DNS Administrators
DNS Administrators have the ability to load arbitrary DLL's using dns.exe. Since dns.exe runs as system, you can run commands through that dll as system.
You will need the privileges necessary to restart the DNS service to conduct this attack.
Attacking DNS Admins
Enumerate DNS Admins
From Linux
Exploitation
With the privileges of a DNS Admin, configure the DLL using dnscmd.exe (requires RSAT DNS).
Host a dll on a share and use it as a plugin
Then restart the DNS service and await what you expect from the DLL.
Last updated