-
Notifications
You must be signed in to change notification settings - Fork 566
[New Rule] Potential DNS Server Privilege Escalation via ServerLevelPluginDll #3717
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
rules/windows/privilege_escalation_dns_serverlevelplugindll.toml
Outdated
Show resolved
Hide resolved
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Two questions but looks good to me! Approving as I know you will consider the questions anyways.
rules/windows/privilege_escalation_dns_serverlevelplugindll.toml
Outdated
Show resolved
Hide resolved
rules/windows/privilege_escalation_dns_serverlevelplugindll.toml
Outdated
Show resolved
Hide resolved
rules/windows/privilege_escalation_dns_serverlevelplugindll.toml
Outdated
Show resolved
Hide resolved
rules/windows/privilege_escalation_dns_serverlevelplugindll.toml
Outdated
Show resolved
Hide resolved
rules/windows/privilege_escalation_dns_serverlevelplugindll.toml
Outdated
Show resolved
Hide resolved
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Added a question about expanding scope a bit. Otherwise, looks good!
…luginDll (#3717) * [New Rule] Potential DNS Server Privilege Escalation via ServerLevelPluginDll * Update privilege_escalation_dns_serverlevelplugindll.toml * Update privilege_escalation_dns_serverlevelplugindll.toml * Update rules/windows/privilege_escalation_dns_serverlevelplugindll.toml --------- Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> (cherry picked from commit 4eff7c6)
…luginDll (#3717) * [New Rule] Potential DNS Server Privilege Escalation via ServerLevelPluginDll * Update privilege_escalation_dns_serverlevelplugindll.toml * Update privilege_escalation_dns_serverlevelplugindll.toml * Update rules/windows/privilege_escalation_dns_serverlevelplugindll.toml --------- Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> (cherry picked from commit 4eff7c6)
…luginDll (#3717) * [New Rule] Potential DNS Server Privilege Escalation via ServerLevelPluginDll * Update privilege_escalation_dns_serverlevelplugindll.toml * Update privilege_escalation_dns_serverlevelplugindll.toml * Update rules/windows/privilege_escalation_dns_serverlevelplugindll.toml --------- Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> (cherry picked from commit 4eff7c6)
…luginDll (#3717) * [New Rule] Potential DNS Server Privilege Escalation via ServerLevelPluginDll * Update privilege_escalation_dns_serverlevelplugindll.toml * Update privilege_escalation_dns_serverlevelplugindll.toml * Update rules/windows/privilege_escalation_dns_serverlevelplugindll.toml --------- Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> (cherry picked from commit 4eff7c6)
…luginDll (#3717) * [New Rule] Potential DNS Server Privilege Escalation via ServerLevelPluginDll * Update privilege_escalation_dns_serverlevelplugindll.toml * Update privilege_escalation_dns_serverlevelplugindll.toml * Update rules/windows/privilege_escalation_dns_serverlevelplugindll.toml --------- Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> (cherry picked from commit 4eff7c6)
…luginDll (#3717) * [New Rule] Potential DNS Server Privilege Escalation via ServerLevelPluginDll * Update privilege_escalation_dns_serverlevelplugindll.toml * Update privilege_escalation_dns_serverlevelplugindll.toml * Update rules/windows/privilege_escalation_dns_serverlevelplugindll.toml --------- Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> (cherry picked from commit 4eff7c6)
Issues
Part of #3005
Summary
Identifies unusual DLLs loaded by the DNS Server process, potentially indicating the abuse of the ServerLevelPluginDll functionality. This can lead to privilege escalation and remote code execution with SYSTEM privileges.
Data
Data
Local DLL
Remote DLL