Skip to content

Firewall and IDS Evasion

Between you and the target there are usually network controls: firewalls (filter by IP/port/protocol), IDS/IPS (detect/block attack patterns), and proxies. Evasion means getting your traffic to the target without being blocked or recognized: hiding the scan, fragmenting packets, using allowed ports and protocols, or encrypting/obfuscating content. You don’t break the control; you pass where it doesn’t look.

  • Network firewall: decides which IPs/ports/protocols pass. Evasion = use what’s allowed or look like it.
  • IDS/IPS (Snort, Suricata): detects attack signatures in traffic. Evasion = payload that doesn’t match the signature.
  • Application firewall (WAF): for HTTP (see WAF Bypass).
  • Egress filtering: limits outbound traffic (key for C2/reverse shells).
-T1/-T2 slow = below the detection threshold
-f / --mtu 16 fragment packets (split the signature)
-D RND:10 decoys: mix your IP with decoys
-S <fake ip> spoof origin (if you can receive or don't care about the reply)
--source-port 53 / 88 exit from a "trusted" port the FW lets through
--data-length 25 add random bytes
--scan-delay space out the packets
# map FW rules
nmap -sA target # ACK scan: distinguishes filtered from unfiltered port

Almost always 80/443 and 53 (DNS) are open outbound:

# reverse shell / C2 over 443 (blends with HTTPS)
# tunnel over allowed protocols
DNS tunneling (iodine/dnscat2) if outbound DNS passes (see net-dnsattacks)
HTTP/HTTPS tunneling C2 over 443, domain fronting
ICMP tunneling (ptunnel) if ICMP exits
# find what exits: test outbound ports
for p in 21 22 53 80 443 8080; do curl -s ...; done
# fragmentation and ambiguous reassembly (the IDS and host reassemble differently)
# payload obfuscation/encoding (so it doesn't match the signature — see web-wafbypass)
# encryption: a payload in TLS isn't inspectable without interception
# timing: space out to avoid "N events in T time" thresholds
# polymorphism: vary the payload each attempt

The principle is the same as with WAFs: the IDS recognizes patterns; change the pattern while keeping the semantics (see WAF Bypass for the HTTP case).

A reverse shell needs to get out. If egress is filtered:

# use the port that does exit (usually 443)
# tunnel over DNS/HTTP (see net-pivot, net-dnsattacks)
# domain fronting / CDN to disguise the destination
  • Default-deny on inbound and outbound (strict egress filtering): cuts C2/reverse shells.
  • Updated IDS/IPS with normalized reassembly (prevents fragmentation evasion); TLS inspection where feasible.
  • Rate-limiting and scan detection; SIEM correlation.
  • Segmentation and allowlist of outbound destinations; Protective DNS (cuts tunneling).
  • Assume an attacker will try 443/DNS: inspect those channels too.
  • Map firewall rules (ACK scan, which ports pass)
  • Evasive scanning (timing, fragmentation, decoys, source-port)
  • Identify allowed outbound ports (egress)
  • C2/reverse shell over 443 or another allowed port
  • Tunneling over DNS/HTTP/ICMP if filtering is strict
  • IDS evasion via fragmentation/obfuscation/encryption
  • Blue: egress default-deny, normalized IDS, Protective DNS?
  • Document which controls were evaded and how