Off The Record - Weaponizing DHCP DNS Dynamic Updates
...As every sysadmin knows - DNS is hard. It is a complex ecosystem with many moving pieces. One such “piece“ is a seemingly harmless feature in the DHCP protocol called “DHCP DNS Dynamic Update“, which allows a DHCP server to register DNS records on behalf of its clients. This feature is also present and enabled by default in the Microsoft DHCP server, one of the most common DHCP servers in the market.
In this session, we will explore this feature and show the attack surface it exposes in Microsoft environments - we will detail a novel attack tactic that could allow unauthenticated attackers to spoof arbitrary DNS records in Active Directory DNS zones, and show how this could be abused to intercept authentication and achieve remote code execution. We will examine the different security settings that should prevent these attacks, and show how they fail to do so in some cases....
By: Ori David
Full Abstract and Presentation Materials:
#off-the-record---weaponizing-dhcp-dns-dynamic-updates-35439
1 view
0
0
2 weeks ago 01:28:53 1
Soothing, relaxing music reduces stress and stops thinking too much
2 weeks ago 00:03:28 1
“The Challenge“ FULL Animation by Gwendy [ EPIC the Musical ]
2 weeks ago 00:01:54 2
[4K USA] Red Mesh Transparent Dresses Try on Haul with Blondy Bella
2 weeks ago 00:18:14 2
Семен Глузман про Зеленського, Порошенка, війну і Путіна
2 weeks ago 00:31:50 1
The Insane World of Mega Rich Pastors
2 weeks ago 00:32:17 2
The Dark World of Megachurches
2 weeks ago 00:05:41 1
Harri Agnel - Lovst (Original Mix) [Official Audio with lyrics]
3 weeks ago 00:01:55 24
World of Tanks Blitz Reforged Update: Join the First Ultra Test!
3 weeks ago 00:08:24 12
Primitive Technology: Cord drill and Pump drill
3 weeks ago 00:11:54 1
Taj Experience | Taj Holiday Village Resort & Spa | Goa | The Offbeat Couple
3 weeks ago 00:20:18 1
Scaring the @#$% out of Players with World’s First ACTUAL Airsoft FLAMETHROWER