Injecting Rogue DNS Records Using DHCP
ID: d207754d-13e7-51ef-b79a-528f9a8bf037
STIX ID: report--d207754d-13e7-51ef-b79a-528f9a8bf037
Feed Name: TrustedSec blog
**Executive Summary:** This report demonstrates a proof-of-concept attack in which an adversary deploys a rogue Linux networking device on a target LAN and uses spoofed DHCP transactions to inject dynamic DNS records (including WPAD or wildcard names) into Windows and some third-party DHCP/DNS setups; the attacker then claims the assigned IP on a virtual interface so the network routes traffic to their device, enabling credential capture or NTLM relay attacks. The write-up includes a step-by-step PoC using dhtest, observations about DHCP/DNS behaviors, and recommends mitigations such as switch port security, reserving key DNS names, and applying Microsoft’s DNS Server Global Query Blocklist.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
