CTD-000114

AD-integrated DNS zone with WINS forward lookup enabled

Medium
Active Directory DNS
Credential Access
v13

Signature Identity

CTD-000114
Threat ID
13
Version
IOE
Indicator Type

Threat Description

The vulnerability related to WINS forwarding in AD-integrated DNS occurs when the DNS server performs a WINS forward lookup. This means that if the DNS server receives an address record query for which it does not have an answer, it sends a NBT-NS Query Request to a pre-configured WINS server. This process can be exploited by a threat actor who can forge DNS responses to compromise user accounts. This is because the DNS server trusts the responses it receives from the WINS server, even if they are not authentic. The threat actor can send malicious responses that trick the DNS server into providing incorrect information, potentially leading to security breaches or unauthorized access to sensitive information. As a result, it is important to properly secure the WINS server and the communication between the DNS server and WINS server to prevent this type of vulnerability.

MITRE ATT&CK: Attack Tactics

Credential Access

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To disable WINS forward lookup: 

  1. Log on to the DNS server using the Domain Admin or Enterprise Admin account.
  2. Press Windows Key + R.
  3. Run dnsmgmt.msc.
  4. On the opened DNS Manager snap-in from the left pane, expand the server name for the DNS server.
  5. Expand Forward Lookup Zones.
  6. From the expanded list, right-click each zone, and then click Properties.
  7. In the Properties dialog box for the zone, click the WINS tab.
  8. Uncheck the Use WINS forward lookup checkbox.
  9. Click on OK.

Frequently Asked Questions

What does AD-integrated DNS zone with WINS forward lookup enabled mean?

An Active Directory-integrated DNS zone with WINS forward lookup enabled allows the DNS server to send a NBT-NS Query Request to a pre-configured WINS server when it cannot resolve an address record query. This process can be exploited by attackers who can forge DNS responses, causing the DNS server to provide incorrect information for name resolution.

This setting allows attackers to bypass authentication or steal credentials, as the DNS server trusts the responses it receives from the WINS server. The risk is indirect but meaningful, placing this issue in the middle of the severity scale.

Attackers can exploit an Active Directory-integrated DNS zone with WINS forward lookup enabled by forging DNS responses that trick the DNS server into providing incorrect information for name resolution. This can lead to authentication bypass or account compromise, as the DNS server trusts the responses it receives from the WINS server.

Cayosoft Guardian detects Active Directory-integrated DNS zones with WINS forward lookup enabled by continuously monitoring the configuration of the DNS server and identifying when WINS forward lookup is enabled. This gives administrators clear visibility into a setting that can be easy to overlook.

Cayosoft Guardian helps reduce the risk by alerting administrators so they can disable WINS forward lookup in the DNS Manager snap-in. Guardian also supports ongoing monitoring to catch if the setting is re-enabled later, limiting reconnaissance opportunities for attackers and keeping unnecessary access points closed.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory DNS
Themes
Infrastructure
Attack Tactics
Credential Access
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical