Firewall and IDS Evasion
Between you and the target there are usually network controls: firewalls (filter by IP/port/protocol), IDS/IPS (detect/block attack patterns), and proxies. Evasion means getting your traffic to the target without being blocked or recognized: hiding the scan, fragmenting packets, using allowed ports and protocols, or encrypting/obfuscating content. You don’t break the control; you pass where it doesn’t look.
What each control filters
Section titled “What each control filters”- Network firewall: decides which IPs/ports/protocols pass. Evasion = use what’s allowed or look like it.
- IDS/IPS (Snort, Suricata): detects attack signatures in traffic. Evasion = payload that doesn’t match the signature.
- Application firewall (WAF): for HTTP (see WAF Bypass).
- Egress filtering: limits outbound traffic (key for C2/reverse shells).
Scan evasion (nmap)
Section titled “Scan evasion (nmap)”-T1/-T2 slow = below the detection threshold-f / --mtu 16 fragment packets (split the signature)-D RND:10 decoys: mix your IP with decoys-S <fake ip> spoof origin (if you can receive or don't care about the reply)--source-port 53 / 88 exit from a "trusted" port the FW lets through--data-length 25 add random bytes--scan-delay space out the packets# map FW rulesnmap -sA target # ACK scan: distinguishes filtered from unfiltered portPass through allowed ports/protocols
Section titled “Pass through allowed ports/protocols”Almost always 80/443 and 53 (DNS) are open outbound:
# reverse shell / C2 over 443 (blends with HTTPS)# tunnel over allowed protocolsDNS tunneling (iodine/dnscat2) if outbound DNS passes (see net-dnsattacks)HTTP/HTTPS tunneling C2 over 443, domain frontingICMP tunneling (ptunnel) if ICMP exits# find what exits: test outbound portsfor p in 21 22 53 80 443 8080; do curl -s ...; doneIDS/IPS evasion
Section titled “IDS/IPS evasion”# fragmentation and ambiguous reassembly (the IDS and host reassemble differently)# payload obfuscation/encoding (so it doesn't match the signature — see web-wafbypass)# encryption: a payload in TLS isn't inspectable without interception# timing: space out to avoid "N events in T time" thresholds# polymorphism: vary the payload each attemptThe principle is the same as with WAFs: the IDS recognizes patterns; change the pattern while keeping the semantics (see WAF Bypass for the HTTP case).
Egress filtering: the C2 challenge
Section titled “Egress filtering: the C2 challenge”A reverse shell needs to get out. If egress is filtered:
# use the port that does exit (usually 443)# tunnel over DNS/HTTP (see net-pivot, net-dnsattacks)# domain fronting / CDN to disguise the destinationFor the defense
Section titled “For the defense”- Default-deny on inbound and outbound (strict egress filtering): cuts C2/reverse shells.
- Updated IDS/IPS with normalized reassembly (prevents fragmentation evasion); TLS inspection where feasible.
- Rate-limiting and scan detection; SIEM correlation.
- Segmentation and allowlist of outbound destinations; Protective DNS (cuts tunneling).
- Assume an attacker will try 443/DNS: inspect those channels too.
Testing checklist
Section titled “Testing checklist”- Map firewall rules (ACK scan, which ports pass)
- Evasive scanning (timing, fragmentation, decoys, source-port)
- Identify allowed outbound ports (egress)
- C2/reverse shell over 443 or another allowed port
- Tunneling over DNS/HTTP/ICMP if filtering is strict
- IDS evasion via fragmentation/obfuscation/encryption
- Blue: egress default-deny, normalized IDS, Protective DNS?
- Document which controls were evaded and how