Unsecure Dynamic DNS Zone Updates Allowed

high

Description

Configuring a dynamic DNS zone with unsecure updates can lead to unauthenticated editing of DNS records, making them vulnerable to rogue DNS records.

Solution

Misconfiguration of dynamic DNS zone updates can significantly impact the security of the Active Directory. Hence, it is crucial either to use dynamic updates in a secure manner, or not use them at all.

See Also

Active Directory Security Assessment Checklist - Misconfigured DNS zones

[MS-DNSP]: Domain Name Service (DNS) Server Management Protocol

Active Directory-Integrated DNS Zones

Dynamic update

Understanding Dynamic Update

Dynamic Update and Secure Dynamic Update

Beyond LLMNR/NBNS Spoofing - Exploiting Active Directory-Integrated DNS

ADIDNS Revisited - WPAD, GQBL, and More

Indicator Details

Name: Unsecure Dynamic DNS Zone Updates Allowed

Codename: C-DYNAMIC-UPDATES

Severity: High

MITRE ATT&CK Information:

Attacker Known Tools

Kevin Robertson: Powermad