Web Hack List

Top 10 winner

Attacking MS Exchange Web Interfaces

Surveys the ways a low-privilege domain account can attack an internet-facing MS Exchange web interface, then adds a new one: reaching the RPC over HTTP v2 proxy by the NetBIOS name leaked in NTLMSSP and abusing MS-OXNSPI address-book identifiers, which on domain controllers are database row numbers, so walking them dumps every Active Directory record.

Record

Researcher
Arseniy Sharoglazov and @_mohemiv
Published by
PT SWARM
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Arseniy Sharoglazov and @_mohemiv, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .