Web Hack List

Top 10 winner

A New Attack Surface on MS Exchange - ProxyLogon

A New Attack Surface on MS Exchange Part 1

Microsoft Exchange splits request handling between a frontend Client Access Service and a backend that trusts frontend-supplied headers, and a static-resource handler took its backend target straight from a client cookie. Chaining that pre-auth SSRF with a post-auth arbitrary file write gives unauthenticated remote code execution on Exchange through port 443, the chain named ProxyLogon.

Record

Document
A New Attack Surface on MS Exchange Part 1
Researcher
Orange Tsai
Published by
Orange Tsai
Date
Topic
HTTP

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Orange Tsai, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .