[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fM1WUdfoPOjPCSqqq6plF8vFarEvvsQ5aBtS15zJ_0YA":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":48,"createdAt":48,"_status":47},245,"How can regular domain users obtain DNS records without DNS admin privileges?","Regular domain users can obtain DNS records using two main approaches: first, by querying LDAP for computer names and then resolving their IP addresses via DNS queries (tools like [SharpAdidnsdump](https:\u002F\u002Fgithub.com\u002Fb4rtik\u002FSharpAdidnsdump) and [adidnsdump](https:\u002F\u002Fgithub.com\u002Fdirkjanm\u002Fadidnsdump) implement this); second, by directly extracting DNS records from LDAP and decoding the binary data (as done by [dns-dump](\u002Fnews\u002Fdomain-penetration-dns-records-and-machineaccount) and PowerView). These methods are covered in detail in the article [Domain Penetration - Obtaining DNS Records with Regular User Privileges](\u002Fnews\u002Fdomain-penetration-obtaining-dns-records-with-regular-user-privileges).","\u003Cp>Regular domain users can obtain DNS records using two main approaches: first, by querying LDAP for computer names and then resolving their IP addresses via DNS queries (tools like [SharpAdidnsdump](https:\u002F\u002Fgithub.com\u002Fb4rtik\u002FSharpAdidnsdump) and [adidnsdump](https:\u002F\u002Fgithub.com\u002Fdirkjanm\u002Fadidnsdump) implement this); second, by directly extracting DNS records from LDAP and decoding the binary data (as done by [dns-dump](\u002Fnews\u002Fdomain-penetration-dns-records-and-machineaccount) and PowerView). These methods are covered in detail in the article [Domain Penetration - Obtaining DNS Records with Regular User Privileges](\u002Fnews\u002Fdomain-penetration-obtaining-dns-records-with-regular-user-privileges).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-obtaining-dns-records-with-regular-user-privileges\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-regular-domain-users-obtain-dns-records-without-dns-admin-privileges-1777484557229","domain penetration, DNS records, regular user privileges, LDAP query, DNS query, SharpAdidnsdump, adidnsdump, dns-dump, PowerView",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":38,"qaPairs":39,"meta":44,"updatedAt":45,"createdAt":46,"_status":47},64,"Domain Penetration - Obtaining DNS Records with Regular User Privileges","domain-penetration-obtaining-dns-records-with-regular-user-privileges","Learn how regular domain users can obtain DNS records using LDAP and DNS queries, with tools like SharpAdidnsdump and dns-dump for penetration testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Domain Penetration - Obtaining DNS Records', methods for acquiring DNS records after gaining DNS administrator privileges in domain penetration were introduced. However, a more common scenario involves having only regular domain user privileges while still needing to obtain DNS records.\u003C\u002Fp>\u003Cp>This article will reference publicly available materials to summarize methods for regular domain users to obtain DNS records and fix bugs in dns-dump.ps1 on newer versions of Windows systems.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Implementation Principles\u003C\u002Fli>\u003Cli>Open-source Tools and Methods\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Implementation Principles\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Implementation Principles of SharpAdidnsdump\u003C\u002Fh3>\u003Cp>First, obtain the names of computers within the domain through LDAP queries, then retrieve their corresponding IP addresses via DNS queries.\u003C\u002Fp>\u003Cp>For detailed implementation, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fb4rtik\u002FSharpAdidnsdump\u003C\u002Fp>\u003Cp>Test environment: test.com\u003C\u002Fp>\u003Ch4>(1) Obtain the names of computers within the domain via LDAP query\u003C\u002Fh4>\u003Cp>The corresponding LDAP query parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>LDAP:\u002F\u002Ftest.com\u002FDC=test.com,CN=microsoftdns,DC=DomainDnsZones,DC=test,DC=com\u003Cbr>(&amp;(!(objectClass=DnsZone))(!(DC=@))(!(DC=*arpa))(!(DC=*DNSZones)))\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Obtain the IP addresses corresponding to domain computers via DNS query\u003C\u002Fh4>\u003Cp>Using the Dns.GetHostEntry method, reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fdotnet\u002Fapi\u002Fsystem.net.dns.gethostentry?redirectedfrom=MSDN&amp;view=netframework-3.5#System_Net_Dns_GetHostEntry_System_String_\u003C\u002Fp>\u003Ch3>2. Implementation principle of dns-dump\u003C\u002Fh3>\u003Cp>First, obtain DNS records via LDAP query, then decode the binary DNS records to retrieve the actual content\u003C\u002Fp>\u003Cp>For details on DNS record decoding, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fmmessano\u002FPowerShell\u002Fblob\u002Fmaster\u002Fdns-dump.ps1#L483\u003C\u002Fp>\u003Ch2>0x03 Open-source tools and methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test Environment:\u003C\u002Fp>\u003Cul>\u003Cli>test.com\u003C\u002Fli>\u003Cli>Server2012 R2\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>1. First obtain the names of computers within the domain via LDAP query, then obtain corresponding IPs via DNS query\u003C\u002Fh3>\u003Ch4>(1) SharpAdidnsdump\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgithub.com\u002Fb4rtik\u002FSharpAdidnsdump\u003C\u002Fp>\u003Cp>C# implementation for querying DNS records\u003C\u002Fp>\u003Cp>Usage:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SharpAdidnsdump test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The results obtained are complete and consistent with dnscmd results\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For dnscmd usage, refer to the previous article 'Domain Penetration - Obtaining DNS Records'\u003C\u002Fp>\u003Ch4>(2) adidnsdump\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgithub.com\u002Fdirkjanm\u002Fadidnsdump\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdirkjanm.io\u002Fgetting-in-the-zone-dumping-active-directory-dns-with-adidnsdump\u002F\u003C\u002Fp>\u003Cp>Python implementation for querying DNS records\u003C\u002Fp>\u003Cp>Suitable for Linux; cannot be used directly on Windows systems due to the need to install impacket\u003C\u002Fp>\u003Cp>Installation method:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>git clone https:\u002F\u002Fgithub.com\u002FSecureAuthCorp\u002Fimpacket.git\u003Cbr>cd impacket\u003Cbr>pip install .\u003Cbr>cd ..\u003Cbr>git clone https:\u002F\u002Fgithub.com\u002Fdirkjanm\u002Fadidnsdump\u003Cbr>cd adidnsdump\u003Cbr>pip install .\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>First, obtain credentials for a domain user (plaintext password or NTLM hash)\u003C\u002Fp>\u003Cp>Usage 1. Direct remote query:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>adidnsdump -u test\\\\testuser1 -p test123! dc.test.com -r\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Usage 2. Query via SOCKS proxy:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>proxychains adidnsdump -u test\\\\testuser1 -p test123! dc.test.com -r --dns-tcp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>You can also use NTLM hash as login credentials\u003C\u002Fp>\u003Ch3>2. First obtain DNS records via LDAP query, decode the binary DNS records to get the actual content\u003C\u002Fh3>\u003Ch4>(1) dns-dump\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgithub.com\u002Fmmessano\u002FPowerShell\u002Fblob\u002Fmaster\u002Fdns-dump.ps1\u003C\u002Fp>\u003Cp>Implemented in PowerShell, used to query DNS records\u003C\u002Fp>\u003Cp>This PowerShell script is relatively old and failed in my test environments Server 2008 R2 and Server 2012 R2\u003C\u002Fp>\u003Cp>After analysis, the LDAP query statement needs to be modified. The new script has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Usage:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Powershell -ep bypass -f dns-dump.ps1 -zone test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The results obtained are complete and consistent with those from dnscmd\u003C\u002Fp>\u003Ch4>(2) PowerView\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Cp>Can also be used to query DNS records\u003C\u002Fp>\u003Cp>The Convert-DNSRecord can be used to decode binary DNS records:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FRecon\u002FPowerView.ps1#L1814\u003C\u002Fp>\u003Cp>Usage is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module PowerView.ps1\u003Cbr>Get-DNSRecord -ZoneName test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Other Tools\u003C\u002Fh3>\u003Ch4>(1) AdFind\u003C\u002Fh4>\u003Cp>C++ implementation (not open source), used for querying domain information\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.joeware.net\u002Ffreetools\u002Ftools\u002Fadfind\u002Findex.htm\u003C\u002Fp>\u003Cp>Common commands are as follows:\u003C\u002Fp>\u003Cp>List domain controller names:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>AdFind -sc dclist\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Query online computers in the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>AdFind -sc computers_active\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The corresponding LDAP query conditions are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Transformed Filter: (&amp;(objectcategory=computer)(!(useraccountcontrol:1.2.840.113556.1.4.803:=2))(pwdlastset&gt;=131932198595370000)(|(!lastlogontimestamp=*)(&amp;(lastlogontimestamp=*)(lastlogontimestamp&gt;=131932198595370000))))\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Query online computers in the current domain (display only name and operating system):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>AdFind -sc computers_active name operatingSystem\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Query all computers in the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>AdFind -f \"objectcategory=computer\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Query all computers in the current domain (display only name and operating system):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>AdFind -f \"objectcategory=computer\" name operatingSystem\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Query all users in the domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>AdFind -users name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Query all GPOs:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>AdFind -sc gpodmp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>or\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>AdFind -gpo\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Query GPO corresponding to the previous article 'Domain Penetration - Remote Execution via Scheduled Tasks in GPO'\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces multiple methods for domain ordinary users to obtain DNS records, applicable to different environments. In practical use, AdFind's query efficiency is relatively low in certain situations.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",3,"published","2026-02-02T08:07:20.755Z",{"title":36,"description":14,"keywords":9,"ogImage":30,"canonicalUrl":30,"noIndex":37},"Domain Penetration: Get DNS Records with Regular User Privileges",false,[],{"docs":40,"hasNextPage":37},[41,42,43,4],248,247,246,{"title":30,"description":30,"image":30},"2026-07-24T02:07:27.411Z","2026-07-23T16:01:15.763Z","draft","2026-07-23T16:04:47.760Z"]