How Domain Fronting Works
A 101 on domain fronting.
How domain fronting works. A 101 on domain fronting. Formally domain fronting is a technique leveraged by threat actors to use high reputation domains to disguise c2 callbacks from both the user and security tool sets. Usually domain fronting relies on content delivery networks cdn that host multiple domains.
We need to be looking into how our tools and techniques relate to trusted sources. Not only do they offer their own services using these but also the ones you can host on their servers amazon cloudfront for instance. How domain fronting works huge internet companies like google amazon and microsoft offer their web services using cdns content delivery networks.
In researching this tool we discovered that most firewalls and tls ssl interception. How domain fronting works domain fronting works at https layer and under these different requests for hostname will be different at different layers. Without domain fronting proxies can see the target host via sni and can choose to block the request to protect the user.
Domain fronting is a masquerading technique that is typically used to circumvent internet censorship by making traffic look like it s associated with a web domain that isn t restricted. Domain fronting works since it s faking the host in sni. That was until recently when i did some work with chris truncer who had us set it up as part of a red team test.
There are a large number of sites and domains your security tools ignore. How domain fronting works domain fronting works at https layer and under these different requests for hostname will be different at different layers. That was the point i.
In domain fronting hostname information will be same for dns request and sni whereas http host header which is hidden from censors from https encryption will carry another hostname. For example gcat is a tool that uses well formed email to communicate with implants. Domain fronting has been around for years and i ve always understood the concept but never actually looked at exactly how it works.