DNS Admins
General
Members of the DNS Admins group can load arbitrary DLL's with the privileges of dns.exe (SYSTEM)
If the DC serves as DNS server, we can escalate to DA
But: need to be able to restart the DNS on the DC
Exploitation
Can use mimilib.dll from mimikatz
Modify kdns.c or use boiler plate from here
mimilib.dll logs all DNS queries to C:\Windows\System32\kiwidns.log by default
Host DLL on SMB server with anonymous access
Be careful, else DNS might fail -> noisy!
Last updated