server (rbldnsd); DNS just becomes a common query protocol because every client supports it.