Covert Channels (Tunneling)

  • Carrying one protocol inside another protocol
    • Eg. Tunneling AppleTalk traffic over IP
  • Any communications protocol can be used to transmit another protocol
    • SSH protocol used to carry telnet, FTP, or X-Windows session
  • Covert tunnel applications
    • Hans, Loki
    • Reverse WWW Shell