[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fSJj8avtdLRYiwvdBskC79phrHM_j1l6Ax-LZD7qAdSo":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":49,"createdAt":49,"_status":48},247,"How does dns-dump.ps1 work, and what fix was needed for newer Windows systems?","dns-dump.ps1 obtains DNS records by querying LDAP for DNS zones and decoding the binary DNS record data to extract actual content. The original script failed on Server 2008 R2 and Server 2012 R2 because its LDAP query statement needed modification. The article provides a patched version and links to the updated script. For the implementation details, see the [dns-dump section](\u002Fnews\u002Fdomain-penetration-obtaining-dns-records-with-regular-user-privileges#dns-dump) and the related [PowerView article](\u002Fnews\u002Fdomain-penetration-dns-records-and-machineaccount).","\u003Cp>dns-dump.ps1 obtains DNS records by querying LDAP for DNS zones and decoding the binary DNS record data to extract actual content. The original script failed on Server 2008 R2 and Server 2012 R2 because its LDAP query statement needed modification. The article provides a patched version and links to the updated script. For the implementation details, see the [dns-dump section](\u002Fnews\u002Fdomain-penetration-obtaining-dns-records-with-regular-user-privileges#dns-dump) and the related [PowerView article](\u002Fnews\u002Fdomain-penetration-dns-records-and-machineaccount).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-obtaining-dns-records-with-regular-user-privileges\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-dns-dumpps1-work-and-what-fix-was-needed-for-newer-windows-systems-1777484557332","dns-dump, PowerShell, LDAP query, binary DNS record decoding, bug fix, Server 2008 R2, Server 2012 R2",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":45,"updatedAt":46,"createdAt":47,"_status":48},64,"Domain Penetration - Obtaining DNS Records with Regular User Privileges","domain-penetration-obtaining-dns-records-with-regular-user-privileges","Learn how regular domain users can obtain DNS records using LDAP and DNS queries, with tools like SharpAdidnsdump and dns-dump for penetration testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Domain Penetration - Obtaining DNS Records', methods for acquiring DNS records after gaining DNS administrator privileges in domain penetration were introduced. However, a more common scenario involves having only regular domain user privileges while still needing to obtain DNS records.\u003C\u002Fp>\u003Cp>This article will reference publicly available materials to summarize methods for regular domain users to obtain DNS records and fix bugs in dns-dump.ps1 on newer versions of Windows systems.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Implementation Principles\u003C\u002Fli>\u003Cli>Open-source Tools and Methods\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Implementation Principles\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Implementation Principles of SharpAdidnsdump\u003C\u002Fh3>\u003Cp>First, obtain the names of computers within the domain through LDAP queries, then retrieve their corresponding IP addresses via DNS queries.\u003C\u002Fp>\u003Cp>For detailed implementation, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fb4rtik\u002FSharpAdidnsdump\u003C\u002Fp>\u003Cp>Test environment: test.com\u003C\u002Fp>\u003Ch4>(1) Obtain the names of computers within the domain via LDAP query\u003C\u002Fh4>\u003Cp>The corresponding LDAP query parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>LDAP:\u002F\u002Ftest.com\u002FDC=test.com,CN=microsoftdns,DC=DomainDnsZones,DC=test,DC=com\u003Cbr>(&amp;(!(objectClass=DnsZone))(!(DC=@))(!(DC=*arpa))(!(DC=*DNSZones)))\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Obtain the IP addresses corresponding to domain computers via DNS query\u003C\u002Fh4>\u003Cp>Using the Dns.GetHostEntry method, reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fdotnet\u002Fapi\u002Fsystem.net.dns.gethostentry?redirectedfrom=MSDN&amp;view=netframework-3.5#System_Net_Dns_GetHostEntry_System_String_\u003C\u002Fp>\u003Ch3>2. Implementation principle of dns-dump\u003C\u002Fh3>\u003Cp>First, obtain DNS records via LDAP query, then decode the binary DNS records to retrieve the actual content\u003C\u002Fp>\u003Cp>For details on DNS record decoding, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fmmessano\u002FPowerShell\u002Fblob\u002Fmaster\u002Fdns-dump.ps1#L483\u003C\u002Fp>\u003Ch2>0x03 Open-source tools and methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test Environment:\u003C\u002Fp>\u003Cul>\u003Cli>test.com\u003C\u002Fli>\u003Cli>Server2012 R2\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>1. First obtain the names of computers within the domain via LDAP query, then obtain corresponding IPs via DNS query\u003C\u002Fh3>\u003Ch4>(1) SharpAdidnsdump\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgithub.com\u002Fb4rtik\u002FSharpAdidnsdump\u003C\u002Fp>\u003Cp>C# implementation for querying DNS records\u003C\u002Fp>\u003Cp>Usage:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SharpAdidnsdump test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The results obtained are complete and consistent with dnscmd results\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For dnscmd usage, refer to the previous article 'Domain Penetration - Obtaining DNS Records'\u003C\u002Fp>\u003Ch4>(2) adidnsdump\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgithub.com\u002Fdirkjanm\u002Fadidnsdump\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdirkjanm.io\u002Fgetting-in-the-zone-dumping-active-directory-dns-with-adidnsdump\u002F\u003C\u002Fp>\u003Cp>Python implementation for querying DNS records\u003C\u002Fp>\u003Cp>Suitable for Linux; cannot be used directly on Windows systems due to the need to install impacket\u003C\u002Fp>\u003Cp>Installation method:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>git clone https:\u002F\u002Fgithub.com\u002FSecureAuthCorp\u002Fimpacket.git\u003Cbr>cd impacket\u003Cbr>pip install .\u003Cbr>cd ..\u003Cbr>git clone https:\u002F\u002Fgithub.com\u002Fdirkjanm\u002Fadidnsdump\u003Cbr>cd adidnsdump\u003Cbr>pip install .\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>First, obtain credentials for a domain user (plaintext password or NTLM hash)\u003C\u002Fp>\u003Cp>Usage 1. Direct remote query:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>adidnsdump -u test\\\\testuser1 -p test123! dc.test.com -r\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Usage 2. Query via SOCKS proxy:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>proxychains adidnsdump -u test\\\\testuser1 -p test123! dc.test.com -r --dns-tcp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>You can also use NTLM hash as login credentials\u003C\u002Fp>\u003Ch3>2. First obtain DNS records via LDAP query, decode the binary DNS records to get the actual content\u003C\u002Fh3>\u003Ch4>(1) dns-dump\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgithub.com\u002Fmmessano\u002FPowerShell\u002Fblob\u002Fmaster\u002Fdns-dump.ps1\u003C\u002Fp>\u003Cp>Implemented in PowerShell, used to query DNS records\u003C\u002Fp>\u003Cp>This PowerShell script is relatively old and failed in my test environments Server 2008 R2 and Server 2012 R2\u003C\u002Fp>\u003Cp>After analysis, the LDAP query statement needs to be modified. The new script has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Usage:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Powershell -ep bypass -f dns-dump.ps1 -zone test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The results obtained are complete and consistent with those from dnscmd\u003C\u002Fp>\u003Ch4>(2) PowerView\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Cp>Can also be used to query DNS records\u003C\u002Fp>\u003Cp>The Convert-DNSRecord can be used to decode binary DNS records:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FRecon\u002FPowerView.ps1#L1814\u003C\u002Fp>\u003Cp>Usage is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module PowerView.ps1\u003Cbr>Get-DNSRecord -ZoneName test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Other Tools\u003C\u002Fh3>\u003Ch4>(1) AdFind\u003C\u002Fh4>\u003Cp>C++ implementation (not open source), used for querying domain information\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.joeware.net\u002Ffreetools\u002Ftools\u002Fadfind\u002Findex.htm\u003C\u002Fp>\u003Cp>Common commands are as follows:\u003C\u002Fp>\u003Cp>List domain controller names:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>AdFind -sc dclist\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Query online computers in the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>AdFind -sc computers_active\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The corresponding LDAP query conditions are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Transformed Filter: (&amp;(objectcategory=computer)(!(useraccountcontrol:1.2.840.113556.1.4.803:=2))(pwdlastset&gt;=131932198595370000)(|(!lastlogontimestamp=*)(&amp;(lastlogontimestamp=*)(lastlogontimestamp&gt;=131932198595370000))))\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Query online computers in the current domain (display only name and operating system):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>AdFind -sc computers_active name operatingSystem\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Query all computers in the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>AdFind -f \"objectcategory=computer\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Query all computers in the current domain (display only name and operating system):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>AdFind -f \"objectcategory=computer\" name operatingSystem\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Query all users in the domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>AdFind -users name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Query all GPOs:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>AdFind -sc gpodmp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>or\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>AdFind -gpo\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Query GPO corresponding to the previous article 'Domain Penetration - Remote Execution via Scheduled Tasks in GPO'\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces multiple methods for domain ordinary users to obtain DNS records, applicable to different environments. In practical use, AdFind's query efficiency is relatively low in certain situations.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",3,"published","2026-02-02T08:07:20.755Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"Domain Penetration: Get DNS Records with Regular User Privileges","domain penetration, DNS records, regular user privileges, LDAP query, DNS query, SharpAdidnsdump, adidnsdump, dns-dump, PowerView",false,[],{"docs":41,"hasNextPage":38},[42,4,43,44],248,246,245,{"title":30,"description":30,"image":30},"2026-07-24T02:07:27.411Z","2026-07-23T16:01:15.763Z","draft","2026-07-23T16:04:48.276Z"]