When AD DNS zones are Active Directory-integrated (ADIDNS), the zone is stored in the directory, and by default Authenticated Users can create child objects (dnsNode) in it. So any domain account can add DNS records. That is a powerful poisoning primitive: unlike LLMNR/NBT-NS, which only answer failed lookups on the local segment, a record in ADIDNS answers for the whole domain, authoritatively, for as long as it exists.
The wildcard trick#
Adding a wildcard record (*) makes the domain DNS server resolve every otherwise-unknown name to your host, turning it into a domain-wide responder, like LLMNR poisoning but enterprise-scale and persistent:
# dnstool.py (from the krbrelayx repo): add a wildcard A record to your IP
dnstool.py -u 'EXAMPLE\user' -p 'password' --record '*' --action add --data <attacker-ip> <dc>
# Powermad (on Windows): add a record via secure dynamic update
Invoke-DNSUpdate -DNSType A -DNSName evil -DNSData <attacker-ip>
Then run Responder or ntlmrelayx to capture or relay the authentication that now flows to you.
Targeted records#
Where a wildcard is too noisy, add a single high-value name:
- WPAD: a
wpadrecord (or an NS record bypassing the Global Query Block List) makes every browser auto-discover your proxy, capturing HTTP auth broadly. The GQBL blocks a directwpadA record, so the NS-record bypass is used. - SCCM / WSUS / WDS names: impersonate update or deployment infrastructure to coerce authentication or push content.
- A specific host whose name you want to hijack for a relay chain.
Exploitation notes#
- The record is authoritative and domain-wide, so it reaches clients a link-local poisoner never would, and it persists until removed; clean it up afterwards.
- It needs only a single domain account, making it a strong early move to source authentications for relay (to LDAP for RBCD, or AD CS ESC8).
- DNS caching means effects are not instant and linger after removal; account for TTLs when timing a capture.
- Pair with
mitm6where IPv6 is available, or use ADIDNS where IPv6 is disabled, to source the same authentications.
Tools#
- dnstool.py (krbrelayx repo): add/modify/remove ADIDNS records from Linux.
- Powermad (
Invoke-DNSUpdate): add records from Windows via secure dynamic update. - Responder / ntlmrelayx: capture or relay the redirected authentication.