Looking at several Windows boxes in a DMZ, and the firewall rules let them talk back to DC using the usual AD ports.
If a Windows host in a DMZ were compromised, couldn’t this lead to further compromise since these boxes interact with Active Directory?
Or am I just being too paranoid?
My initial thought was to have these boxes not be part of a domain of any sort and disallow any Microsoft protocols at all. My thought is that port 53 or (obviously port 80) might be attack vectors.