Investigating C&C and exfiltration attacks
C&C or command and control is when the attacker’s server communicates with the victim’s machine by either configuring malware installed on the victim’s machine to send reverse shell to the attacker C&C server or exploiting a service run by the victim, such as the SSH or Telnet services, to send instructions and commands to be executed on the victim’s machine. Exfiltration is when an attacker collects needed and valuable data and decides to transfer it to their server by using either the same C&C channel or another channel.
As we mentioned in the previous chapter, the firewall is positioned between the LAN (internal network) zone and the WAN (internet) zone. In the case of C&C or exfiltration attacks, the victim’s machine exists in the LAN zone and the attacker’s server exists in the WAN zone. See Figure 9.6:
Figure 9.6 – Firewall positions between...