Exchange / OWA

Version, NTLM auth realm

Small helper to check Exchange Version, Release date and NTLM auth realm

Internal Pentest - NTLM Reco

Proxy Logon

ProxyShell - CVE-2021-34473

Check if exchange is vulnerable:

CVE-2023-36745 - RCE

ProxyNotShell

Exploiting Exchange Powershell after ProxyNotShell

User enumeration

Metasploit owa_login

MailSniper

Msmailprobe

Password Spray

Bruteforce

Cloud

Microsoft Exchange ActiveSync (EAS)

/Microsoft-Server-ActiveSync/is reachable

Resources

Interesting Books

Interesting Books

Disclaimer: As an Amazon Associate, I earn from qualifying purchases. This helps support this GitBook project at no extra cost to you.

Last updated