20.6 C
Canberra
Tuesday, January 6, 2026

Shield AD DNS on Public Wi-Fi


At Cisco Reside Melbourne 2025, the SOC noticed many fascinating behaviors from the varied purchasers of the convention community.  One of many extra fascinating ones was observations pertains to the DNS site visitors emitted by Home windows purchasers on the community, on the lookout for their group’s Lively Listing Area Controllers.  With our Endace full packet seize for the occasion, we had been in a position to seize DNS site visitors from purchasers on the community and carry out evaluation utilizing Splunk Enterprise.

As a reminder, when a Home windows consumer is searching for to speak to a website controller it can make DNS queries for SRV information for names like _kerberos._tcp.dc._msdcs.DOMAINNAME or _ldap._tcp.dc._msdcs.DOMAINNAME.  These DNS requests allow the consumer to search out close by Kerberos or LDAP servers for his or her area. 

Within the Cisco Reside Melbourne 2025 SOC, we noticed purchasers ship out DNS queries for about 3,800 distinct names beginning with “_ldap” or “_kerberos”.  Whereas most of them returned a failure of some kind (NXDOMAIN or SERVFAIL), roughly 300 had a profitable DNS response.  A few of these had been profitable in subsequent makes an attempt to hook up with the service (which means the area controllers are accessible in some trend from the general public web), and some had been adopted up by cleartext LDAP BINDs, leaking credential info throughout the native community and Web.  (SEE DANIEL’S BLOG POST)

Duane - redacted ldap and kerberos queriesDuane - redacted ldap and kerberos queries

There are a number of issues to think about from this.

First, there may be an open-source intelligence (OSINT) facet to this.  The operators of any wi-fi community that you just connect with along with your laptop computer acquire telemetry about your group.

Second, a malicious wi-fi community may – relying on how your purchasers are configured – trick the consumer into sharing authentication info with it.  Instruments similar to Responder are designed for this objective.  Correctly configured fashionable Home windows purchasers will use SMB signing, LDAP over TLS, LDAP channel binding, and different types of safety towards a hostile community setting.  Are you positive your purchasers are configured in a means that makes them sturdy towards a hostile community?

Third, in case your group has Lively Listing area controllers on the general public Web, are you taking the required steps to guard them?

Lastly, the Cisco Reside community is designed to be a protected community for attendees to make use of. However that’s no assure that – elsewhere – the identical SSID couldn’t be used to face up a hostile community.  Shoppers will normally auto-connect after they see a wi-fi community they’ve linked to earlier than.

One dependable mitigation for all of it is a VPN consumer. A correctly configured VPN consumer like Cisco Safe Shopper can assist each a full tunnel VPN and “Begin Earlier than Login”.  With this function, the consumer laptop connects to the VPN as early as doable.  All site visitors, together with DNS lookups, are despatched over the VPN.  Whereas this doesn’t eradicate all these dangers, it raises the protection bar considerably.

Try the opposite blogs by my colleagues within the Cisco Reside Melbourne 2026 SOC.


We’d love to listen to what you suppose! Ask a query and keep linked with Cisco Safety on social media.

Cisco Safety Social Media

LinkedIn
Fb
Instagram
X



Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

[td_block_social_counter facebook="tagdiv" twitter="tagdivofficial" youtube="tagdiv" style="style8 td-social-boxed td-social-font-icons" tdc_css="eyJhbGwiOnsibWFyZ2luLWJvdHRvbSI6IjM4IiwiZGlzcGxheSI6IiJ9LCJwb3J0cmFpdCI6eyJtYXJnaW4tYm90dG9tIjoiMzAiLCJkaXNwbGF5IjoiIn0sInBvcnRyYWl0X21heF93aWR0aCI6MTAxOCwicG9ydHJhaXRfbWluX3dpZHRoIjo3Njh9" custom_title="Stay Connected" block_template_id="td_block_template_8" f_header_font_family="712" f_header_font_transform="uppercase" f_header_font_weight="500" f_header_font_size="17" border_color="#dd3333"]
- Advertisement -spot_img

Latest Articles