動作
專案資訊 #1089
已結束專案資訊 #1064: 2025-PenTest
Dangerous Permission over DNSAdmins Group
狀態:
Closed-關閉
優先權:
Normal
被分派者:
周益利
分類:
-
開始日期:
2025-08-01
完成日期:
2025-12-31
完成百分比:
100%
預估工時:
概述
bookmark20250527164529819756743971 "Dangerous Permission over DNSAdmins Group
" Granting excessive permissions to the DNSAdmins group allows attackers to load malicious DLLs on domain controllers via DNS server modifications. This enables privilege escalation to Domain Admin, as compromised members can execute code on DCs, facilitating persistent backdoor access and control over DNS resolution. "It is imperative that the permissions assigned to the DNSAdmins group for non-administrative domain objects be reviewed with the utmost care. These permissions must be granted only for the minimum necessity.
"
檔案
動作
