---
title: "About Data Exfiltration"
canonical: "https://docs.infoblox.com/space/nios85/35384925/About%20Data%20Exfiltration"
format: markdown
---
The DNS protocol is increasingly used as a pathway for data exfiltration through DNS tunneling attacks. DNS tunneling involves tunneling another protocol through port 53 — often not inspected by firewalls (even the next-generation firewalls) — by malware-infected devices or malicious insiders. There are a number of tools available for tunneling over DNS for a common motivation of bypassing captive portals for paid Wi-Fi access. A free tunneling application released under the ISC license for forwarding IPv4 traffic through DNS servers is one example of the software used in this kind of attack.

As illustrated in *<span style="color: #0000ff">[Figure](#AboutDataExfiltration-bookmark3346)</span>*[ ](#AboutDataExfiltration-bookmark3346)*<span style="color: #0000ff">[43.1](#AboutDataExfiltration-bookmark3346)</span>*, sensitive information such as credit card numbers and company financial can be stolen either by establishing a DNS tunnel from within the network or by encrypting and embedding chunks of that data in DNS queries. Data is decrypted at the other end and put back together so valuable information can be stolen and misused by malicious attackers.   
> Macro (anchor)

*Figure **43.1 **Data** Exfiltration*

> Macro (drawio)

  
You can use the following features to specifically target DNS tunneling traffic and minimize the risk of DNS data exfiltration:

> Macro (legacy-content)