File transfer via DNS
aldeid.com
aldeid.com
Useful for hotspots that allow DNS but nothing else
If you're interested in IP-over-DNS, you may also be interested in IP-over-Facebook: https://news.ycombinator.com/item?id=7256477
A lot of ping traffic through, shows up like most of these ideas in any shop with regular network monitoring.
If anyone is interested in having more fun with this kind of stuff, take a look at Tor's pluggable transports[1], for example. A taste specimen of 'covert channels':
* various 'have everything appear to be random TCP with no other marks' transports (+/- padded packet lengths, time intervals, etc.)
* skype-look-alike transport
* various-stuff-over-http-look-alike (html, etc) transport
* a transport that imitates git's push/pull
* a transport that, given enough 'permitted'/non-censored data, learns to imitate arbitrary protocols (learns and encodes them as regular expressions; some interesting and crazy CA madness)
* etc.
[1]: https://www.torproject.org/docs/pluggable-transports.html.en and https://trac.torproject.org/projects/tor/wiki/doc/PluggableT...
While a high number of requests for uncommon domains might trigger a lot of suspicion, you can cart out smaller amounts of data over DNS in ways that are really hard to detect. I've seen situations where data was being sent over DNS requests where the attacker merely held the ability to view the outgoing DNS traffic, but didn't really control (or want to risk modification) of traffic.
Not airtight, but ... something like that?
It's unbearably slow (especially when you use SSL over it, which I'd consider almost mandatory if you do this) for anything other than email and maybe running a few shell commands, however. Applying additional obfuscation/whitening to the data stream to make it harder to detect makes it even slower.