Collected research
The OWASSRF + TabShell exploit chain
Setting X-OWA-ExplicitLogonUser to an address starting with owa/ makes Exchange strip that prefix when proxying, turning the request into authenticated SSRF onto backend endpoints such as /powershell. Inside the restricted PowerShell session, re-enabling TabExpansion and abusing Get-Command and Import-Module escapes the sandbox to run any cmdlet.
Record
- Researcher
- @rskvp93
- Published by
- Blog of Viettel Cyber Security
- Date
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of @rskvp93, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .