Web Hack List

Collected research

The OWASSRF + TabShell exploit chain

Setting X-OWA-ExplicitLogonUser to an address starting with owa/ makes Exchange strip that prefix when proxying, turning the request into authenticated SSRF onto backend endpoints such as /powershell. Inside the restricted PowerShell session, re-enabling TabExpansion and abusing Get-Command and Import-Module escapes the sandbox to run any cmdlet.

Record

Researcher
@rskvp93
Published by
Blog of Viettel Cyber Security
Date
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of @rskvp93, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .