Top 10 winner
A New Attack Surface on MS Exchange - ProxyLogon
A New Attack Surface on MS Exchange Part 1
Microsoft Exchange splits request handling between a frontend Client Access Service and a backend that trusts frontend-supplied headers, and a static-resource handler took its backend target straight from a client cookie. Chaining that pre-auth SSRF with a post-auth arbitrary file write gives unauthenticated remote code execution on Exchange through port 443, the chain named ProxyLogon.
Record
- Document
- A New Attack Surface on MS Exchange Part 1
- Researcher
- Orange Tsai
- Published by
- Orange Tsai
- Date
- Topic
- HTTP
In the archive
Related sources
- Part 2: ProxyOracle
- Part 3: ProxyShell
- Part 4: ProxyRelay (2022)
- ProxyLogon demonstration
- DEF CON 29 - Orange Tsai - ProxyLogon Just Tip of the Iceberg, New Attack Surface on Exchange Server
- ProxyLogon is Just the Tip of the Iceberg: A New Attack Surface on Microsoft Exchange Server!
Tags
This page is the archive's own catalogue record. The research is the work of Orange Tsai, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .