DNS tunnelling

DNS is allowed out of almost every network and inspected in almost none, which makes it a convenient way to smuggle data.

Requests and responses can carry small amounts of arbitrary information, so an attacker can trickle data out or maintain a channel back, through a protocol the firewall was never going to block. The volume is low and the traffic looks ordinary, which is exactly why it survives. Anything permitted everywhere and watched nowhere ends up used this way.

Checked against the primary source.

More on Networks